File tree 3 files changed +15
-3
lines changed
3 files changed +15
-3
lines changed Original file line number Diff line number Diff line change @@ -20,6 +20,8 @@ ProtectKernelTunables=yes
20
20
ProtectKernelModules =yes
21
21
ProtectControlGroups =yes
22
22
AmbientCapabilities =CAP_NET_BIND_SERVICE
23
+ CapabilityBoundingSet =CAP_NET_BIND_SERVICE
24
+
23
25
24
26
[Install]
25
27
WantedBy =multi-user.target
Original file line number Diff line number Diff line change 1
1
#! /bin/sh
2
+ # Reload systemd daemon to account for new/updated service files
2
3
systemctl daemon-reload
4
+
5
+ # Enable services
3
6
systemctl enable xdpderper.service
4
7
systemctl enable derper.service
8
+
9
+ # Start services
5
10
systemctl start xdpderper.service
6
- systemctl start derper.service
11
+ systemctl start derper.service
12
+
13
+ # setcap
14
+ sudo setcap ' cap_net_bind_service=+ep' /usr/bin/derper
15
+ sudo setcap ' cap_net_bind_service=+ep' /usr/bin/xdpderper
16
+
Original file line number Diff line number Diff line change 1
1
#! /bin/sh
2
2
getent group xdpderper > /dev/null || groupadd -r xdpderper
3
- getent passwd xdpderper > /dev/null || useradd -r -g xdpderper -s /sbin/nologin -c " XDPDERP server" xdpderper
3
+ getent passwd xdpderper > /dev/null || useradd -r -g xdpderper -s /bin/bash -c " XDPDERP server" xdpderper
4
4
getent group derper > /dev/null || groupadd -r derper
5
- getent passwd derper > /dev/null || useradd -r -g derper -s /sbin/nologin -c " DERP server" derper
5
+ getent passwd derper > /dev/null || useradd -r -g derper -s /bin/bash -c " DERP server" derper
You can’t perform that action at this time.
0 commit comments