Re: Perms on refclock socket
| Newsgroups | gmane.comp.time.chrony.user |
|---|---|
| Message-ID | <zjesc2uihltyouhfgf6bxwjpu2gglgmf47n6u2bng3dbcadeyo@ujp7grjkzjmy> |
On Mon, Mar 18, 2024 at 09:15:57AM +0100, Miroslav Lichvar wrote: > Normally you wouldn't want non-root users to be able to send chronyd > bogus refclock data in order to modify the system clock. If an attacker can assume the identity of this account, I have *much* bigger problems than that. > If you really want to change the permissions or ownership of the > socket, you can do it in the chronyd systemd service file like this > ExecStartPost=/usr/bin/chown user:root /var/run/chrony.refclock.sock Thanks. I'll probably use a dedicated group instead, but the idea is perfect. -- Ian -- To unsubscribe email chrony-users-request-kWFZVVI9zxvPqho9SqqRMmD2FQJk+8+b@public.gmane.org with "unsubscribe" in the subject. For help email chrony-users-request-kWFZVVI9zxvPqho9SqqRMmD2FQJk+8+b@public.gmane.org with "help" in the subject. Trouble? Email [email protected]