timesyncd: run timesyncd as unpriviliged user "systemd-timesync" (but still with CAP_SYS_TIME)

This commit is contained in:
Lennart Poettering
2014-05-17 20:33:47 +02:00
parent 2bcc252371
commit a349eb10d3
5 changed files with 93 additions and 2 deletions

5
README
View File

@@ -183,6 +183,11 @@ USERS AND GROUPS:
exist. During execution this network facing service will drop
privileges and assume this uid/gid for security reasons.
The NTP daemon requires the "systemd-timesync" system user and
group to exist. During execution this network facing service
will drop priviliges (with the exception of CAP_SYS_TIME) and
assume this uid/gid for security reasons.
WARNINGS:
systemd will warn you during boot if /etc/mtab is not a
symlink to /proc/mounts. Please ensure that /etc/mtab is a