[chrony-users] Chrony as non-root user (again) |
[ Thread Index |
Date Index
| More chrony.tuxfamily.org/chrony-users Archives
]
- To: chrony-users@xxxxxxxxxxxxxxxxxxxx
- Subject: [chrony-users] Chrony as non-root user (again)
- From: Kevin <kevincox@xxxxxxxxxxx>
- Date: Thu, 10 Sep 2020 19:28:23 -0400
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kevincox.ca; s=google; h=to:from:subject:message-id:date:user-agent:mime-version :content-transfer-encoding:content-language; bh=K1CGrY/jr1tv6wnbtOq26VS15rlRIwzoHyizSpwyMUQ=; b=BZ5NeWF6V0iBNL4Wl5moacPhHjonJffsLDdw7Ml1xCA4QnK+uqN4+0PVJFYnicVCbX xwOkEM6pjLjUOv9qNyGRA4AqWLwrDULMrsl8ulADmFGimv+EMCqzHgH720JWtjfA+kEA fq4JKVC2uFVC/ygIORYLuqHEzsTj/J0+yyAiLjBVY5C2hSKOhpL07sK6y01/gNxd745l o17m1WYyL8rcwlGXtaiXkBOvbXrEybuv0nhvlPZ4wmX3chsoZx1C0zojJKFRBFML5rxG At9NNMyXY+tyjZInCMOlfLWn7LwN8lO1ZInHTO/CJaJFPMQbqd+WiXtL0r88Khwfk7PR eN9w==
I know it has been discussed a number of times before on this list (ex:
https://www.mail-archive.com/chrony-users@xxxxxxxxxxxxxxxxxxxx/msg01751.html)
however it seems like it was dismissed too quickly.
The given reason was:
> Even when running as a client only, chronyd may need root permissions
to open some devices (e.g. /dev/ptp*, /dev/rtc*), create directories
(/var/run/chrony), or enable HW timestamping.
However it seems to me that all of these (except maybe for HW
timestamping, I am not familiar) can be managed by more fine grained
permissions such as chaining the group or ACL of the device node,
creating the directories beforehand or via process capabilities.
Would it be possible to enable running chrony as a non-privileged user?
This can either be downgrading the root check to a warning or by adding
a flag (such as
https://www.mail-archive.com/chrony-dev@xxxxxxxxxxxxxxxxxxxx/msg01731.html)
that allows running as a non-root user. This would help those of us for
whom the features we need are available in a non-root process.
If it would make you more comfortable you can label the flag as
experimental or similar, but it would be a nice way to get some testing
and allow running chrony more locked down.
--
To unsubscribe email chrony-users-request@xxxxxxxxxxxxxxxxxxxx
with "unsubscribe" in the subject.
For help email chrony-users-request@xxxxxxxxxxxxxxxxxxxx
with "help" in the subject.
Trouble? Email listmaster@xxxxxxxxxxxxxxxxxxxx.