Hi all, is it reasonable to try to limit the condor.service (and/or condor-ce.service) units in their exec capabilities, i.e, CapabilityBoundingSet [1]? ð I guess that condor needs a broad set of capabilities to switch users etc. but maybe dropping some of the network related capabilities? Cheers, Thomas [1] https://www.freedesktop.org/software/systemd/man/systemd.exec.html
Attachment:
0x4C44535B5D7ADD74.asc
Description: application/pgp-keys
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature