Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Clarify the capabilities for cert expiry #87

Merged
merged 2 commits into from
Nov 3, 2023

Conversation

rowezuniga
Copy link
Contributor

Background

If a cert expiry experiment is configured to target a CIDR, the linux capabilities dac_read_search and sys_ptrace are required to discover the active connections that match that CIDR.

Changes

Update a comment to clarify that we need those capabilities for service discovery (in gremlind) but also certificate expiry experiments (in gremlin).

@rowezuniga rowezuniga requested review from a team as code owners October 30, 2023 22:43
@rowezuniga rowezuniga merged commit 91d49a0 into master Nov 3, 2023
@thefirstofthe300 thefirstofthe300 deleted the cert-expiry-linux-capabilities branch January 3, 2024 22:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
3 participants