This is the message I'm talking about:
- Code: Select all
grsec: denied auto-loading kernel module for a network device with CAP_SYS_MODULE (deprecated). Use CAP_NET_ADMIN and alias netdev-bonding instead.
These messages appear before the RBAC systems would be activated, so I have no clue how I might determine the executable causing it and how I could make the binary to ask for CAP_NET_ADMIN. I suspect it's not a simple policy issue. Modprobe and all other relevant module binaries have CAP_NET_ADMIN in my rule set. I suppose udev triggers the auto load logic for bonding. The parameters are included in the necessary files, but the mechanism doesn't care about those.
I got to the point, where I chose the dirty way and had altered the defaults in the kernel source. Of course it works, but I'm seeking a proper solution.
Please let me know what am I supposed to do to get rid of this and make the system auto-load the module with the correct parameters. I have no clue where can I teach the system the suggested alias.
Thanks:
Dw.