pam_cap settings are not applied on SELinux enabled systems
Issue
- Capabilities configured for users using
pam_capPAM module are not taken into account when users are logging in using eithersshor on console - AVC message related to "avc: denied { setcap }" can be seen in the
audit.logfile
Environment
- Red Hat Enterprise Linux 7 and later
pam_cap
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.