<!DOCTYPE html><html><body>Hi,<br><br>> Just add the capability to the service unit file.<br><br>Sure, I can do that.<br><br>My doubts are not about how to do it, but whether it is a good idea. CAP_SYS_ADMIN is a rather huge pile of capabilities, and certainly there is a reason userdbd runs with a very constrained set now?<br><br>-nik</body></html>