File nm-add-CAP_SYS_ADMIN-permission.patch of Package NetworkManager.12638
Index: NetworkManager-1.16.2/data/NetworkManager.service.in
===================================================================
--- NetworkManager-1.16.2.orig/data/NetworkManager.service.in
+++ NetworkManager-1.16.2/data/NetworkManager.service.in
@@ -17,7 +17,8 @@ KillMode=process
CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE CAP_AUDIT_WRITE CAP_KILL CAP_SYS_CHROOT
# ibft settings plugin calls iscsiadm which needs CAP_SYS_ADMIN
-#CapabilityBoundingSet=CAP_SYS_ADMIN
+# netconfig calls setdomainname which needs CAP_SYS_ADMIN
+CapabilityBoundingSet=CAP_SYS_ADMIN
ProtectSystem=true
ProtectHome=read-only