From a48a62a1af02aec4473c9deed98dd5b89d210f93 Mon Sep 17 00:00:00 2001 From: Zbigniew Jędrzejewski-Szmek Date: Sun, 18 Jan 2015 15:05:40 -0500 Subject: tmpfiles: use ACL magic on journal directories --- README | 11 +++-------- 1 file changed, 3 insertions(+), 8 deletions(-) (limited to 'README') diff --git a/README b/README index fa95433ecb..c72209262e 100644 --- a/README +++ b/README @@ -178,14 +178,9 @@ USERS AND GROUPS: During runtime, the journal daemon requires the "systemd-journal" system group to exist. New journal files will be readable by this group (but not writable), which may be used - to grant specific users read access. - - It is also recommended to grant read access to all journal - files to the system groups "wheel" and "adm" with a command - like the following in the post installation script of the - package: - - # setfacl -nm g:wheel:rx,d:g:wheel:rx,g:adm:rx,d:g:adm:rx /var/log/journal/ + to grant specific users read access. In addition, system + groups "wheel" and "adm" will be given read-only access to + journal files using systemd-tmpfiles.service. The journal gateway daemon requires the "systemd-journal-gateway" system user and group to -- cgit v1.2.3-54-g00ecf