Module: kamailio
Branch: master
Commit: a2ff40c6a7df4511012a3b130a1d3e8eb33ed83e
URL: 
https://github.com/kamailio/kamailio/commit/a2ff40c6a7df4511012a3b130a1d3e8eb33ed83e

Author: Victor Seva <[email protected]>
Committer: Victor Seva <[email protected]>
Date: 2026-01-29T08:57:54+01:00

ims_ipsec_pcscf: document needed permissions for non-root execution

related #4420

---

Modified: src/modules/ims_ipsec_pcscf/doc/ims_ipsec_pcscf_admin.xml

---

Diff:  
https://github.com/kamailio/kamailio/commit/a2ff40c6a7df4511012a3b130a1d3e8eb33ed83e.diff
Patch: 
https://github.com/kamailio/kamailio/commit/a2ff40c6a7df4511012a3b130a1d3e8eb33ed83e.patch

---

diff --git a/src/modules/ims_ipsec_pcscf/doc/ims_ipsec_pcscf_admin.xml 
b/src/modules/ims_ipsec_pcscf/doc/ims_ipsec_pcscf_admin.xml
index e587a8dfc2f..ebcf68276a9 100644
--- a/src/modules/ims_ipsec_pcscf/doc/ims_ipsec_pcscf_admin.xml
+++ b/src/modules/ims_ipsec_pcscf/doc/ims_ipsec_pcscf_admin.xml
@@ -14,6 +14,15 @@
     <para>This module contains methods for IPSec 
initialisation/deinitialisation related for usage of Kamailio as a
        Proxy-CSCF.</para>
 
+    <para>&kamailio; process needs specific permssions in order to manage 
IPSec tunnels,
+    if executed by non-root user be sure to allow needed capabilities.</para>
+    <example>
+      <title>Systemd override configuration</title>
+      <programlisting format="linespecific">
+[Service]
+AmbientCapabilities=CAP_NET_ADMIN CAP_NET_RAW
+      </programlisting>
+    </example>
   </section>
 
   <section>

_______________________________________________
Kamailio - Development Mailing List -- [email protected]
To unsubscribe send an email to [email protected]
Important: keep the mailing list in the recipients, do not reply only to the 
sender!

Reply via email to