From Debian package 0.2.20100524-11 * Allow snmpd to setuid and setgid. Index: policy/modules/services/snmp.te =================================================================== --- policy/modules/services/snmp.te.orig +++ policy/modules/services/snmp.te @@ -24,7 +24,7 @@ # # Local policy # -allow snmpd_t self:capability { chown dac_override kill ipc_lock sys_ptrace net_admin sys_nice sys_tty_config }; +allow snmpd_t self:capability { chown dac_override setgid setuid kill ipc_lock sys_ptrace net_admin sys_nice sys_tty_config }; dontaudit snmpd_t self:capability { sys_module sys_tty_config }; allow snmpd_t self:process { signal_perms getsched setsched }; allow snmpd_t self:fifo_file rw_fifo_file_perms;