Now I suppose what we could do is define a new CAP_SYS_RESTART
capability and require that. Then the admin to whom I'm trying
to cater could simply 'capset cap_sys_restart=pe /bin/restart'.
Then all users could use restart without being granted the
extra privilege implied by CAP_SYS_ADMIN.
-serge
--