(In reply to werner@suse.com from comment #7) > I'm now simply using group root with 4750 If it is okay that the tool can only be used root then it is fine by me. Then you could simply drop the setuid-root bit altogether. This would save us the whitelisting entry. If you want to keep the setuid-root bit then we can also add some useable group to the permissions easy profile.