[Freeipa-devel] [PATCH 0034] Secure permissions of Custodia server.keys

Christian Heimes cheimes at redhat.com
Mon Aug 8 14:09:38 UTC 2016


I have split up patch 0032 into two smaller patches. This patch only
addresses the server.keys file.

Custodia's server.keys file contain the private RSA keys for encrypting
and signing Custodia messages. The file was created with permission 644
and is only secured by permission 700 of the directory
/etc/ipa/custodia. The installer and upgrader ensure that the file
has 600.

https://bugzilla.redhat.com/show_bug.cgi?id=1353936
https://fedorahosted.org/freeipa/ticket/6056
-------------- next part --------------
A non-text attachment was scrubbed...
Name: freeipa-cheimes-0034-Secure-permissions-of-Custodia-server.keys.patch
Type: text/x-patch
Size: 2245 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20160808/a8ed056c/attachment.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 455 bytes
Desc: OpenPGP digital signature
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20160808/a8ed056c/attachment.sig>


More information about the Freeipa-devel mailing list