Arch Linux

Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!
Tasklist

FS#29107 - [openssl] directory permissions

Attached to Project: Arch Linux
Opened by Hubert Kario (tomato) - Sunday, 25 March 2012, 11:36 GMT
Last edited by Pierre Schmitz (Pierre) - Saturday, 21 April 2012, 18:29 GMT
Task Type Bug Report
Category Packages: Core
Status Closed
Assigned To Pierre Schmitz (Pierre)
Architecture x86_64
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Description:
openssl when installing complains about permissions to /etc/ssl/private:

upgrading openssl [#####] 100%
warning: directory permissions differ on etc/ssl/private/
filesystem: 700 package: 755

Shouldn't they *be* 700 in packge?!

* package version: 1.0.1-1
* config and/or log files etc.


Steps to reproduce:
Install openssl upgrade with properly set permissions on /etc/ssl/private
This task depends upon

Closed by  Pierre Schmitz (Pierre)
Saturday, 21 April 2012, 18:29 GMT
Reason for closing:  Upstream
Comment by Pierre Schmitz (Pierre) - Sunday, 25 March 2012, 15:24 GMT
Did you modify these permissions yourself? 755 seems fine to me. You might need to set different permissions to the files you put there. E.g. one for the imap user and another for http etc..
Comment by Hubert Kario (tomato) - Sunday, 25 March 2012, 22:22 GMT
I don't remember if I changed them, but most documentation I encountered suggested to keep private keys in folders readable only by the user that starts the daemons (so either root or system user). Debian keeps this folder owned by root:ssl-cert with 750 permissions.

What should be the persmissions of apache ssl folder: http://serverfault.com/q/216477/55663
Comment by Pierre Schmitz (Pierre) - Saturday, 21 April 2012, 18:29 GMT
I don't see a reason to change the upstream default.

Loading...