Create the master key file readable by its owner only - #37
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The key file is created with a plain
open(), so it gets whatever the umask gives (0664 inpractice), readable by any local user on the host.
It's now created 0600 with
os.open(), where the mode is set as the file is created - achmod afterwards would leave a short window where the key is readable by everyone. O_EXCL so
an existing key can't be overwritten.
On load, a key readable by group or other is now a startup error rather than a warning.
This stops other local users reading the key. It doesn't get it away from www-data - uwsgi
reads it as www-data by design, and nginx workers are www-data too.
To check, with the key owned by www-data and mode 0600: