Unless I am mistaken, I just noticed that openca-common includes:

/var/lib/openca/crypto/index.txt
/var/lib/openca/crypto/serial

This means that upgrading the openca-common package will overwrite these
files without any warning or question.

Is this really desirable?

Also I am going to remove world readable permissions on this directory
(and instead only allow access by the www-data user):

/var/lib/openca/crypto/keys

Are there any other directories that should not be world
readable?
-- 
Brian May <[EMAIL PROTECTED]>


-------------------------------------------------------
This SF.net email is sponsored by:Crypto Challenge is now open! 
Get cracking and register here for some mind boggling fun and 
the chance of winning an Apple iPod:
http://ads.sourceforge.net/cgi-bin/redirect.pl?thaw0031en
_______________________________________________
OpenCA-Devel mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/openca-devel

Reply via email to