Bug#863042: [Letsencrypt-devel] Bug#863042: dehydrated: insecure file permissions by default

2017-05-22 Thread Mattia Rizzolo
Control: tag -1 unreproducible moreinfo On Sat, May 20, 2017 at 07:25:03PM +0300, Alexander GQ Gerasiov wrote: > dehydrated package by default create private files with word-readable > permissions. That's not what it doe around here, nor I could find anybody who had your experience. One of the fi

Bug#863042: dehydrated: insecure file permissions by default

2017-05-20 Thread Alexander Gerasiov
Hello Alexander, On Sat, 20 May 2017 19:25:03 +0300 Alexander GQ Gerasiov wrote: > > -- System Information: > Debian Release: 9.0 > APT prefers testing > APT policy: (700, 'testing'), (670, 'stable-updates'), (670, > 'stable'), (600, 'unstable'), (550, 'experimental') Architecture: > amd64

Bug#863042: dehydrated: insecure file permissions by default

2017-05-20 Thread Alexander GQ Gerasiov
Source: dehydrated Version: 0.3.1-3~bpo8+1 Severity: serious Tags: security dehydrated package by default create private files with word-readable permissions. How I got this: I installed dehydrated 0.3.1-3~bpo8+1 Put my domain with subdomains to /etc/dehydrated/domains.txt and run # dehydrated -c