]> granicus.if.org Git - icinga2/commitdiff
Fix incorrect permissions for key files.
authorGunnar Beutner <gunnar.beutner@netways.de>
Wed, 11 Dec 2013 14:14:24 +0000 (15:14 +0100)
committerGunnar Beutner <gunnar.beutner@netways.de>
Wed, 11 Dec 2013 14:14:24 +0000 (15:14 +0100)
Fixes #5300

pki/icinga2-build-ca.cmake
pki/icinga2-build-key.cmake

index 1ac4eec24e9da82caa847becf00545051c91b64d..ce8c9e6607b79f74b4c9ded13b5a07ff6ca6d835 100644 (file)
@@ -19,4 +19,5 @@ cp $ICINGA2PKIDIR/vars $ICINGA_CA/
 source $ICINGA_CA/vars
 
 KEY_DIR=$ICINGA_CA openssl req -config $ICINGA2PKIDIR/openssl.cnf -new -newkey rsa:4096 -x509 -days 3650 -keyform PEM -keyout $ICINGA_CA/ca.key -outform PEM -out $ICINGA_CA/ca.crt && \
+       chmod 600 $ICINGA_CA/ca.key && \
        echo -e "\n\tIf you want to change the default settings for server certificates check out \"$ICINGA_CA/vars\".\n"
index 6d0bbdd3f0d41d9cfaf4ac236eb7251c2003f5bc..972640f3f9d6251ee883fec51db296e694041355 100644 (file)
@@ -28,5 +28,6 @@ fi
 
 REQ_COMMON_NAME="$name" KEY_DIR="$ICINGA_CA" openssl req -config $ICINGA2PKIDIR/openssl.cnf -new -newkey rsa:4096 -keyform PEM -keyout $ICINGA_CA/$name.key -outform PEM -out $ICINGA_CA/$name.csr -nodes && \
        openssl x509 -days "$REQ_DAYS" -CA $ICINGA_CA/ca.crt -CAkey $ICINGA_CA/ca.key -req -in $ICINGA_CA/$name.csr -outform PEM -out $ICINGA_CA/$name.tmp -CAserial $ICINGA_CA/serial && \
+       chmod 600 $ICINGA_CA/$name.key && \
        openssl x509 -in $ICINGA_CA/$name.tmp -text >  $ICINGA_CA/$name.crt && \
        rm -f $ICINGA_CA/$name.csr $ICINGA_CA/$name.tmp