[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Problem with special permissions of config file



Ben Collins <bcollins@debian.org> writes:

> On Wed, May 30, 2001 at 08:14:52PM +0200, Stefan Hornburg (Racke) wrote:
> > 
> > My package courier-authmysql has a configuration file where the
> > password for the MySQL database can be stored. So I set this
> > file to 600 in postinst. But dpkg put the backup file .dpkg-old
> > in the same directory with 622 which seems a rather bad idea
> > to me. Is there anything I can do about it ?
> > 
> > It is a potato backport where this happened, I didn't try it
> > out on sid.
> 
> Set the perms in the package, so the file gets installed with the
> correct perms. Don't set perms in postinst like this.

You're right, this a packaging bug in the first place. But it would
be more security-aware of dpkg to preserve the permissions. I thinking
about filing a bug.

Thanks for your answer

Ciao
        Racke

-- 
Master of Swiss Web 2001: http://www.zweifel.ch/

For projects and other business stuff please refer to COBOLT NetServices
(URL: http://www.cobolt.net; Email: info@cobolt.net; Phone: 0041-1-3884400)



Reply to: