Re: Problem with special permissions of config file
Ben Collins <bcollins@debian.org> writes:
> On Wed, May 30, 2001 at 08:14:52PM +0200, Stefan Hornburg (Racke) wrote:
> >
> > My package courier-authmysql has a configuration file where the
> > password for the MySQL database can be stored. So I set this
> > file to 600 in postinst. But dpkg put the backup file .dpkg-old
> > in the same directory with 622 which seems a rather bad idea
> > to me. Is there anything I can do about it ?
> >
> > It is a potato backport where this happened, I didn't try it
> > out on sid.
>
> Set the perms in the package, so the file gets installed with the
> correct perms. Don't set perms in postinst like this.
You're right, this a packaging bug in the first place. But it would
be more security-aware of dpkg to preserve the permissions. I thinking
about filing a bug.
Thanks for your answer
Ciao
Racke
--
Master of Swiss Web 2001: http://www.zweifel.ch/
For projects and other business stuff please refer to COBOLT NetServices
(URL: http://www.cobolt.net; Email: info@cobolt.net; Phone: 0041-1-3884400)
Reply to: