Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DKG CLI write keys with 600 #75

Open
gakonst opened this issue May 29, 2020 · 0 comments
Open

DKG CLI write keys with 600 #75

gakonst opened this issue May 29, 2020 · 0 comments

Comments

@gakonst
Copy link
Contributor

gakonst commented May 29, 2020

5.1 [dkg-cli] Private keys written with read permissions Severity: medium
5.1.1 Description
The private keys generated by the dkg new utility are written with 644 permissions, allowing them to be read by all users of the system. This may expose private keys to unauthorized users.
5.1.2 Recommendation
Permissions should preferably be set to 600, to disallow read access from other users.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant