Skip to content

Conversation

@mrwacky42
Copy link

Since we generate some potentially sensitive files using concat, it seems wise to limit access to the concatdir to root.

@mrwacky42
Copy link
Author

Tested in a dev environment.
First, I removed a few files in /var/lib/puppet/concat, and the targets they generate.
Then I changed setup.pp with this patch and ran puppet.
It changed the permissions of /var/lib/puppet/concat, and regenerated the files happily.

ripienaar added a commit that referenced this pull request Jun 21, 2011
As discussed .. Make $concatdir only readable by root.
@ripienaar ripienaar merged commit 41a8ea2 into puppetlabs:master Jun 21, 2011
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants