|
Message-ID: <5EA177BBB85E4EF4900F47CD51F0323E@wildbit.com> Date: Tue, 9 Apr 2013 14:08:20 -0400 From: Russ Thompson <russ@...dbit.com> To: oss-security@...ts.openwall.com Subject: Postfix incorrect permissions on configurations. Request. Postfix is setting the following permissions by default on Debian Squeeze. I'm seeing roughly the same on RHEL/CentOS 6.x, this appears to be a requirement of "sendmail.postfix" 0755 /etc/postfix 0644 /etc/postfix/* 0755 /etc/postfix-script 0755 /etc/post-install Which allows all users to execute these scripts and read configurations. Setting to tighter/more typical permissions (i.e 640) results in: postfix/sendmail[21007]: fatal: open /etc/postfix/main.cf: Permission denied Thanks - Russ
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.