[Opendnssec-user] ods-signerd changing file mode of signed zones

Mathieu Arnold mat at mat.cc
Fri Mar 28 13:00:57 UTC 2014


+--On 28 mars 2014 12:04:33 +0100 Rickard Bellgrim <rickard at opendnssec.org>
wrote:
| On Fri, Mar 28, 2014 at 11:01 AM, Mathieu Arnold <mat at mat.cc> wrote:
| 
|> 
|> 
|> +--On 28 mars 2014 07:42:18 +0100 Rickard Bellgrim
|> <rickard at opendnssec.org
|> > 
|> wrote:
|> | On Thu, Mar 27, 2014 at 5:45 PM, Mathieu Arnold <mat at mat.cc> wrote:
|> | 
|> |> I've browsed ODS's sources, and can't really figure out why it would
|> |> happen, I can't see anywhere where umask is changed, or even where
|> |> file modes are used to write to files...
|> |> 
|> | 
|> |  Are you running SoftHSM 1.3.6? It uses umask when opening the token
|> | database, but restores it right after.
|> | 
|> | 
|> https://github.com/opendnssec/SoftHSMv1/commit/dc2914a396f79bd131e2f620dc
|> | 710b7e0bff1b6f
|> 
|> Yes, I am, that solves it then :-)
|> As my softhsm token db are still 644, I believe it fails in doing what it
|> thinks it does.
|> 
| 
| SoftHSM would only set 600 on new files. It won't change it on existing
| files. Your token db was probably created by an earlier version, right?

Hum, well, yes, true, an earlier version, about 4 years ago :-)

| (It still is an issue that the main application (ods-signer) gets
| affected.)

That it is :-)

-- 
Mathieu Arnold



More information about the Opendnssec-user mailing list