mirror of
https://gitlab.kit.edu/kit/scc/sys/mail/exim-encrypt-dlfunc.git
synced 2025-12-06 12:33:55 +01:00
Change umask to besser protect generated key files.
This commit is contained in:
@ -2,6 +2,8 @@
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
#include <ctype.h>
|
||||
#include <sys/types.h>
|
||||
#include <sys/stat.h>
|
||||
#include <sodium.h>
|
||||
|
||||
//void
|
||||
@ -77,6 +79,9 @@ write_key_files(const char *filebase, const char *varname,
|
||||
sprintf(exim_filename, "%s_exim.conf", filebase);
|
||||
sprintf(raw_filename, "%s.raw", filebase);
|
||||
|
||||
// set restrictive umask (access to user only)
|
||||
mode_t original_umask = umask(S_IXUSR | S_IRWXG | S_IRWXO);
|
||||
|
||||
// open exim config snippet file
|
||||
f = fopen(exim_filename, "w+");
|
||||
if (f == NULL) {
|
||||
@ -103,6 +108,8 @@ write_key_files(const char *filebase, const char *varname,
|
||||
// close raw file
|
||||
fclose(f);
|
||||
|
||||
// restore original umask
|
||||
umask(original_umask);
|
||||
}
|
||||
|
||||
void create_cryptobox_keys(const char *filebase, const char *varname)
|
||||
|
||||
Reference in New Issue
Block a user