[BlueOnyx:22730] Re: invalid cert letsencrypt

Michael Stauber mstauber at blueonyx.it
Mon Feb 25 12:56:21 -05 2019


Hi Tomohiro,

> ssh blueonyx
> # umask
> 022

I see. Thank you.

> The 5208R source code could not be found :)
> https://devel.blueonyx.it/repos/trunk/BlueOnyx/

The 5207R/5208R sources (they're the same) are here:

http://devel.blueonyx.it/trac/browser/BlueOnyx/5207R

> utils/cce/server/src/main.c
> 229:    umask(027);

Nice catch! Yeah, that'll do. Still: For security reasons I'd like to
keep it there. We just need to get acme.sh use the right unask instead
or change the file permissions after the fact. For that reason I already
had added a chmod 644 to the files in acme.sh that we previously hadn't.

-- 
With best regards

Michael Stauber



More information about the Blueonyx mailing list