diff options
author | Davanum Srinivas <dims@linux.vnet.ibm.com> | 2013-01-28 20:23:53 -0500 |
---|---|---|
committer | Davanum Srinivas <dims@linux.vnet.ibm.com> | 2013-01-28 21:04:35 -0500 |
commit | f57b61de71b2eaa31d889f7147968f8db4892e47 (patch) | |
tree | 91ac56e0d3aebd4454ee3f005d5d99ed7cf10d1d | |
parent | ce09c50c9253131396f713edbf11ca427341be0e (diff) | |
download | nova-f57b61de71b2eaa31d889f7147968f8db4892e47.tar.gz nova-f57b61de71b2eaa31d889f7147968f8db4892e47.tar.xz nova-f57b61de71b2eaa31d889f7147968f8db4892e47.zip |
Fix authorized_keys file permissions
Explicitly set the file permissions to be 0600
Fixes LP# 1107908
Change-Id: Ife44deff41959180d31e7e88c29233e9b8cb0af2
-rw-r--r-- | nova/tests/test_virt_disk.py | 4 | ||||
-rw-r--r-- | nova/virt/disk/api.py | 1 |
2 files changed, 3 insertions, 2 deletions
diff --git a/nova/tests/test_virt_disk.py b/nova/tests/test_virt_disk.py index e6a57e085..0c51e8267 100644 --- a/nova/tests/test_virt_disk.py +++ b/nova/tests/test_virt_disk.py @@ -67,7 +67,7 @@ class VirtDiskTest(test.TestCase): "key was injected by Nova\nmysshkey\n", 'gid': 100, 'uid': 100, - 'mode': 0700}) + 'mode': 0600}) vfs.teardown() @@ -101,7 +101,7 @@ class VirtDiskTest(test.TestCase): "key was injected by Nova\nmysshkey\n", 'gid': 100, 'uid': 100, - 'mode': 0700}) + 'mode': 0600}) vfs.teardown() diff --git a/nova/virt/disk/api.py b/nova/virt/disk/api.py index 3d7d0f516..304781a64 100644 --- a/nova/virt/disk/api.py +++ b/nova/virt/disk/api.py @@ -443,6 +443,7 @@ def _inject_key_into_fs(key, fs): ]) _inject_file_into_fs(fs, keyfile, key_data, append=True) + fs.set_permissions(keyfile, 0600) _setup_selinux_for_keys(fs, sshdir) |