[Bug 1207499] Keys in /etc/cryptsetup-keys.d are set to 0777
https://bugzilla.suse.com/show_bug.cgi?id=1207499 https://bugzilla.suse.com/show_bug.cgi?id=1207499#c3 Gregory Boga <gregory_boga@comcast.net> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |gregory_boga@comcast.net --- Comment #3 from Gregory Boga <gregory_boga@comcast.net> --- (In reply to Ludwig Nussel from comment #1)
where do those file in /etc/cryptsetup-keys.d/ come from? Did you create them manually or via yast?
Hello if we are talking about the "installer", which I believe is yast, than yast creates "/etc/cryptsetup-keys.d/" when the user creates an encrypted filesystem, block device, partition, etc. I am currently running a freshly installed tumbleweed snapshot (20230310-0) and can confirm that in the system logs, I also have this warning. However, when I go to adjust permissions, the directory is not on my system. I have combed through the cryptsetup and LUKS1 documentation, and it appears that "/etc/cryptsetup-keys.d/name.key" should have permissions of 0600, but since this directory does not exist on my system, I am not sure how LUKS1/dm-crypt have been setup. Maybe Tumbleweed hardcodes this structure into initramfs, key loaded into memory? -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com