[krbdev.mit.edu #8542] Check for k5login permission
Greg Hudson via RT
rt-comment at krbdev.mit.edu
Thu Feb 2 01:08:53 EST 2017
I have the same concern as Sam. I understand the desire to police the
permissions of security-sensitive files within home directories, since
users don't always do a good job of it. (Nor does all documentation;
it's depressing how often users of shared web host systems are
instructed to use "chmod 777".) But adding a mode bit check runs the
risk of breaking deployments where permissive mode bits are intended and
safe within the context of the OS setup.
More information about the krb5-bugs
mailing list