[krbdev.mit.edu #8542] Check for k5login permission

Greg Hudson via RT rt-comment at krbdev.mit.edu
Thu Feb 2 01:08:53 EST 2017


I have the same concern as Sam.  I understand the desire to police the 
permissions of security-sensitive files within home directories, since 
users don't always do a good job of it.  (Nor does all documentation; 
it's depressing how often users of shared web host systems are 
instructed to use "chmod 777".)  But adding a mode bit check runs the 
risk of breaking deployments where permissive mode bits are intended and 
safe within the context of the OS setup.


More information about the krb5-bugs mailing list