Bug#955206: freeradius: Daemon has write privilege to configuration

2020-04-03 Thread Bernhard Schmidt
Am 03.04.20 um 15:10 schrieb wf...@niif.hu: Hi, > "Debian Bug Tracking System" writes: > >> - set ReadOnlyDirectories to the configuration (Closes: #955206) > > Well, not very transparent or general, but certainly address my main > concern. However, the file ownerships still send the wrong

Bug#955206: freeradius: Daemon has write privilege to configuration

2020-04-03 Thread wferi
"Debian Bug Tracking System" writes: > - set ReadOnlyDirectories to the configuration (Closes: #955206) Well, not very transparent or general, but certainly address my main concern. However, the file ownerships still send the wrong message to me. Could you please explain why the configuration

Bug#955206: freeradius: Daemon has write privilege to configuration

2020-03-28 Thread Ferenc Wágner
Source: freeradius Version: 3.0.17+dfsg-1.1 Severity: wishlist Dear Maintainer, In the default installation freeradius runs as user freerad, which is also the user owning the /etc/freeradius directory structure. This means that an arbitrary code execution compromise in the daemon means