Re: [libvirt PATCH] remote: use SocketMode=0600 when polkit is not compiled

2020-09-03 Thread Daniel P . Berrangé
On Thu, Sep 03, 2020 at 04:22:39PM +0200, Ján Tomko wrote: > On a Wednesday in 2020, Daniel P. Berrangé wrote: > > The systemd .socket unit files we ship for libvirt daemons use > > SocketMode=0666 on the assumption that libvirt is built with > > polkit which provides access control. > > > > Some

Re: [libvirt PATCH] remote: use SocketMode=0600 when polkit is not compiled

2020-09-03 Thread Ján Tomko
On a Wednesday in 2020, Daniel P. Berrangé wrote: The systemd .socket unit files we ship for libvirt daemons use SocketMode=0666 on the assumption that libvirt is built with polkit which provides access control. Some people, however, may have explicitly turned off polkit at build time and not re

Re: [libvirt PATCH] remote: use SocketMode=0600 when polkit is not compiled

2020-09-03 Thread Jiri Denemark
On Wed, Sep 02, 2020 at 18:54:36 +0100, Daniel P. Berrangé wrote: > The systemd .socket unit files we ship for libvirt daemons use > SocketMode=0666 on the assumption that libvirt is built with > polkit which provides access control. > > Some people, however, may have explicitly turned off polkit

[libvirt PATCH] remote: use SocketMode=0600 when polkit is not compiled

2020-09-02 Thread Daniel P . Berrangé
The systemd .socket unit files we ship for libvirt daemons use SocketMode=0666 on the assumption that libvirt is built with polkit which provides access control. Some people, however, may have explicitly turned off polkit at build time and not realize that leaves them insecure unless they also cha

Re: [PATCH] remote: use SocketMode=0600 when polkit is not compiled

2020-08-07 Thread Pavel Hrdina
On Fri, Aug 07, 2020 at 01:45:52PM +0100, Daniel P. Berrangé wrote: > The systemd .socket unit files we ship for libvirt daemons use > SocketMode=0666 on the assumption that libvirt is built with > polkit which provides access control. > > Some people, however, may have explicitly turned off polki

[PATCH] remote: use SocketMode=0600 when polkit is not compiled

2020-08-07 Thread Daniel P . Berrangé
The systemd .socket unit files we ship for libvirt daemons use SocketMode=0666 on the assumption that libvirt is built with polkit which provides access control. Some people, however, may have explicitly turned off polkit at build time and not realize that leaves them insecure unless they also cha