[Bug 1700611] Re: sources.list file created for ESM is world-readable, leaks subscriber token to all local users

2017-11-27 Thread Andreas Hasenack
Reopening, let's use auth.conf ** Changed in: ubuntu-advantage-tools (Ubuntu) Status: Incomplete => Triaged -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu.

[Bug 1700611] Re: sources.list file created for ESM is world-readable, leaks subscriber token to all local users

2017-06-30 Thread Andreas Hasenack
** Also affects: ubuntu-advantage-script via https://github.com/CanonicalLtd/ubuntu-advantage-script/issues/22 Importance: Unknown Status: Unknown -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in

[Bug 1700611] Re: sources.list file created for ESM is world-readable, leaks subscriber token to all local users

2017-06-30 Thread Andreas Hasenack
There seems to be a difference in behavior in apt. Precise's apt-cache, for example, doesn't seem to care: ubuntu@precise-esm:~$ l /etc/apt/sources.list.d/staging-ubuntu-esm-precise.list -rw--- 1 root root 200 Jun 7 18:35 /etc/apt/sources.list.d/staging-ubuntu-esm-precise.list

[Bug 1700611] Re: sources.list file created for ESM is world-readable, leaks subscriber token to all local users

2017-06-29 Thread Andreas Hasenack
Making the file 0600 makes apt-cache complain about it when run by non- root users. Is that an issue worth having? $ apt policy asdf E: Opening /etc/apt/sources.list.d/dropbox.list - ifstream::ifstream (13: Permission denied) E: The list of sources could not be read. (dropbox.list was just

[Bug 1700611] Re: sources.list file created for ESM is world-readable, leaks subscriber token to all local users

2017-06-27 Thread Andreas Hasenack
Filed upstream: https://github.com/CanonicalLtd/ubuntu-advantage- script/issues/22 ** Bug watch added: github.com/CanonicalLtd/ubuntu-advantage-script/issues #22 https://github.com/CanonicalLtd/ubuntu-advantage-script/issues/22 -- You received this bug notification because you are a member