bzr branch
http://bzr.recompile.se/loggerhead/mandos/trunk
954
by Teddy Hogeborn
Move UMASK setting to more proper place |
1 |
# -*- shell-script -*-
|
2 |
||
3 |
# Since the initramfs image will contain key files, we need to
|
|
4 |
# restrict permissions on it by setting UMASK here.
|
|
5 |
#
|
|
6 |
# The proper place to set UMASK is (according to
|
|
7 |
# /etc/cryptsetup-initramfs/conf-hook), in
|
|
8 |
# /etc/initramfs-tools/initramfs.conf, which we shouldn't edit. The
|
|
9 |
# corresponding directory for drop-in files from packages is
|
|
10 |
# /usr/share/initramfs-tools/conf.d, and this file will be installed
|
|
11 |
# there as "mandos-conf".
|
|
12 |
#
|
|
13 |
# This setting of UMASK will have unfortunate unintended side effects
|
|
14 |
# on the files *inside* the initramfs, but these are later fixed by
|
|
15 |
# "initramfs-tools-hook", installed as
|
|
16 |
# "/usr/share/initramfs-tools/hooks/mandos".
|
|
17 |
UMASK=0027 |