Project

General

Profile

Actions

User story #8607

closed

Document security level of Rudder content

Added by Alexis Mousset over 8 years ago. Updated over 5 years ago.

Status:
Released
Priority:
N/A
Category:
Documentation
Target version:
UX impact:
Suggestion strength:
User visibility:
Effort required:
Name check:
Fix check:
Regression:

Description

  • What is accessible from who? From where?
  • What is encrypted? When?
  • Directive and 50_techniques are private, and always encrypted/root-readable only
  • The rudder group can give access to private data
  • All the rest (tools, ncf/common, etc.) should be considered "public", and may even be readable from non accepted hosts (ncf)
  • Shared files?

Related issues 2 (0 open2 closed)

Related to Rudder - Bug #8503: Files in /var/local/rudder/ncf are world readableReleasedAlexis MoussetActions
Related to Rudder - Bug #8159: Do not backup modified promise files and encrypt ncf/local transferReleasedNicolas CHARLES2016-04-07Actions
Actions

Also available in: Atom PDF