Ver código fonte

letsencrypt permissions

Bob Mottram 7 anos atrás
pai
commit
fbc4c53d3a
2 arquivos alterados com 6 adições e 0 exclusões
  1. 2
    0
      src/freedombone-addcert
  2. 4
    0
      src/freedombone-utils-setup

+ 2
- 0
src/freedombone-addcert Ver arquivo

240
         echo $"Failed to install letsencrypt for domain $LETSENCRYPT_HOSTNAME"
240
         echo $"Failed to install letsencrypt for domain $LETSENCRYPT_HOSTNAME"
241
         echo $'Also see https://letsencrypt.status.io to check for any service outages'
241
         echo $'Also see https://letsencrypt.status.io to check for any service outages'
242
         chgrp -R ssl-cert /etc/letsencrypt
242
         chgrp -R ssl-cert /etc/letsencrypt
243
+        chmod -R 600 /etc/letsencrypt
243
         chmod -R g=rX /etc/letsencrypt
244
         chmod -R g=rX /etc/letsencrypt
244
         systemctl start nginx
245
         systemctl start nginx
245
         exit 63216
246
         exit 63216
288
     # this group can be used to assign read permissions for
289
     # this group can be used to assign read permissions for
289
     # application user accounts
290
     # application user accounts
290
     chgrp -R ssl-cert /etc/letsencrypt
291
     chgrp -R ssl-cert /etc/letsencrypt
292
+    chmod -R 600 /etc/letsencrypt
291
     chmod -R g=rX /etc/letsencrypt
293
     chmod -R g=rX /etc/letsencrypt
292
 
294
 
293
     nginx_ensite ${LETSENCRYPT_HOSTNAME}
295
     nginx_ensite ${LETSENCRYPT_HOSTNAME}

+ 4
- 0
src/freedombone-utils-setup Ver arquivo

560
     if [ -d /var/lib/prosody ]; then
560
     if [ -d /var/lib/prosody ]; then
561
         chown -R prosody /var/lib/prosody
561
         chown -R prosody /var/lib/prosody
562
     fi
562
     fi
563
+    if [ -d /etc/letsencrypt ]; then
564
+        chmod -R 600 /etc/letsencrypt
565
+        chmod -R g=rX /etc/letsencrypt
566
+    fi
563
 }
567
 }
564
 
568
 
565
 function disable_core_dumps {
569
 function disable_core_dumps {