Red Hat Bugzilla – Bug 1158759
Wrong permission for configuration file /etc/sysconfig/virt-who on rhel7.1
Last modified: 2016-11-30 19:33:27 EST
Description of problem: Configuration file /etc/sysconfig/virt-who may contain passwords but its permissions are 644 (rw-r--r--). It should be 600 (rw-------) to prevent non-root users to read the configuration file. Version-Release number of selected component (if applicable): virt-who-0.11-2.el7.noarch How reproducible: Always Steps to Reproduce: 1.Check the permission of virt-who config file. [root@hp-z220-03 20141030094255]# ll /etc/sysconfig/virt-who -rw-r--r--. 1 root root 1976 Oct 30 11:18 /etc/sysconfig/virt-who Actual results: its permissions are 644 (rw-r--r--) Expected results: It should be 600 (rw-------) to prevent non-root users to read the configuration file. Additional info:
Fixed in virt-who-0.11-3.el7.
Verified it on virt-who-0.11-3.el7.noarch. Steps to verify: 1.Check the permission of virt-who config file. it's 600 (rw-------) [root@hp-z220-06 sysconfig]# ls -alt virt-who -rw-------. 1 root root 1977 Nov 12 14:57 virt-who
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHSA-2015-0430.html