#720 closed System Defect (fixed)

Permissions on pc-activedirectory.conf allow users to view domain admin password

Reported by: xenophonf Owned by:
Priority: major Milestone:
Component: System Configuration Version: 9.1-RELEASE
Keywords: Cc: trac-bugs@…

Description

/usr/local/etc/pc-activedirectory.conf should have permissions 0400, instead of 0444. Otherwise, unprivileged users will be able to view the username and password of the account used to join the PC-BSD system to the domain.

Change History (2)

comment:2 Changed 11 months ago by kenmoore

  • Resolution set to fixed
  • Status changed from new to closed
Note: See TracTickets for help on using tickets.