Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 20 Oct 2021 18:22:18 +0000
From:      bugzilla-noreply@freebsd.org
To:        ports-bugs@FreeBSD.org
Subject:   [Bug 258827] security/step-certificates: step-ca fails to start in the init process included SSH certs
Message-ID:  <bug-258827-7788-elGzrdXaCK@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-258827-7788@https.bugs.freebsd.org/bugzilla/>
References:  <bug-258827-7788@https.bugs.freebsd.org/bugzilla/>

next in thread | previous in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D258827

--- Comment #4 from Markus Wipp <mw@wipp.bayern> ---
Hi Adam,=20

sorry for the long delay due to illness.

I just checked and found the following:

1) the directory /usr/local/etc/step is generated during installation with =
the
correct permissions
2) if the directory is deleted, it will be recreated by the smallstep progr=
am
with the "wrong" permissions. the fix is as you already found out to recrea=
te
the correct permission with "chmod go+rx /usr/local/etc/step"

I think there are possibly three ways to handle this:

1) don't delete the directory, but only its contents
2) file a bug with smallstep-certificates directly, to have it create the
directory with the correct permissions
3) add some code in the init-script to check whether the directory exists a=
nd
create it with the correct permissions if necessary

Best regards
Markus

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-258827-7788-elGzrdXaCK>