summary refs log tree commit diff
diff options
context:
space:
mode:
authorChris Ostrouchov <chris.ostrouchov@gmail.com>2019-01-30 12:53:54 -0500
committerChris Ostrouchov <chris.ostrouchov@gmail.com>2019-01-30 12:53:54 -0500
commit5a5def3753f050ba104ccd160d1cba501ad577ff (patch)
tree26acc025c714e6d089e6a665556d595e441c6604
parent72f324dbc76f57728c5ae20a82bda1fc195c28c5 (diff)
downloadnixpkgs-5a5def3753f050ba104ccd160d1cba501ad577ff.tar
nixpkgs-5a5def3753f050ba104ccd160d1cba501ad577ff.tar.gz
nixpkgs-5a5def3753f050ba104ccd160d1cba501ad577ff.tar.bz2
nixpkgs-5a5def3753f050ba104ccd160d1cba501ad577ff.tar.lz
nixpkgs-5a5def3753f050ba104ccd160d1cba501ad577ff.tar.xz
nixpkgs-5a5def3753f050ba104ccd160d1cba501ad577ff.tar.zst
nixpkgs-5a5def3753f050ba104ccd160d1cba501ad577ff.zip
munge: fix module munge.key permissions from 0700 -> 0400 readonly
-rw-r--r--nixos/modules/services/security/munge.nix2
1 files changed, 1 insertions, 1 deletions
diff --git a/nixos/modules/services/security/munge.nix b/nixos/modules/services/security/munge.nix
index fda864f2c30..504bc66c6d1 100644
--- a/nixos/modules/services/security/munge.nix
+++ b/nixos/modules/services/security/munge.nix
@@ -50,7 +50,7 @@ in
       path = [ pkgs.munge pkgs.coreutils ];
 
       preStart = ''
-        chmod 0700 ${cfg.password}
+        chmod 0400 ${cfg.password}
         mkdir -p /var/lib/munge -m 0711
         chown -R munge:munge /var/lib/munge
         mkdir -p /run/munge -m 0755