Home page logo

oss-sec logo oss-sec mailing list archives

Postfix incorrect permissions on configurations. Request.
From: Russ Thompson <russ () wildbit com>
Date: Tue, 9 Apr 2013 14:08:20 -0400

Postfix is setting the following permissions by default on Debian Squeeze.  I'm seeing roughly the same on RHEL/CentOS 
6.x, this appears to be a requirement of "sendmail.postfix"  

0755 /etc/postfix
0644 /etc/postfix/*
0755 /etc/postfix-script
0755 /etc/post-install

Which allows all users to execute these scripts and read configurations.  Setting to tighter/more typical permissions 
(i.e 640) results in:  postfix/sendmail[21007]: fatal: open /etc/postfix/main.cf: Permission denied

- Russ

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]