HomeFreeBSD

Restrict default /root permissions

Description

Restrict default /root permissions

Remove world-readability from the root directory. Sensitive information may be
stored in /root and we diverge here from normative administrative practice, as
well as installation defaults of other Unix-alikes. The wheel group is still
permitted to read the directory.

750 is no more restrictive than defaults for the rest of the open source
Unix-alike world. In particular, Ben Woods surveyed DragonFly, NetBSD,
OpenBSD, ArchLinux, CentOS, Debian, Fedora, Slackware, and Ubuntu. None have a
world-readable /root by default.

Submitted by: Gordon Bergling <gbergling AT gmail.com>
Reviewed by: ian, myself
Discussed with: emaste (informal approval)
Relnotes: sure?
Differential Revision: https://reviews.freebsd.org/D23392

Details

Provenance
cemAuthored on
Reviewer
ian
Differential Revision
D23392: More Secure Permissions for /root
Parents
rS361790: ifconfig(8): make it possible to filter output by interface group.
Branches
Unknown
Tags
Unknown