From 3eed44907b0befc3962432f14c048fdeeaf69adb Mon Sep 17 00:00:00 2001 From: Guillaume Abrioux Date: Wed, 21 Oct 2020 14:26:57 +0200 Subject: [PATCH] iscsi: fix ownership on iscsi-gateway.cfg This file is currently deployed with '0644' ownership making this file readable by any user on the system. Since it contains sensitive information it should be readable by the owner only. Closes: https://bugzilla.redhat.com/show_bug.cgi?id=1890119 Signed-off-by: Guillaume Abrioux (cherry picked from commit a822f773002a010ebedddcc2c8cd8f5a03dc786a) --- roles/ceph-iscsi-gw/tasks/common.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/roles/ceph-iscsi-gw/tasks/common.yml b/roles/ceph-iscsi-gw/tasks/common.yml index 1117f15c3..3c672aff4 100644 --- a/roles/ceph-iscsi-gw/tasks/common.yml +++ b/roles/ceph-iscsi-gw/tasks/common.yml @@ -44,6 +44,7 @@ dest: /etc/ceph/iscsi-gateway.cfg config_type: ini config_overrides: '{{ iscsi_conf_overrides }}' + mode: "0600" notify: restart ceph rbd-target-api-gw - name: set_fact container_exec_cmd -- 2.47.3