Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-30-2009, 03:04 AM
Junior Member
 
Posts: 6
Default [SOLVED] security: SSL private key readable on file system

Hi all,

we're using Release 5.0.16_GA_2921.UBUNTU8 UBUNTU8 FOSS edition and I want to install a Thawte SSL123 certificate. Generating the CSR, I've seen that the files in the directory /opt/zimbra/ssl/zimbra/commercial have very generous access rights:

root@XYZ:/opt/zimbra/ssl/zimbra/commercial# ls -axl
total 16
drwxr----- 2 zimbra zimbra 4096 Jun 13 16:50 .
drwxr----- 5 zimbra zimbra 4096 May 21 20:48 ..
-rw-r--r-- 1 root root 704 Jul 27 11:50 commercial.csr
-rw-r--r-- 1 root root 891 Jul 27 11:50 commercial.key

Isn't this a security hole, or am I misunderstanding something here?

Best regards
Florian
Reply With Quote
  #2 (permalink)  
Old 07-30-2009, 08:13 AM
Outstanding Member
 
Posts: 708
Default

Since . is only accessible to zimbra, no, it isn't.
Reply With Quote
  #3 (permalink)  
Old 07-30-2009, 08:35 AM
Starter Member
 
Posts: 1
Default

Hello,

one small comment / explanation for florianh.

"rw-r--r-- 1 root root 891 Jul 27 11:50 commercial.key" means readable for all
but "drwxr----- 5 zimbra zimbra 4096 May 21 20:48 .." means only zimbra and root can go there to read. No other user can change in that directory to read.

kr Georg
Reply With Quote
  #4 (permalink)  
Old 07-30-2009, 08:37 AM
Junior Member
 
Posts: 6
Default

Oops... you're right! My fault!
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.