aboutsummaryrefslogtreecommitdiffstats
path: root/contrib
diff options
context:
space:
mode:
authortilghman <tilghman@f38db490-d61c-443f-a65b-d21fe96a405b>2008-04-08 16:54:21 +0000
committertilghman <tilghman@f38db490-d61c-443f-a65b-d21fe96a405b>2008-04-08 16:54:21 +0000
commit66ae197ec56500a456552866b5b3683b41cf12db (patch)
tree28860c040dd99df13e1cc8456668370040fb280a /contrib
parentea4ffbc5c60d55aaccce732def7bec227f3eda34 (diff)
Merged revisions 113399 via svnmerge from
https://origsvn.digium.com/svn/asterisk/branches/1.4 ........ r113399 | tilghman | 2008-04-08 11:51:28 -0500 (Tue, 08 Apr 2008) | 6 lines Add security note on astgenkey's manpage. (closes issue #12373) Reported by: lmamane Patches: 20080406__bug12373.diff.txt uploaded by Corydon76 (license 14) ........ git-svn-id: http://svn.digium.com/svn/asterisk/trunk@113400 f38db490-d61c-443f-a65b-d21fe96a405b
Diffstat (limited to 'contrib')
-rw-r--r--contrib/scripts/astgenkey.815
1 files changed, 15 insertions, 0 deletions
diff --git a/contrib/scripts/astgenkey.8 b/contrib/scripts/astgenkey.8
index 8f8325982..328a4d259 100644
--- a/contrib/scripts/astgenkey.8
+++ b/contrib/scripts/astgenkey.8
@@ -109,6 +109,21 @@ Run quietly.
Don't encrypt the private key.
.RE
+.SH SECURITY
+The keys are created, using the umask of the user running the command.
+To create the keys in a secure manner, you should check to ensure that
+your umask is first set to disallow the private key from being world-
+readable, such as with the following commands:
+
+.I umask 0066
+
+.I astgenkey yourkey
+
+And then make the key accessible to Asterisk (assuming you run it as
+user "asterisk").
+
+ chown asterisk /var/lib/asterisk/keys/yourname.*
+
.SH FILES
.I /var/lib/asterisk/keys
.RS