From d6c85a7b6e233c93fc5f1c38188262fbdd5a321c Mon Sep 17 00:00:00 2001 From: Matt Borja Date: Tue, 11 Jul 2017 11:58:37 -0700 Subject: [PATCH] Restrict permissions on config scripts to author Scripts containing potentially sensitive information should be restricted to least privilege required. --- manifests/config.pp | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/manifests/config.pp b/manifests/config.pp index bc71a2f..68b81a5 100644 --- a/manifests/config.pp +++ b/manifests/config.pp @@ -45,7 +45,7 @@ concat { $::couchbase::params::node_init_script: owner => '0', group => '0', - mode => '0655', + mode => '0700', } @@ -83,7 +83,7 @@ concat { $::couchbase::params::cluster_init_script: owner => '0', group => '0', - mode => '0655', + mode => '0700', } concat::fragment { '00_cluster_init_script_header': @@ -114,7 +114,7 @@ concat { $::couchbase::params::cluster_script: owner => '0', group => '0', - mode => '0655', + mode => '0700', } concat::fragment { '00_script_header':