certs/Makefile: Run key generation with a stricter umask (fixes a race condition)
authorKim Alvefur <zash@zash.se>
Wed, 23 Dec 2015 12:07:03 +0100
changeset 7033 b5bc9f77f096
parent 7032 b2d160baa957
child 7034 89221daefae9
child 7054 ecfa474ff570
certs/Makefile: Run key generation with a stricter umask (fixes a race condition)
certs/Makefile
--- a/certs/Makefile	Tue Dec 22 14:15:09 2015 +0000
+++ b/certs/Makefile	Wed Dec 23 12:07:03 2015 +0100
@@ -26,5 +26,5 @@
 	sed 's,example\.com,$*,g' openssl.cnf > $@
 
 %.key:
-	openssl genrsa $(keysize) > $@
-	@chmod 400 $@
+	umask 0077 && openssl genrsa -out $@ $(keysize)
+	@chmod 400 $@ -c