Re: [chrony-users] Chrony permissions question. |
[ Thread Index |
Date Index
| More chrony.tuxfamily.org/chrony-users Archives
]
- To: chrony-users@xxxxxxxxxxxxxxxxxxxx
- Subject: Re: [chrony-users] Chrony permissions question.
- From: Miroslav Lichvar <mlichvar@xxxxxxxxxx>
- Date: Thu, 2 Jan 2020 09:36:26 +0100
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1577954191; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=HvQ8MFcanmOGBs+hGv2w9GzOQDVG6tmImx//veMkJ1Q=; b=CyUxLe5n06yxeZ++jXX6LvM+oaEfQ8PXEFqJE+NmOEeeTQgKuDc0xAXR2+0Fzc6jHHs+JK zxBp1UOukH98sZfPVHHyNiSGWCm68yFF/GFrsenUAZUmte6VGPCp0IwXcTR4qCzWXK5ypD 721E51lu6TxSVTn2EjU81r3sdGosHNM=
On Fri, Dec 20, 2019 at 04:30:52PM +0000, Kohr, Alexander wrote:
> I know in RHEL 7 the default location of the drift file sis the home directory of /var/lib/chrony. (I also know it is the recommended location for some other files if they are enabled in the chrony configuration.)
> Is there a reasons that the chrony home directory is /var/lib/chrony instead of something else, that does not contain the drift file?
The package contains just two directories, /var/lib/chrony and
/var/log/chrony. The former seems like a better "home" directory to
me. When I look in /etc/passwd, there are quite a few other daemons
that have a home directory in /var/lib. If it was changed to /, it
would still be readable by everyone.
> If so is there a reason that the chrony home directory permission are 755 instead of 750 or 700?
The reason is that it contains files that could be useful to all users
of the system, e.g. to read the drift of the system clock, or see that
the daemon is still working.
--
Miroslav Lichvar
--
To unsubscribe email chrony-users-request@xxxxxxxxxxxxxxxxxxxx
with "unsubscribe" in the subject.
For help email chrony-users-request@xxxxxxxxxxxxxxxxxxxx
with "help" in the subject.
Trouble? Email listmaster@xxxxxxxxxxxxxxxxxxxx.