From 927efbbbbb1477658a350d4aa2ba49d6d2d2842b Mon Sep 17 00:00:00 2001 From: Jameson Graef Rollins Date: Sun, 29 Jun 2008 01:38:34 -0400 Subject: More work on priviledge separation for host/authentication keyring. Working now using dkg's new method with trust signatures. Implement better return codes for functions. Cleanup of functions. --- debian/monkeysphere.postinst | 29 +++++++++++++++++++++++------ 1 file changed, 23 insertions(+), 6 deletions(-) (limited to 'debian/monkeysphere.postinst') diff --git a/debian/monkeysphere.postinst b/debian/monkeysphere.postinst index 50eaefa..87fbe12 100755 --- a/debian/monkeysphere.postinst +++ b/debian/monkeysphere.postinst @@ -5,13 +5,30 @@ # Author: Jameson Rollins # (c) 2008 +VARLIB="/var/lib/monkeysphere" + if ! getent passwd monkeysphere >/dev/null ; then echo "adding monkeysphere user..." - adduser --quiet --system --no-create-home --home '/var/lib/monkeysphere' \ - --shell '/bin/sh' --gecos 'monkeysphere authentication user,,,' monkeysphere + adduser --quiet --system --no-create-home --group \ + --home '/var/lib/monkeysphere' \ + --shell '/bin/sh' \ + --gecos 'monkeysphere authentication user,,,' \ + monkeysphere fi -# install host gnupg home directories -install --mode 700 -d /var/lib/monkeysphere/gnupg-host -# install authentication gnupg home directories -install --mode 700 --owner monkeysphere -d /var/lib/monkeysphere/gnupg-authentication +# install host gnupg home directory +install --owner root --group monkeysphere --mode 750 -d "$VARLIB"/gnupg-host +# install host gpg.conf +cat < "$VARLIB"/gnupg-host/gpg.conf +list-options show-uid-validity +EOF + +# install authentication gnupg home directory +install --owner monkeysphere --group monkeysphere --mode 700 -d "$VARLIB"/gnupg-authentication +# install authentication gpg.conf +cat < "$VARLIB"/gnupg-authentication/gpg.conf +list-options show-uid-validity +primary-keyring ${VARLIB}/gnupg-authentication/pubring.gpg +keyring ${VARLIB}/gnupg-host/pubring.gpg +EOF +chown monkeysphere:monkeysphere "$VARLIB"/gnupg-authentication/gpg.conf -- cgit v1.2.3