浏览代码

Be more restrictif on sensu_ssl_client_cert

Be more restrictif with sensu_ssl_client_cert
roumano 7 年之前
父节点
当前提交
f81f034224
共有 1 个文件被更改,包括 1 次插入1 次删除
  1. 1 1
      tasks/ssl.yml

+ 1 - 1
tasks/ssl.yml

@@ -24,7 +24,7 @@
       dest: "{{ sensu_config_path }}/ssl/{{ item.dest }}"
       mode: " {{ item.perm }}"
     with_items:
-      - {src: "{{ sensu_ssl_client_cert }}", dest: cert.pem , perm: "0644" }
+      - {src: "{{ sensu_ssl_client_cert }}", dest: cert.pem , perm: "0640" }
       - {src: "{{ sensu_ssl_client_key }}" , dest: key.pem  , perm: "0640" }
     notify: restart sensu-client service
     when: sensu_ssl_manage_certs