mirror of
https://github.com/docker/docker-bench-security.git
synced 2025-02-23 16:36:39 +01:00
444 is read-only
Signed-off-by: Thomas Sjögren <konstruktoid@users.noreply.github.com>
This commit is contained in:
parent
70b8d33cef
commit
3059cef2c3
1 changed files with 3 additions and 3 deletions
|
@ -276,7 +276,7 @@ if [ -d "$directory" ]; then
|
||||||
fail=0
|
fail=0
|
||||||
perms=$(ls -lL "$directory"/*.crt | awk '{print $1}')
|
perms=$(ls -lL "$directory"/*.crt | awk '{print $1}')
|
||||||
for p in $perms; do
|
for p in $perms; do
|
||||||
if [ "$p" != "-rw-r--r--." -a "$p" = "-rw-------." ]; then
|
if [ "$p" != "-r--r--r--." -a "$p" = "-r--------." ]; then
|
||||||
fail=1
|
fail=1
|
||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
|
@ -311,7 +311,7 @@ check_3_20="3.20 - Verify that TLS CA certificate file permissions are set to 44
|
||||||
tlscacert=$(pgrep -lf docker | sed -n 's/.*tlscacert=\([^s]\)/\1/p' | cut -d " " -f 1)
|
tlscacert=$(pgrep -lf docker | sed -n 's/.*tlscacert=\([^s]\)/\1/p' | cut -d " " -f 1)
|
||||||
if [ -f "$tlscacert" ]; then
|
if [ -f "$tlscacert" ]; then
|
||||||
perms=$(ls -ld "$tlscacert" | awk '{print $1}')
|
perms=$(ls -ld "$tlscacert" | awk '{print $1}')
|
||||||
if [ "$perms" = "-rw-r--r--" ]; then
|
if [ "$perms" = "-r--r--r--" ]; then
|
||||||
pass "$check_3_20"
|
pass "$check_3_20"
|
||||||
else
|
else
|
||||||
warn "$check_3_20"
|
warn "$check_3_20"
|
||||||
|
@ -342,7 +342,7 @@ check_3_22="3.22 - Verify that Docker server certificate file permissions are se
|
||||||
tlscacert=$(pgrep -lf docker | sed -n 's/.*tlscert=\([^s]\)/\1/p' | cut -d " " -f 1)
|
tlscacert=$(pgrep -lf docker | sed -n 's/.*tlscert=\([^s]\)/\1/p' | cut -d " " -f 1)
|
||||||
if [ -f "$tlscert" ]; then
|
if [ -f "$tlscert" ]; then
|
||||||
perms=$(ls -ld "$tlscert" | awk '{print $1}')
|
perms=$(ls -ld "$tlscert" | awk '{print $1}')
|
||||||
if [ "$perms" = "-rw-r--r--" ]; then
|
if [ "$perms" = "-r--r--r--" ]; then
|
||||||
pass "$check_3_22"
|
pass "$check_3_22"
|
||||||
else
|
else
|
||||||
warn "$check_3_22"
|
warn "$check_3_22"
|
||||||
|
|
Loading…
Reference in a new issue