From 2a770a93b1ad1ab9b19b5676b059c8d21ff28940 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jens=20Mei=C3=9Fner?= Date: Mon, 23 Nov 2020 20:32:24 +0100 Subject: [PATCH] Protect only private keys and leave certificates world readable. --- lib/Froxlor/Cron/Http/DomainSSL.php | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/lib/Froxlor/Cron/Http/DomainSSL.php b/lib/Froxlor/Cron/Http/DomainSSL.php index 4ccc410d..40d4304e 100644 --- a/lib/Froxlor/Cron/Http/DomainSSL.php +++ b/lib/Froxlor/Cron/Http/DomainSSL.php @@ -105,7 +105,9 @@ class DomainSSL $_fh = fopen($filename, 'w'); fwrite($_fh, $dom_certs[$type]); fclose($_fh); - chmod($filename, 0600); + if ($type == 'ssl_key_file') { + chmod($filename, 0600); + } } } // override corresponding array values