cloud-gov / cg-atlas

Repository hosting issues and artifacts related to operations of the cloud.gov platform
Creative Commons Zero v1.0 Universal
3 stars 1 forks source link

Tripwire needs security enhancements #159

Open sharms opened 7 years ago

sharms commented 7 years ago

Currently tripwire job is owned by root however is set to 755 which enables vcap or others to read the job file. Because tripwire is invoked during pre-start to create the vault, the -P and -Q parameters are visible to these users.