-
Notifications
You must be signed in to change notification settings - Fork 41
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Check for OOB permission changes to PKI on disk every run.
If the permissions has changed, the consuming service may not be able to access it- thus trigger a regeneration in that case so the permissions get properly updated. Note that this *can* lead to a war of certmgr trying to enforce permissions it has been told to enforce, and an external SCM trying to change the permissions. This is inherintly racy and wrong either way- and certmgr has no way to know if the service actually was able to use the PKI- thus the only option is to just force a regen.
- Loading branch information
Showing
2 changed files
with
35 additions
and
11 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters