kentpeacock / rpms / openssh

Forked from rpms/openssh 2 years ago
Clone
8f2528
diff -up openssh-6.6p1/authfile.c.keyperm openssh-6.6p1/authfile.c
8f2528
--- openssh-6.6p1/authfile.c.keyperm	2014-02-04 01:20:15.000000000 +0100
8f2528
+++ openssh-6.6p1/authfile.c	2014-05-05 15:20:43.075246776 +0200
8f2528
@@ -54,6 +54,7 @@
8f2528
 
8f2528
 #include <errno.h>
8f2528
 #include <fcntl.h>
8f2528
+#include <grp.h>
8f2528
 #include <stdio.h>
8f2528
 #include <stdarg.h>
8f2528
 #include <stdlib.h>
8f2528
@@ -979,6 +980,13 @@ key_perm_ok(int fd, const char *filename
8f2528
 #ifdef HAVE_CYGWIN
8f2528
 	if (check_ntsec(filename))
8f2528
 #endif
8f2528
+	if (st.st_mode & 040) {
8f2528
+		struct group *gr;
8f2528
+
8f2528
+		if ((gr = getgrnam("ssh_keys")) && (st.st_gid == gr->gr_gid))
8f2528
+			st.st_mode &= ~040;
8f2528
+	}
8f2528
+
8f2528
 	if ((st.st_uid == getuid()) && (st.st_mode & 077) != 0) {
8f2528
 		error("@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@");
8f2528
 		error("@         WARNING: UNPROTECTED PRIVATE KEY FILE!          @");