You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
While using the OpenKruise 1.5.4 image, I discovered numerous certificate private key files with 644 permissions within the image. I am eager to understand the specific purpose and significance of these private key files. Additionally, I noticed that the protection.log file also has 644 permissions, and I would like to inquire whether adjusting its permissions to 640 could further enhance system security.May I ask if there is any plan to address these issues?
The text was updated successfully, but these errors were encountered:
these files belongs to the alpine base image, it is not enough to enhance the system security by just changing the permission of these files. In stead, openkruise can switch to use distroless base image. You're welcome to submit patch to change the base image.
While using the OpenKruise 1.5.4 image, I discovered numerous certificate private key files with 644 permissions within the image. I am eager to understand the specific purpose and significance of these private key files. Additionally, I noticed that the protection.log file also has 644 permissions, and I would like to inquire whether adjusting its permissions to 640 could further enhance system security.May I ask if there is any plan to address these issues?
The text was updated successfully, but these errors were encountered: