[Authentication] Question about home directory permissions

Stef Walter stefw at redhat.com
Thu Aug 8 07:32:47 PDT 2013


On 31.07.2013 17:11, Scott Dowdle wrote:
> Greetings,
> 
> I'm using Fedora 19.  I see that the oddjob and oddjob-mkhomedir
> packages are responsible for making user home directories if they
> don't exist when the user logs in.
> 
> I read the documentation on the optional /etc/realmd.conf file.  I
> moved stuff from /home to /students with the [users] section and the
> "default-home =" thing.  That works great.  I wasn't sure how to make
> the system notice the change and ended up leaving the domain and
> joining it again.  The documentation doesn't seem to be very clear on
> that but I got it working.

Yes, that was correct.

I've updated the documentation:

http://cgit.freedesktop.org/realmd/realmd/commit/?id=ac98d162c0cd2e9bd43469505a2f6a07cc773f73

> I can login, it makes a homedir where I want... but the permissions
> on it are too open (755).  I do see something that looks like the
> place to put it in:
> 
> /etc/oddjobd.conf.d/oddjobd-mkhomedir.conf
> 
> There are two methods and both pass "-u 0002".  Altering one or both
> of those to other values didn't seem to get me what I wanted... and
> made it where users couldn't access their home dirs anymore.  The
> desired permissions for their homedirs would be 750 or 700.  Maybe
> I'm having a brain fart with my umask values.
> 
> What is the proper way to adjust the homedir permissions and what
> would the values be for the permissions I want?

Hmmm, that's not good. Seems like a bad oddjob default. Since this is
about Fedora defaults, we should file a bug in the Red Hat Bugzilla:

https://bugzilla.redhat.com/show_bug.cgi?id=995097

Stef


More information about the Authentication mailing list