Skip to content

Commit b28b9db

Browse files
cgwaltersbluca
authored andcommitted
docs/CREDENTIALS: Don't write authorized_keys with executable bits
No reason to make this file executable. (cherry picked from commit 47374e0) (cherry picked from commit 30f9309) (cherry picked from commit e09ef87)
1 parent 850d3d7 commit b28b9db

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

docs/CREDENTIALS.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -409,7 +409,7 @@ qemu-system-x86_64 \
409409
-device scsi-hd,drive=hd,bootindex=1 \
410410
-device vhost-vsock-pci,id=vhost-vsock-pci0,guest-cid=42 \
411411
-smbios type=11,value=io.systemd.credential:vmm.notify_socket=vsock:2:1234 \
412-
-smbios type=11,value=io.systemd.credential.binary:tmpfiles.extra=$(echo "f~ /root/.ssh/authorized_keys 700 root root - $(ssh-add -L | base64 -w 0)" | base64 -w 0)
412+
-smbios type=11,value=io.systemd.credential.binary:tmpfiles.extra=$(echo "f~ /root/.ssh/authorized_keys 600 root root - $(ssh-add -L | base64 -w 0)" | base64 -w 0)
413413
```
414414

415415
A process on the host can listen for the notification, for example:

0 commit comments

Comments
 (0)