Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

keylime-agent.conf should default to run_as = keylime:tss #439

Closed
kkaarreell opened this issue Aug 23, 2022 · 2 comments
Closed

keylime-agent.conf should default to run_as = keylime:tss #439

kkaarreell opened this issue Aug 23, 2022 · 2 comments

Comments

@kkaarreell
Copy link
Contributor

kkaarreell commented Aug 23, 2022

Rust agent should be dropping privileges by default, making it more secure.
While Python agent has run_as = we should strive for more secure defaults for the rust agent.

@kkaarreell kkaarreell changed the title keylime-agent.conf should default to run_as = keylime keylime-agent.conf should default to run_as = keylime:tss Aug 23, 2022
@kkaarreell
Copy link
Contributor Author

I am sorry, I got confused by Fedora defaults and falsely assumed that Python agent uses keylime:tss. I have therefore updated the issue description.

@ansasaki
Copy link
Contributor

This was fixed by #449
The new default for run_as is keylime:tss

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants