Patch: controlling the location of server-side SSL files

CommitFest 2012-01
Topic Security
Patch Status Committed
Author Peter Eisentraut
Reviewers Susanne Ebrecht
Committer Nobody
Close Date 2012-02-22
Patch by petere on 2012-01-14 01:50:34 PM: Initial version.
Review by miracee on 2012-01-17 09:11:41 AM: Patch is ok besides one small thing in docs:

In runtime.sgml:
must disallow any access to world or group; achieve this by the command
chmod 0600 server.key

I fear modern Linux users won't understand chmod 0600.

I would write something like this:
achieve this by either the command
chmod 0600 server.key or the command chmod u=rw server.key

