More strict fcache rules
commit2a565482f491621fe8a906c990aa890be153a906
authorLove Hornquist Astrand <lha@h5l.org>
Thu, 11 Jul 2013 17:29:04 +0000 (11 19:29 +0200)
committerLove Hornquist Astrand <lha@h5l.org>
Thu, 11 Jul 2013 17:29:04 +0000 (11 19:29 +0200)
treeaabce02ead37fa4989a593430787226d3ba2d3c2
parentefe81b12ef6dcd23baa0103a8a49af4dcf54d588
More strict fcache rules

- use O_NOFOLLOW
- be more strict not to follow symlinks
- require cache files to be owned by the user
- have sane permissions (not group/other readable)
lib/krb5/fcache.c