From cdd2eb2099098d3d5f95074ee2c0a32ea809be12 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Niels=20M=C3=B6ller?= <nisse@lysator.liu.se> Date: Wed, 2 Oct 2002 20:44:17 +0200 Subject: [PATCH] (main): Comment on the lax security of the private key file. Rev: src/nettle/examples/rsa-keygen.c:1.6 --- examples/rsa-keygen.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/examples/rsa-keygen.c b/examples/rsa-keygen.c index af33b231..fc4176c3 100644 --- a/examples/rsa-keygen.c +++ b/examples/rsa-keygen.c @@ -143,6 +143,8 @@ main(int argc, char **argv) return EXIT_FAILURE; } + /* NOTE: This doesn't set up paranoid access restrictions on the + * private key file, like a serious key generation tool would do. */ if (!write_file(priv_name, priv_buffer.size, priv_buffer.contents)) { werror("Failed to write private key: %s\n", -- GitLab