<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwiz.co.uk/rss_namespace/">
 <channel>
  <title>Identity Finder Forums : LaunchDaemon plist ownership and permissions</title>
  <link>http://www.identityfinder.com/forum/</link>
  <description>This is an XML content feed of; Identity Finder Forums : Identity Finder for Mac : LaunchDaemon plist ownership and permissions</description>
  <pubDate>Tue, 21 May 2013 12:00:54 +0000</pubDate>
  <lastBuildDate>Tue, 01 Mar 2011 14:51:56 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 10.14</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>www.identityfinder.com/forum/RSS_post_feed.asp?TID=113</WebWizForums:feedURL>
  <item>
   <title>LaunchDaemon plist ownership and permissions : Thanks, we look forward to this...</title>
   <link>http://www.identityfinder.com/forum/forum_posts.asp?TID=113&amp;PID=251&amp;title=launchdaemon-plist-ownership-and-permissions#251</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.identityfinder.com/forum/member_profile.asp?PF=47">RITJeremy</a><br /><strong>Subject:</strong> 113<br /><strong>Posted:</strong> 01 Mar 2011 at 2:51pm<br /><br />Thanks, we look forward to this change!]]>
   </description>
   <pubDate>Tue, 01 Mar 2011 14:51:56 +0000</pubDate>
   <guid isPermaLink="true">http://www.identityfinder.com/forum/forum_posts.asp?TID=113&amp;PID=251&amp;title=launchdaemon-plist-ownership-and-permissions#251</guid>
  </item> 
  <item>
   <title>LaunchDaemon plist ownership and permissions : Thank you for the suggestion....</title>
   <link>http://www.identityfinder.com/forum/forum_posts.asp?TID=113&amp;PID=246&amp;title=launchdaemon-plist-ownership-and-permissions#246</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.identityfinder.com/forum/member_profile.asp?PF=20">Product Management</a><br /><strong>Subject:</strong> 113<br /><strong>Posted:</strong> 01 Mar 2011 at 2:47pm<br /><br />Thank you for the suggestion.&nbsp; The launchedaemon will be set to root:wheel and 644.]]>
   </description>
   <pubDate>Tue, 01 Mar 2011 14:47:47 +0000</pubDate>
   <guid isPermaLink="true">http://www.identityfinder.com/forum/forum_posts.asp?TID=113&amp;PID=246&amp;title=launchdaemon-plist-ownership-and-permissions#246</guid>
  </item> 
  <item>
   <title>LaunchDaemon plist ownership and permissions : The current (Feb 17 but listed...</title>
   <link>http://www.identityfinder.com/forum/forum_posts.asp?TID=113&amp;PID=241&amp;title=launchdaemon-plist-ownership-and-permissions#241</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.identityfinder.com/forum/member_profile.asp?PF=47">RITJeremy</a><br /><strong>Subject:</strong> 113<br /><strong>Posted:</strong> 25 Feb 2011 at 11:57am<br /><br />The current (Feb 17 but listed as Feb 15 on the Web site) postinstall installer script copies the LaunchDaemon plist and sets the ownership/permissions to <b>root:admin</b> and <b>755</b>.<div><br></div><div>My understanding of launchd is that the plist should be set to root:wheel and 644.</div><div><br></div><div>Apple TN2083 states:</div><div><br></div><blockquote ="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: n&#111;ne; padding: 0px;"><div>When you install your daemon, make sure that you set the file system permissions correctly. Apple recommends that daemons be owned by root, have an owning group of wheel, and use permissions 755 (rwxr-xr-x) for executables and directories, and 644 (rw-r--r--) for files. In addition, every directory from your daemon up to the root directory must be owned by root and only writable by the owner (or owned by root and sticky). If you don't do this correctly, a non-admin user might be able to escalate their privileges by modifying your daemon (or shuffling it aside).</div></blockquote><br><div>Every other LaunchDaemon stored in the local domain by other vendors that I have encountered uses root:wheel and 644.</div><div><br></div><div>On the launchd-dev mailing list, I’ve seen responses that the plist should be fine as long as it is owned by root and only writable by root. However, I believe it would still be a good practice to change the plist to <b>root:wheel</b> ownership and <b>644</b> permissions in the IDF Mac Edition installer build script.</div>]]>
   </description>
   <pubDate>Fri, 25 Feb 2011 11:57:38 +0000</pubDate>
   <guid isPermaLink="true">http://www.identityfinder.com/forum/forum_posts.asp?TID=113&amp;PID=241&amp;title=launchdaemon-plist-ownership-and-permissions#241</guid>
  </item> 
 </channel>
</rss>