summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--vps-builder.scm1
1 files changed, 1 insertions, 0 deletions
diff --git a/vps-builder.scm b/vps-builder.scm
index da27135..cd6d8e4 100644
--- a/vps-builder.scm
+++ b/vps-builder.scm
@@ -273,6 +273,7 @@
;; password would be *locked*, which means "passwd" will prompt
;; for a password, but there's none, so it can't be changed.
(run* (chroot ,root-dir useradd -p "" -m -G ,cs-groups ,user))
+ (change-file-mode ~ #o700) ; Lock down homedir
(install-directory root-dir ~/.ssh user user #o700)
(install-file root-dir pubkey
(make-pathname ~/.ssh "authorized_keys")