Browse Source

Merge pull request #170 from glerchundi/fix-encryption-keys-leak

secfix: encryption keys (with iv) were leaked in travis logs
Gorka Lerchundi Osa 9 years ago
parent
commit
ee01e1bb63
2 changed files with 4 additions and 3 deletions
  1. 4 3
      .travis.yml.before_install
  2. BIN
      keys.tar.xz.enc

+ 4 - 3
.travis.yml.before_install

@@ -1,12 +1,13 @@
 #!/bin/bash
 set -e
-set -x
+set +x
 
 # extract signing keys if available, exit otherwise.
-if [ -z "$encrypted_b8cbf04cae0b_key" ] ; then
+if [[ -z "$OPENSSL_KEY" || -z "$OPENSSL_IV" ]] ; then
     exit 0
 fi
-openssl aes-256-cbc -K $encrypted_b8cbf04cae0b_key -iv $encrypted_b8cbf04cae0b_iv -in keys.tar.xz.enc -out keys.tar.xz -d
+
+openssl aes-256-cbc -K $OPENSSL_KEY -iv $OPENSSL_IV -in keys.tar.xz.enc -out keys.tar.xz -d
 tar xf keys.tar.xz
 gpg --import keys/public.key
 gpg --allow-secret-key-import --import keys/private.key

BIN
keys.tar.xz.enc