This commit is a bare-bones stable/mitaka backport of the fix for
CVE-2016-7404. It only retains
* Permissions for /etc/sysconfig/heat-params inside Magnum
created instances are tightened to 0600 (used to be 0755).
from the original patch. This was done for two reasons:
* Since stable/mitaka only passes tokens (which expire eventually)
an attacker would have to gain access to the instance within
a very short time window (the token expiration time).
* Backporting the remaining changes would have required
backporting the trusts infrastructure that was only
completed in stable/newton. This would mean a considerable
change in the stable/mitaka default behaviour.
Please note, that this change does not apply apply to existing
clusters. They will have to be deleted and rebuilt to benefit
from these changes.
(cherry picked from commit 0bb0d6486d)
Change-Id: I329d29cdcce2225f8aa5b57852e6a37d4f8aaa3e