[Mailman-Developers] [Fwd: [ mailman-Bugs-1188133 ] CGI group id not properly tested]

Nigel Metheringham Nigel.Metheringham at dev.intechnology.co.uk
Mon Apr 25 10:53:35 CEST 2005


On Sun, 2005-04-24 at 16:16 -0400, Barry Warsaw wrote:
> BTW, note that Postfix generally isn't susceptible to this
> misunderstanding because Postfix will run its mail programs using the
> user and group owner of the alias file the filter program is defined
> in.  Because the typical Postfix+Mailman installation is using the
> /usr/local/mailman/data/aliases.db file that is group owned by mailman,
> --with-mail-gid=mailman /is/ the right value to use.

Similar arrangements exist with exim.  The normal policy with the
exim/Mailman configuration is to set the invoking uid/gid for the
mailman wrapper suit whatever mailman was built for.  [This is
particularly useful when you are using a packaged mailman, which was
probably built by someone considering how things work for sendmail]

	Nigel.
-- 
[ Nigel Metheringham           Nigel.Metheringham at InTechnology.co.uk ]
[ - Comments in this message are my own and not ITO opinion/policy - ]




More information about the Mailman-Developers mailing list