[Mailman-Users] Group id Catch-22 after list move

Todd Green tag at cs.utah.edu
Mon Apr 7 09:03:12 CEST 2003


Yes, but the man page doesn't cover setgid scripts.  Do a test of
creating a simple script that prints out the {e}gid and make the script
setgid to mailman.  In our case it runs as the egid of mailman, not as
the group of the alias file.

While we're talking about uid's and indirectly security, is there any
reason why mailman wants all the list dirs and files readable by others?
This lets anyone with local filesystem access dump the list databases.

Todd





More information about the Mailman-Users mailing list