Great Circle Associates Majordomo-Users
(January 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: File modes
From: Jason L Tibbitts III <tibbs @ hpc . uh . edu>
Date: 03 Jan 1997 19:39:38 -0600
To: Bill <bill @ wagill . com>
Cc: majordomo-users @ GreatCircle . COM
In-reply-to: Bill's message of Fri, 03 Jan 1997 16:36:59 -0800
References: <1.5.4.32.19970104003659.0066d420@mail.nas.com>

>>>>> "B" == Bill  <bill@wagill.com> writes:

B> The NEWLIST documentation in the Majordomo distribution indicates that
B> the <list-name> file should be mode 664.

This is basically required unless you have your groups set up carefully.
It's for the same reason $homedir being 751.

B> Wouldn't this allow anyone in the world to view a list's members' e-mail
B> addresses? (thus defeating any other security measures in the
B> majordomo.cf file).

Yes, but it also allows the MTA (which sometimes runs permissionless) to
actually read the files so that it can send mail to the addresses in them.

If your mailer allows, you can go all the way down to 600.  You can also
have 710 on $homedir and likewise tight permissions on everything else.
The trick is to make sure your group memberships are such that your mailer
can always get to the files.  This is of course heavily dependent on your
MTA (sometimes even down to specific versions), which is why the Majordomo
documentation is somewhat vague.  If you want to deviate, you should know
what you're doing or be willing to experiment (i.e. do it before you have
lists that need to stay up).

 - J<


References:
Indexed By Date Previous: File modes
From: Bill <bill@wagill.com>
Next: [no subject]
From: Unknown
Indexed By Thread Previous: File modes
From: Bill <bill@wagill.com>
Next: Re: File modes
From: Bill <bill@wagill.com>

Google
 
Search Internet Search www.greatcircle.com