Great Circle Associates Majordomo-Workers
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Enhancement suggestion.
From: Brock Rozen <brozen @ netvoyage . net>
Date: Wed, 17 Jul 1996 14:00:42 -0700 (PDT)
To: Sean Kamath <kamath @ pogo . WV . TEK . COM>
Cc: Alan Millar <amillar @ bolis . COM>
In-reply-to: <9607172021.AA05943@catenary.WV.TEK.COM>
Reply-to: brozen @ netvoyage . net

On Wed, 17 Jul 1996, Sean Kamath wrote:

> First, a comment.  I'm not suggesting much of a change.  Right now,
> there's no verification that a command being sent in comes from
> "list-owner", and I'm not proposing it start.  It's merely for list
> notification of subscriptions and the like.  One thing we want to do
> is send mail to all the list's owners, and say "hay, you own this
> list.  Do you still need it?"-type of thing.  So, we need it
> reasonably current.  Soooo...

You can send messages to list-owner and it will go to all of the people
who are listed in the aliases file. Same deal...

> Say I'm owner owner of "foobar".  But I get transfered to our India
> facility, and will now work on the "bar" projects.  Joanie, the new
> head of the bar command, needs to assume ownership of the foobar
> mailing list.  I send the command

Right now if there's a security breach I still maintain overall command of
the lists and all stuff still eventually comes back to owner-list. If the
owner is listed in the config file then the hacker would have TOTAL
control of the lists.

The current way means that something is further beyond reach of hacking
majordomo. The hacker would have to actually get in to the system.

> 
> approve pw newowner foobar joanie@pogo.wv.tek.com

What about multiple owners?

I know listproc does this by using an add and remove feature, instead of
replacing the owners.

> Of course, I may not know of what I spean, but it seem that it can't be
> *that* hard to replace the calls to
> 
> 	&sendmail(NOTICE, "$list-approval")
> 
> to
> 
> 	&sendmail(NOTICE, $main'config_opts{$clean_list, "owner"));
> 
> Having said all that, I suppose I ought to go off and impliment it
> myself, eh? ;-)

This is a major design change, IMO. I'm interested in seeing a patch
before totally committing to it. It's something that I'm personally,
willing to consider -- and with that, supporting you in trying to get it
changed, if I like it.

Thanks,

 ------------------------------------------------------------------------- 
 | Brock Rozen | brozen@netvoyage.net | http://www.netvoyage.net/~brozen | 
 ------------------------------------------------------------------------- 



References:
Indexed By Date Previous: Re: Enhancement suggestion.
From: "James B. Byrne" <byrnejb@harte-lyne.ca>
Next: Re: Enhancement suggestion.
From: "Alan Millar" <amillar@bolis.com>
Indexed By Thread Previous: Re: Enhancement suggestion.
From: "James B. Byrne" <byrnejb@harte-lyne.ca>
Next: Re: Enhancement suggestion.
From: "Alan Millar" <amillar@bolis.com>

Google
 
Search Internet Search www.greatcircle.com