>> The daemon is a HTTP server that is intended to listen for
>> connections from the public internet.
> 
> No, it is not intended to listen on the public internet.

A lot of people use OpenID with blogs and public web sites now - I think
it is very reasonable to assume that people will install the package
with the intention of connecting it to the public internet.

> However, nothing in its documentation suggests otherwise, so this is a
> documentation bug.

Actually, the documentation does say it is alpha code, so it is not too
unreasonable

I really think saslauthd (or Dovecot) is worth looking at though, as a
way to run the gracie process without root privileges.  Is there any
reason you would rule out that possibility?



-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to