Your message dated Sun, 3 Jan 2021 02:12:06 +0100
with message-id <[email protected]>
and subject line Re: Bug#341205: README's highly confused and wrong
configurations
has caused the Debian Bug report #341205,
regarding courier-webadmin: unsecureok allows webadmin for everybody
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
341205: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=341205
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: courier-webadmin
Version: 0.47-11
Severity: important
A server is generally administred by a remote user.
creating the "unsecureok" files allows webadmin to everybody.
Solution:
Specify by a comma-separated, comma-ended list
the IP addresses of valid administrators
-- System Information:
Debian Release: testing/unstable
APT prefers testing
APT policy: (500, 'testing'), (500, 'stable')
Architecture: i386 (i586)
Shell: /bin/sh linked to /bin/bash
Kernel: Linux 2.4.23
Locale: LANG=fr_FR@euro, LC_CTYPE=fr_FR@euro (charmap=ISO-8859-15) (ignored:
LC_ALL set to fr_FR@euro)
Versions of packages courier-webadmin depends on:
ii apache [httpd] 1.3.31-5 Versatile, high-performance HTTP s
ii apache-perl [httpd] 1.3.31-5 Versatile, high-performance HTTP s
ii apache-ssl [httpd] 1.3.31-5 Versatile, high-performance HTTP s
ii courier-base 0.47-11 Courier Mail Server - Base system
courier-webadmin recommends no packages.
-- debconf information:
* courier-webadmin/install-cgi: true
--- End Message ---
--- Begin Message ---
Control: tags -1 -pending +wontfix
Hi,
please ignore my last message inadvertently sent here.
My answer to this issue here: yes, creating an "unsecureok" file is -
well - pretty unsecure. I do not recommend using that in a production
setup.
However, the original proposal was:
Solution:
Specify by a comma-separated, comma-ended list
the IP addresses of valid administrators
This clearly is not secure, either, and won't be implemented that way.
I don't think this is a documentation issue, as the OP actually found
the "unsecureok" trick.
Regards
Markus
--- End Message ---