also sprach Micah Anderson <[EMAIL PROTECTED]> [2007.05.20.0114 +0200]:
> If you have people other than root who are writing to
> /etc/backup.d and you have added them to the 'admingroup' in the
> backupninja config, you wont have this problem. 

Yes, I will, because as members of the admingroup, those people will
be able to read and write files, but some ways of editing create new
inodes, which will then be unwantingly owned by the user and no
longer root.

> I am slightly confused because you requested the feature to add
> the 'admingroup' function, included a patch and we fixed the patch
> up and included it (although it introduced some errors that we
> later had to fix, we fixed those), but now you are suggesting we
> through out that enhancement, as well as the original code
> altogether? Or am I missing something here?

The admingroup enhancement was splendid, thanks for that!

Maybe instead of telling you what I want, let me know what the
security enhancement is by requiring that config files be owned by
root instead of just members of the admingroup?

Cheers, and looking forward to EDI.

-- 
 .''`.   martin f. krafft <[EMAIL PROTECTED]>
: :'  :  proud Debian developer, author, administrator, and user
`. `'`   http://people.debian.org/~madduck - http://debiansystem.info
  `-  Debian - when you have better things to do than fixing systems

Attachment: signature.asc
Description: Digital signature (GPG/PGP)

Reply via email to