-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi Holger,

Thanks for testing the package against policy 6.8 and finding this bug
but I'm not sure if this bug applies to us.

On postinstall a user is created (needed for pdns and pdns-recursor) to
run both daemons under. Here is that unowned file created.

This user won't be removed on post removal because of security, see the
scenario:

User created (by pdns package)
Pdns creates files under pdns user
User removed (by pdns package)

Now we have files which have an unknown uid on the system.

System admin creates a user (by accident with the same uid as pdns had
before)
Now this user is able to read / write those files.

That's not what we want to happen, I can't remember exactly the bug
where this is told, but that's why we don't remove the user and so we
have a unowned file on the system.

How to proceed on this one ?

Regards,

Matthijs Mohlmann
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAkp+5/IACgkQ2n1ROIkXqbBKjACeIGiJk9snmNm3uSFsd1E+l7Dq
Dp4AnjrZw/ymKa9SBDnUU+nz4WF+UIKK
=5Bon
-----END PGP SIGNATURE-----



-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to