You can subscribe to this list here.
| 2001 |
Jan
(39) |
Feb
(258) |
Mar
(396) |
Apr
(439) |
May
(337) |
Jun
(351) |
Jul
(296) |
Aug
(205) |
Sep
(328) |
Oct
(174) |
Nov
(252) |
Dec
(172) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(213) |
Feb
(194) |
Mar
(337) |
Apr
(314) |
May
(373) |
Jun
(522) |
Jul
(417) |
Aug
(471) |
Sep
(486) |
Oct
(422) |
Nov
(274) |
Dec
(299) |
| 2003 |
Jan
(354) |
Feb
(310) |
Mar
(379) |
Apr
(349) |
May
(388) |
Jun
(218) |
Jul
(368) |
Aug
(340) |
Sep
(222) |
Oct
(176) |
Nov
(214) |
Dec
(211) |
| 2004 |
Jan
(221) |
Feb
(187) |
Mar
(190) |
Apr
(211) |
May
(114) |
Jun
(136) |
Jul
(124) |
Aug
(178) |
Sep
(244) |
Oct
(203) |
Nov
(215) |
Dec
(156) |
| 2005 |
Jan
(334) |
Feb
(268) |
Mar
(302) |
Apr
(309) |
May
(192) |
Jun
(288) |
Jul
(273) |
Aug
(215) |
Sep
(318) |
Oct
(347) |
Nov
(226) |
Dec
(265) |
| 2006 |
Jan
(192) |
Feb
(227) |
Mar
(311) |
Apr
(197) |
May
(224) |
Jun
(213) |
Jul
(285) |
Aug
(227) |
Sep
(190) |
Oct
(209) |
Nov
(169) |
Dec
(174) |
| 2007 |
Jan
(149) |
Feb
(112) |
Mar
(144) |
Apr
(204) |
May
(178) |
Jun
(155) |
Jul
(246) |
Aug
(221) |
Sep
(187) |
Oct
(262) |
Nov
(163) |
Dec
(158) |
| 2008 |
Jan
(256) |
Feb
(318) |
Mar
(307) |
Apr
(237) |
May
(202) |
Jun
(105) |
Jul
(131) |
Aug
(107) |
Sep
(153) |
Oct
(165) |
Nov
(159) |
Dec
(189) |
| 2009 |
Jan
(202) |
Feb
(150) |
Mar
(151) |
Apr
(132) |
May
(56) |
Jun
(115) |
Jul
(103) |
Aug
(150) |
Sep
(141) |
Oct
(187) |
Nov
(154) |
Dec
(105) |
| 2010 |
Jan
(128) |
Feb
(83) |
Mar
(64) |
Apr
(37) |
May
(92) |
Jun
(91) |
Jul
(90) |
Aug
(145) |
Sep
(53) |
Oct
(69) |
Nov
(98) |
Dec
(149) |
| 2011 |
Jan
(44) |
Feb
(99) |
Mar
(70) |
Apr
(78) |
May
(138) |
Jun
(132) |
Jul
(151) |
Aug
(146) |
Sep
(107) |
Oct
(168) |
Nov
(88) |
Dec
(94) |
| 2012 |
Jan
(51) |
Feb
(153) |
Mar
(141) |
Apr
(102) |
May
(79) |
Jun
(63) |
Jul
(87) |
Aug
(39) |
Sep
(67) |
Oct
(84) |
Nov
(57) |
Dec
(31) |
| 2013 |
Jan
(55) |
Feb
(96) |
Mar
(79) |
Apr
(33) |
May
(53) |
Jun
(63) |
Jul
(57) |
Aug
(76) |
Sep
(39) |
Oct
(47) |
Nov
(68) |
Dec
(61) |
| 2014 |
Jan
(26) |
Feb
(98) |
Mar
(29) |
Apr
(57) |
May
(58) |
Jun
(51) |
Jul
(34) |
Aug
(26) |
Sep
(69) |
Oct
(81) |
Nov
(52) |
Dec
(48) |
| 2015 |
Jan
(67) |
Feb
(18) |
Mar
(92) |
Apr
(32) |
May
(37) |
Jun
(21) |
Jul
(26) |
Aug
(28) |
Sep
(6) |
Oct
(24) |
Nov
(35) |
Dec
(34) |
| 2016 |
Jan
(16) |
Feb
(24) |
Mar
(49) |
Apr
(11) |
May
(37) |
Jun
(68) |
Jul
(35) |
Aug
(24) |
Sep
(35) |
Oct
(63) |
Nov
(20) |
Dec
(26) |
| 2017 |
Jan
(98) |
Feb
(82) |
Mar
(42) |
Apr
(62) |
May
(55) |
Jun
(28) |
Jul
(17) |
Aug
(13) |
Sep
(4) |
Oct
(11) |
Nov
(6) |
Dec
(17) |
| 2018 |
Jan
(22) |
Feb
(6) |
Mar
(16) |
Apr
(9) |
May
(20) |
Jun
(25) |
Jul
(15) |
Aug
(10) |
Sep
(6) |
Oct
(2) |
Nov
(14) |
Dec
(25) |
| 2019 |
Jan
(8) |
Feb
(6) |
Mar
(6) |
Apr
(4) |
May
(13) |
Jun
(8) |
Jul
(14) |
Aug
(36) |
Sep
(10) |
Oct
(27) |
Nov
(5) |
Dec
|
| 2020 |
Jan
(10) |
Feb
(4) |
Mar
|
Apr
(1) |
May
(2) |
Jun
(3) |
Jul
(4) |
Aug
(11) |
Sep
(1) |
Oct
(1) |
Nov
(5) |
Dec
(12) |
| 2021 |
Jan
(2) |
Feb
|
Mar
(4) |
Apr
(6) |
May
(8) |
Jun
(2) |
Jul
(1) |
Aug
(7) |
Sep
(3) |
Oct
(23) |
Nov
(10) |
Dec
(17) |
| 2022 |
Jan
(1) |
Feb
|
Mar
(1) |
Apr
(2) |
May
(6) |
Jun
(5) |
Jul
(27) |
Aug
(5) |
Sep
(3) |
Oct
(9) |
Nov
(3) |
Dec
(11) |
| 2023 |
Jan
(13) |
Feb
(7) |
Mar
(3) |
Apr
|
May
(4) |
Jun
(9) |
Jul
|
Aug
(17) |
Sep
|
Oct
|
Nov
(1) |
Dec
(1) |
| 2025 |
Jan
(2) |
Feb
(6) |
Mar
(4) |
Apr
(10) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
(2) |
| 2026 |
Jan
|
Feb
(3) |
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Jamie C. <jca...@we...> - 2006-07-31 21:59:01
|
On 31/Jul/2006 14:37 Barry wrote .. > I just installed usermin 1.221 on my centos 4.3 system. > > when I try to start it via the usermin module, I get a "Failed to open > PID file" error in my browser. Anyone know where this file should be > and what its permissions are? The file it is referring to is /var/usermin/miniserv.pid. You might want to try killing all Usermin miniserv.pl processes, deleting that file and re-trying the startup. - Jamie |
|
From: Greg M. <Moe...@ge...> - 2006-07-31 21:50:39
|
Wooops... I thought you were talking about webmin, and not usermin. That P= ID file would be in a different place, I'd suspect. Don't use usermin too = much here, so I'll leave that question for someone that does.=0D=0A=0D=0A>>= > bo...@de... 7/31/2006 4:44 PM >>>=0D=0AOn Mon, 31 Jul 2006 14= :37:44 -0700=0D=0ABarry <we...@i1...> wrote:=0D=0A=0D=0A> I just instal= led usermin 1.221 on my centos 4.3 system.=0D=0A>=20=0D=0A> when I try to = start it via the usermin module, I get a "Failed to open=20=0D=0A> PID file= " error in my browser. Anyone know where this file should be=20=0D=0A> and= what its permissions are=3F=0D=0A=0D=0Ais the server running=0D=0A=0D=0A--= -----------------------------------------------------------------------=0D=0A= Take Surveys. Earn Cash. Influence the Future of IT=0D=0AJoin SourceForge.n= et's Techsay panel and you'll get the chance to share your=0D=0Aopinions on= IT & business topics through brief surveys -- and earn cash=0D=0Ahttp://ww= w.techsay.com/default.php=3Fpage=3Djoin.php&p=3Dsourceforge&CID=3DDEVDEV =0D= =0A-=0D=0AForwarded by the Webmin mailing list at web...@li...= eforge.net=20=0D=0ATo remove yourself from this list, go to=0D=0Ahttp://lis= ts.sourceforge.net/lists/listinfo/webadmin-list=20=0D=0A=0D=0A=0D=0A=0D=0A=0D= =0ANOTICE: This communication is intended only for the use of the individu= al or entity to which it is addressed and may contain information that is p= rivileged, confidential and exempt from disclosure under applicable law. I= f the reader of this communication is not the intended recipient or the emp= loyee or agent responsible for delivering the communication, you are hereby= notified that any dissemination, distribution or copying of this communica= tion is strictly prohibited. If you have received this communication in er= ror, please notify me immediately by replying to this email.=0D=0A=0D=0AREM= INDER: The disclosure of medical information is strictly prohibited by fed= eral regulation. Unauthorized release of medical information may result in= administrative, civil and criminal sanctions.=0D=0A |
|
From: boricua <bo...@de...> - 2006-07-31 21:47:16
|
On Mon, 31 Jul 2006 14:37:44 -0700 Barry <we...@i1...> wrote: > I just installed usermin 1.221 on my centos 4.3 system. > > when I try to start it via the usermin module, I get a "Failed to open > PID file" error in my browser. Anyone know where this file should be > and what its permissions are? is the server running |
|
From: Barry <we...@i1...> - 2006-07-31 21:38:48
|
I just installed usermin 1.221 on my centos 4.3 system. when I try to start it via the usermin module, I get a "Failed to open PID file" error in my browser. Anyone know where this file should be and what its permissions are? Thanks, Barry |
|
From: Jamie C. <jca...@we...> - 2006-07-31 21:15:36
|
On 31/Jul/2006 14:00 Barry wrote .. > I have just used webmin to install , via yum, SpamAssassin. For now, the > default configuration in the webmin module looks fine. I am using > sendmail on a CentOS4.3 box. > > Do I need to do anything else to get spamassassin up and running? Is Sendmail actually calling SpamAssassin for mail arriving on your system? You can tell by looking for X-Spam headers in the delivered email.. If not, you need to enable it on the 'Procmail Spam Delivery' page in the SpamAssassin module. - Jamie |
|
From: Barry <we...@i1...> - 2006-07-31 21:01:39
|
I have just used webmin to install , via yum, SpamAssassin. For now, the default configuration in the webmin module looks fine. I am using sendmail on a CentOS4.3 box. Do I need to do anything else to get spamassassin up and running? Thanks, Barry |
|
From: Jamie C. <jca...@we...> - 2006-07-31 18:10:31
|
Generally, I recommend locking down users like this not by setting permissions, but by restricting the services they can use. For example, you should deny SSH logins, configure your FTP server to only let them see their home directory, and do the same with Usermin..<br /><br />=A0- Jamie<br /><br />On 31/Jul/2006 10:39 Russ Ferriday wrote .. <blockquote type=3D"cite"> I can through all virtual hosts doing this on each user. If I do, dovecot will no longer serve imap for any of those users.<div><div><div><br class=3D"khtml-block-placeholder" /></div><div>Do you think a basic level of security should be part of the default setup for a virtual server?</div><div><br class=3D"khtml-block-placeholder" /></div><div>John Hinton suggested this change:</div><div><blockquote type=3D"cite"><div><br class=3D"khtml-block-placeholder" /></div><div style=3D"margin: 0px;">Inside of Apache 2 conf.</div><div style=3D"margin: 0px; min-height: 14px;"><br /></div><div style=3D"margin: 0px;"><IfModule mod_userdir.c></div><div style=3D"margin: 0px;"> #</div><div style=3D"margin: 0px;"> # UserDir is disabled by default since it can confirm the presence</div><div style=3D"margin: 0px;"> # of a username on the system (depending on home directory</div><div style=3D"margin: 0px;"> # permissions).</div><div style=3D"margin: 0px;"> #</div><div style =3D"margin: 0px;"> UserDir disable</div></blockquote></div><div><br class=3D"khtml-block-placeholder" /></div><div>This will affect web access to folders, but does not affect local access.</div><div><br class=3D"khtml-block-placeholder" /></div><div>As it is at the moment, when I install two virtual servers, their users can mutually browse directories and files.</div><div><br class=3D"khtml-block-placeholder" /></div><div>--r<br /><div><div>On 31 Jul 2006, at 18:21, Jamie Cameron wrote:</div><br class=3D"Apple-interchange-newline" /><blockquote type=3D"cite"> Have you tried setting mode 711 instead? That allows anyone to chdir to the directory, but not list it ..<br /><br /> - Jamie<br /><br />On 31/Jul/2006 10:09 Russ Ferriday wrote .. <blockquote type=3D"cite"> <div>For either of the chmod versions, I get the following in /var/log/maillog</div><div><br class=3D"khtml-block-placeholder" /></div><div>Jul 31 16:37:12 air660 dovecot: chdir(/home/topia/homes/russf) failed wi th uid 509: Permission denied</div><div>Jul 31 16:37:12 air660 imap-login: Login: russf.topia [::ffff:86.128.111.255]</div><div>Jul 31 16:37:12 air660 dovecot: child 25628 (imap) returned error 89</div><div><br class=3D"khtml-block-placeholder" /></div><div>Bear in mind my original problem, also. Users on virtual hosts, can by default read other users' homes, because permissions in general are 755.</div><div><br class=3D"khtml-block-placeholder" /></div><div>Thanks for looking at this.</div><div><br class=3D"khtml-block-placeholder" /></div><div>--r</div><br /><div><div>On 31 Jul 2006, at 17:32, Jamie Cameron wrote:</div><br class=3D"Apple-interchange-newline" /><blockquote type=3D"cite"> On 31/Jul/2006 08:34 Russ Ferriday wrote .. <blockquote type=3D"cite"> <div><br class=3D"khtml-block-placeholder" /></div>Dovecot does not run as soon as I do either of<div> chmod o-rx /home/<virtdomain></div><div>or</div><div><div><div> <span style=3D"border-collapse: separate; col or: rgb(0, 0, 0); font-family: Helvetica; font-size: 11px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: sepa rate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><div><font size=3D"3"><span style=3D"font-size: 11px;" class=3D"Apple-style-span"> chmod o-rx /home/<virtdomain>/homes/user</span></font></div><div><font size=3D"3" class=3D"Apple-style-span"><span style=3D"font-size: 11px;" class=3D"Apple-style-span"><br class=3D"khtml-block-placeholder" /></span></font></div><div><font size=3D"3" class=3D"Apple-style-span"><span style=3D"font-size: 11px;" class=3D"Apple-style-span">Is there a recommended way of preventing a virt domain user being able to see the data of another virt domain user?</span></font></div><br /></span></span></span></span></span></span></span></div><br /></div></div></blockquote>That is quite surprising, as Dovecot usually runs with the permissions of the user<br />who is logged in via IMAP or POP3. What exact error message are you getting from it?<br /><br /> - Jamie<br /><br /></blockquote></div><div><span class=3D"Apple-style-span" style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 11px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;"><span class=3D"Apple-style-span" style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;"><span class=3D"Apple-style-span" style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-s ize: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;"><span class=3D"Apple-style-span" style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;"><span class=3D"Apple-style-span" style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;"><span class=3D"Apple-style-span" style=3D"border-collapse: separate; color: rgb( 0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;"><span class=3D"Apple-style-span" style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;"><br class=3D"Apple-interchange-newline" /></span></span></span></span></span></span></span> </div><br /></blockquote><br /><div style=3D"margin: 0px;">-------------------------------------------------------------------------</div><div style=3D"margin: 0px;">Take Surveys. Earn Cash. Influence the Future of IT</div><div style=3D"margin: 0px;">Join SourceForge.net's Techsay panel and you'll get the chan ce to share your</div><div style=3D"margin: 0px;">opinions on IT & business topics through brief surveys -- and earn cash</div><div style=3D"margin: 0px;"><a href=3D"http://www.techsay.com/default.php?page=3Djoin.php&p=3Dsourceforge&CID=3DDEVDEV-">http://www.techsay.com/default.php?page=3Djoin.php&p=3Dsourceforge&CID=3DDEVDEV-</a></div><div style=3D"margin: 0px;">Forwarded by the Webmin mailing list at <a href=3D"_unsafe_link_">web...@li...</a></div><div style=3D"margin: 0px;">To remove yourself from this list, go to</div><div style=3D"margin: 0px;"><a href=3D"http://lists.sourceforge.net/lists/listinfo/webadmin-list">http://lists.sourceforge.net/lists/listinfo/webadmin-list</a></div> </blockquote></div><br /><div> <span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 11px; font-style: normal; font-variant: normal; font-weight: normal; letter-spa cing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: s eparate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacin g: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><p style=3D"margin: 0px; font-size: 10px;"><font size=3D"2" face=3D"Helvetica" style=3D"font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; font-size: 10px;"><span style=3D"font-size: 10px;" class=3D"Apple-style-span">=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97</span></font></p><div style=3D"margin: 0px; fon t-size: 10px;"><span style=3D"font-size: 10px;" class=3D"Apple-style-span">Russ Ferriday</span></div><div style=3D"margin: 0px; font-size: 10px;"><b style=3D"font-weight: bold; font-size: 10px;"><span style=3D"font-weight: bold; font-size: 10px;" class=3D"Apple-style-span"><span style=3D"font-weight: bold; font-size: 10px;" class=3D"Apple-style-span"><span style=3D"font-weight: bold; font-size: 10px;" class=3D"Apple-style-span"><span style=3D"font-weight: bold; font-size: 10px;" class=3D"Apple-style-span"><span style=3D"font-size: 10px; font-weight: bold;" class=3D"Apple-style-span">Topia Systems</span></span></span></span></span></b></div><div style=3D"margin: 0px; font-size: 10px;"><span style=3D"font-size: 10px;" class=3D"Apple-style-span">tel: (+44) (0) 2076 177758</span></div><div style=3D"margin: 0px; font-size: 10px;"><span style=3D"font-size: 10px;" class=3D"Apple-style-span">mobile: (+44) (0) 7789 338868</span></div><div style=3D"margin: 0px; font-size: 10px;"><span style=3D"font-size: 10px;" class=3D"Apple-style-span">skype: ferriday</span></div><br class=3D"Apple-interchange-newline" /></span></span></span></span></span></span></span> </div><br /></div></div></div></blockquote><br /> |
|
From: Russ F. <rus...@gm...> - 2006-07-31 17:40:04
|
I can through all virtual hosts doing this on each user. If I do, =20 dovecot will no longer serve imap for any of those users. Do you think a basic level of security should be part of the default =20 setup for a virtual server? John Hinton suggested this change: > > Inside of Apache 2 conf. > > <IfModule mod_userdir.c> > # > # UserDir is disabled by default since it can confirm the presence > # of a username on the system (depending on home directory > # permissions). > # > UserDir disable This will affect web access to folders, but does not affect local =20 access. As it is at the moment, when I install two virtual servers, their =20 users can mutually browse directories and files. --r On 31 Jul 2006, at 18:21, Jamie Cameron wrote: > Have you tried setting mode 711 instead? That allows anyone to =20 > chdir to the directory, but not list it .. > > - Jamie > > On 31/Jul/2006 10:09 Russ Ferriday wrote .. >> For either of the chmod versions, I get the following in /var/log/=20 >> maillog >> >> Jul 31 16:37:12 air660 dovecot: chdir(/home/topia/homes/russf) =20 >> failed with uid 509: Permission denied >> Jul 31 16:37:12 air660 imap-login: Login: russf.topia [::ffff:=20 >> 86.128.111.255] >> Jul 31 16:37:12 air660 dovecot: child 25628 (imap) returned error 89 >> >> Bear in mind my original problem, also. Users on virtual hosts, =20 >> can by default read other users' homes, because permissions in =20 >> general are 755. >> >> Thanks for looking at this. >> >> --r >> >> On 31 Jul 2006, at 17:32, Jamie Cameron wrote: >> >>> On 31/Jul/2006 08:34 Russ Ferriday wrote .. >>>> >>>> Dovecot does not run as soon as I do either of >>>> chmod o-rx /home/<virtdomain> >>>> or >>>> chmod o-rx /home/<virtdomain>/homes/user >>>> >>>> Is there a recommended way of preventing a virt domain user =20 >>>> being able to see the data of another virt domain user? >>>> >>>> >>> That is quite surprising, as Dovecot usually runs with the =20 >>> permissions of the user >>> who is logged in via IMAP or POP3. What exact error message are =20 >>> you getting from it? >>> >>> - Jamie >>> >> >> > > ----------------------------------------------------------------------=20= > --- > Take Surveys. Earn Cash. Influence the Future of IT > Join SourceForge.net's Techsay panel and you'll get the chance to =20 > share your > opinions on IT & business topics through brief surveys -- and earn =20 > cash > http://www.techsay.com/default.php?=20 > page=3Djoin.php&p=3Dsourceforge&CID=3DDEVDEV- > Forwarded by the Webmin mailing list at webadmin-=20 > li...@li... > To remove yourself from this list, go to > http://lists.sourceforge.net/lists/listinfo/webadmin-list =97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97 Russ Ferriday Topia Systems tel: (+44) (0) 2076 177758 mobile: (+44) (0) 7789 338868 skype: ferriday |
|
From: Jamie C. <jca...@we...> - 2006-07-31 17:21:34
|
Have you tried setting mode 711 instead? That allows anyone to chdir to the directory, but not list it ..<br /><br />=A0- Jamie<br /><br />On 31/Jul/2006 10:09 Russ Ferriday wrote .. <blockquote type=3D"cite"> <div>For either of the chmod versions, I get the following in /var/log/maillog</div><div><br class=3D"khtml-block-placeholder" /></div><div>Jul 31 16:37:12 air660 dovecot: chdir(/home/topia/homes/russf) failed with uid 509: Permission denied</div><div>Jul 31 16:37:12 air660 imap-login: Login: russf.topia [::ffff:86.128.111.255]</div><div>Jul 31 16:37:12 air660 dovecot: child 25628 (imap) returned error 89</div><div><br class=3D"khtml-block-placeholder" /></div><div>Bear in mind my original problem, also. Users on virtual hosts, can by default read other users' homes, because permissions in general are 755.</div><div><br class=3D"khtml-block-placeholder" /></div><div>Thanks for looking at this.</div><div><br class=3D"khtml-block-placeholder" /></div><div>--r</div><br /><div><div>On 31 Jul 2006, at 17:32, Jamie Cameron wrote:</div><br class=3D"Apple-interchange-newline" /><blockquote type=3D"cite"> On 31/Jul/2006 08:34 Russ Ferriday wrote .. <blockquote type=3D"cite"> <div><br class=3D"khtml-block-placeholder" /></div>Dovecot does not run as soon as I do either of<div> chmod o-rx /home/<virtdomain></div><div>or</div><div><div><div> <span class=3D"Apple-style-span" style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 11px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;"><span class=3D"Apple-style-span" style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;"><span class=3D"Apple-style-span" style=3D"color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;"><span class=3D"Apple-style-span" style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;"><span class=3D"Apple-style-span" style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;"><span class=3D"Apple-style-span" style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: norma l; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;"><span class=3D"Apple-style-span" style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;"><div><font size=3D"3"><span class=3D"Apple-style-span" style=3D"font-size: 11px;"> chmod o-rx /home/<virtdomain>/homes/user</span></font></div><div><font size=3D"3" class=3D"Apple-style-span"><span class=3D"Apple-style-span" style=3D"font-size: 11px;"><br class=3D"khtml-block-placeholder" /></span></font></div><div><font size=3D"3" class=3D"Apple-style-span"><span class=3D"Apple-style-span" style=3D"font-size: 11px;">Is there a recommended way of preventing a virt domain user being able to see the data of another virt domain user?</span></font></div><br /></span></span></span></span></span></span></span></div><br /></div></div></blockquote>That is quite surprising, as Dovecot usually runs with the permissions of the user<br />who is logged in via IMAP or POP3. What exact error message are you getting from it?<br /><br /> - Jamie<br /><br /></blockquote></div><div><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 11px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font- style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing : 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-sty le: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><br class=3D"Apple-interchange-newline" /></span></span></span></span></span></span></span> </div><br /></blockquote><br /> |
|
From: Russ F. <rus...@gm...> - 2006-07-31 17:09:44
|
For either of the chmod versions, I get the following in /var/log/ maillog Jul 31 16:37:12 air660 dovecot: chdir(/home/topia/homes/russf) failed with uid 509: Permission denied Jul 31 16:37:12 air660 imap-login: Login: russf.topia [::ffff: 86.128.111.255] Jul 31 16:37:12 air660 dovecot: child 25628 (imap) returned error 89 Bear in mind my original problem, also. Users on virtual hosts, can by default read other users' homes, because permissions in general are 755. Thanks for looking at this. --r On 31 Jul 2006, at 17:32, Jamie Cameron wrote: > On 31/Jul/2006 08:34 Russ Ferriday wrote .. >> >> Dovecot does not run as soon as I do either of >> chmod o-rx /home/<virtdomain> >> or >> chmod o-rx /home/<virtdomain>/homes/user >> >> Is there a recommended way of preventing a virt domain user being >> able to see the data of another virt domain user? >> >> > That is quite surprising, as Dovecot usually runs with the > permissions of the user > who is logged in via IMAP or POP3. What exact error message are you > getting from it? > > - Jamie > |
|
From: Jamie C. <jca...@we...> - 2006-07-31 16:32:58
|
On 31/Jul/2006 08:34 Russ Ferriday wrote .. <blockquote type=3D"cite"> <div><br class=3D"khtml-block-placeholder" /></div>Dovecot does not run as soon as I do either of<div> chmod o-rx /home/<virtdomain></div><div>or</div><div><div><div> <span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 11px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-col lapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; lette r-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><span style=3D"border-collapse: separate; -x-border-x-spacing: 0px; -x-border-y-spacing: 0px; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 10px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; text-indent: 0px; text-transform: none; orphans: 2; white-space: normal; widows: 2; word-spacing: 0px;" class=3D"Apple-style-span"><div><font size=3D"3" class= 3D"Apple-style-span"><span style=3D"font-size: 11px;" class=3D"Apple-style-span"> chmod o-rx /home/<virtdomain>/homes/user</span></font></div><div><font size=3D"3" class=3D"Apple-style-span"><span style=3D"font-size: 11px;" class=3D"Apple-style-span"><br class=3D"khtml-block-placeholder" /></span></font></div><div><font size=3D"3" class=3D"Apple-style-span"><span style=3D"font-size: 11px;" class=3D"Apple-style-span">Is there a recommended way of preventing a virt domain user being able to see the data of another virt domain user?</span></font></div><br /></span></span></span></span></span></span></span></div><br /></div></div></blockquote>That is quite surprising, as Dovecot usually runs with the permissions of the user<br />who is logged in via IMAP or POP3. What exact error message are you getting from it?<br /><br />=A0- Jamie<br /><br /> |
|
From: John H. <web...@ew...> - 2006-07-31 16:08:15
|
Russ Ferriday wrote:
>
> Dovecot does not run as soon as I do either of
> chmod o-rx /home/<virtdomain>
> or
> chmod o-rx /home/<virtdomain>/homes/user
>
> Is there a recommended way of preventing a virt domain user being able=20
> to see the data of another virt domain user?
>
> --r
Inside of Apache 2 conf.
<IfModule mod_userdir.c>
#
# UserDir is disabled by default since it can confirm the presence
# of a username on the system (depending on home directory
# permissions).
#
UserDir disable
#
# To enable requests to /~user/ to serve the user's public_html
# directory, remove the "UserDir disable" line above, and uncomment
# the following line instead:
#
# UserDir public_html
</IfModule>
>
> =97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97
>
> Russ Ferriday
> *Topia Systems*
> tel: (+44) (0) 2076 177758
> mobile: (+44) (0) 7789 338868
> skype: ferriday
>
> -----------------------------------------------------------------------=
-
>
> -----------------------------------------------------------------------=
--
> Take Surveys. Earn Cash. Influence the Future of IT
> Join SourceForge.net's Techsay panel and you'll get the chance to share=
your
> opinions on IT & business topics through brief surveys -- and earn cash
> http://www.techsay.com/default.php?page=3Djoin.php&p=3Dsourceforge&CID=3D=
DEVDEV
>
> =20
This sig might be considered a bit much on a listserver?
Best,
John Hinton
|
|
From: Russ F. <rus...@gm...> - 2006-07-31 15:34:44
|
Dovecot does not run as soon as I do either of
chmod o-rx /home/<virtdomain>
or
chmod o-rx /home/<virtdomain>/homes/user
Is there a recommended way of preventing a virt domain user being =20
able to see the data of another virt domain user?
--r
=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97=97
Russ Ferriday
Topia Systems
tel: (+44) (0) 2076 177758
mobile: (+44) (0) 7789 338868
skype: ferriday
|
|
From: Craig W. <cra...@az...> - 2006-07-31 15:00:49
|
On Mon, 2006-07-31 at 09:16 -0400, boricua wrote: > it wouold be nice if someone could provide a howto dns with webmin :-) > ---- Joe Cooper has some very valuable information on his website about using webmin with various daemons such as BIND http://www.swelltech.com/support/webminguide-1.0/index.html Craig |
|
From: Robert M. <rg...@ht...> - 2006-07-31 14:37:13
|
boricua wrote: > On Mon, 31 Jul 2006 09:46:32 -0400 > "Robert Moskowitz" <rg...@ht...> wrote: > > >> boricua wrote: >> >>> it wouold be nice if someone could provide a howto dns with webmin :-) >>> >>> >> First you need a howto on DNS and Bind. >> >> Webmin just manages your zone files for you. You still need to know what >> zone files you need and what you need in them. >> >> > i kind of got a glimps of it > > > http://www.linuxjournal.com/node/1000064 There are some serious BIND howtos out there. Is this for DNS within a corp net? Is this for your public DNS? Do you have control of your zone and have to operate your master zone file and reverse lookup zone file? Do you have a CIDR block (of IP addresses) assigned to you and will your ISP delegate running the reverse zone for them? Is all you are after is a little experience to understand what I am even asking? I have run my own zone since I set it up in '96. With various ISPs, I have had various cooperation. My current ISP finally delegated my CIDR block to me, then I had to fight with them to get the delegation right on their side (it helps when I have spent years in IETF DNS meetings...). I have also contributed errata to Cricket's BIND book on the generate command specifically for reverse lookup delegation, and in IMNSHO, Webmin does not handle GENERATE and inbedded $ORIGIN statements well. I have to review my whole zone file after using one of the dialogs; for example when I change an MX record or add a SRV record for a SIP server. But I still use Webmin rather than plug through the old way with VI. |
|
From: boricua <bo...@de...> - 2006-07-31 13:58:32
|
On Mon, 31 Jul 2006 09:46:32 -0400 "Robert Moskowitz" <rg...@ht...> wrote: > boricua wrote: > > it wouold be nice if someone could provide a howto dns with webmin :-) > > > First you need a howto on DNS and Bind. > > Webmin just manages your zone files for you. You still need to know what > zone files you need and what you need in them. > i kind of got a glimps of it http://www.linuxjournal.com/node/1000064 |
|
From: Robert M. <rg...@ht...> - 2006-07-31 13:47:22
|
boricua wrote: > it wouold be nice if someone could provide a howto dns with webmin :-) > First you need a howto on DNS and Bind. Webmin just manages your zone files for you. You still need to know what zone files you need and what you need in them. > ------------------------------------------------------------------------- > Take Surveys. Earn Cash. Influence the Future of IT > Join SourceForge.net's Techsay panel and you'll get the chance to share your > opinions on IT & business topics through brief surveys -- and earn cash > http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV > - > Forwarded by the Webmin mailing list at web...@li... > To remove yourself from this list, go to > http://lists.sourceforge.net/lists/listinfo/webadmin-list > > |
|
From: boricua <bo...@de...> - 2006-07-31 13:19:21
|
it wouold be nice if someone could provide a howto dns with webmin :-) |
|
From: Robert M. <rg...@ht...> - 2006-07-31 10:40:45
|
Jamie Cameron wrote: > On 30/Jul/2006 18:53 Robert Moskowitz wrote .. > >> Jamie Cameron wrote: >> >>> On 27/Jul/2006 21:01 Robert Moskowitz wrote .. >>> >>> >>>> Well, >>>> >>>> I have finally gotten TinyCA2 up and working! Many things got in the >>>> way; but it is now up and running on my notebook (running Centos 4.3). >>>> >>>> >>>> But the server cert, I suspect I DO have to keep it informed, so WHEN >>>> >> I >> >>>> move it to a better directory than my home directory, I will have to >>>> update the file location in the SSL module. >>>> >>>> >>>> Now about that file being password protected.... >>>> >>>> When I supplied Webmin with the cert location (I put the cert and >>>> private key in a single file), the update failed with a message that >>>> webmin did not restart. >>>> >>>> So from a terminal window I issued: /etc/webmin/start >>>> >>>> And was asked: >>>> >>>> Enter PEM pass phrase: >>>> >>>> So either I have to live with being asked for the PEM pass phrase >>>> everytime I start Webmin (reasonable for running it occationally on >>>> >> my >> >>>> notebook), or creat the server cert without a passphrase? >>>> >>>> I can see that needing a passphrase on a server would require that said >>>> passphrase be somewhere on the filesystem (or in a token) anyway, so >>>> just put it in a root controled directory and don't passphrase protect >>>> it? What does Webmin do what it creates its own cert? >>>> >>>> >>> Webmin always creates non-password-protected cert files, to avoid the >>> >> problem >> >>> of the openssl library prompting for the password at startup time. I >>> >> suppose >> >>> I could add code to allow a password to be specified in Webmin's config >>> >> files >> >>> somewhere (like Apache does), but security-wise this would be no different >>> from not having a passphrase at all! >>> >>> Basically, I recommend creating certs without a passphrase, if you want >>> >> to >> >>> use them with a web server than can be started automatically at boot >>> >> time. >> I cannot see how to get TinyCA to create a server cert without a >> password. When I leave the password field blank, I get a error about no >> password.... >> >> So until I can get the author to accommodate non-passworded server >> certs, I worked out the following: >> >> echo password > /etc/webmin/start >> >> I can put that into the webmin start script. >> > > I guess you really mean echo password | /etc/webmin/start right? > I looked in the SSL Perl library for a way of automating this so that > the passphrase can be in the Webmin configuration, but there doesn't > seem to be any :-( > Interestingly, | does not work, but > does..... Empirical testing wins out over theory. |
|
From: Obantec S. <su...@ob...> - 2006-07-31 08:31:34
|
----- Original Message ----- From: "Jamie Cameron" <jca...@we...> To: "Webmin users list" <web...@li...> Sent: Monday, July 31, 2006 6:57 AM Subject: Re: [webmin-l] update on previous issue deleting spam via usermin <snip> > > This is definately an IE-specific issue .. > I would be interested to know if you see it on XP as well, or only on 2000. > > - Jamie > > ------------------------------------------------------------------------- > Take Surveys. Earn Cash. Influence the Future of IT > Join SourceForge.net's Techsay panel and you'll get the chance to share your > opinions on IT & business topics through brief surveys -- and earn cash > http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV > - > Forwarded by the Webmin mailing list at web...@li... > To remove yourself from this list, go to > http://lists.sourceforge.net/lists/listinfo/webadmin-list > > > > -- > No virus found in this incoming message. > Checked by AVG Anti-Virus. > Version: 7.1.394 / Virus Database: 268.10.5/403 - Release Date: 28/07/2006 > > Hi Jamie from my customer on XP pro, i asked him to send html of part page which he gets when deleting more than 5. "Hello Mark, I see no difference! On Delete All, I sometimes get a blank page, but mostly the blue page, HTML below:- <!doctype html public "-//W3C//DTD HTML 3.2 Final//EN"> <html> <head> <meta http-equiv="Content-Type" content="text/html; Charset=iso-8859-1"> <title>Confirm Delete</title> <SCRIPT LANGUAGE="JavaScript"> defaultStatus="rmhhco logged into Usermin 1.224 on proteus2.obantec.net (Redhat Linux Fedora 3)"; </SCRIPT> </head> <body bgcolor=#6696bc link=#000000 vlink=#000000 text=#000000 leftmargin="0" topmargin="0" marginwidth="0" marginheight="0" ><table width="100%" border="0" cellspacing="0" cellpadding="0" background="/images/top_bar/bg.jpg" height="32"> <tr> <td width="4" nowrap><img src="/images/top_bar/left.jpg" width="4" height="32"></td> <td width="100%" nowrap><a href="http://www.usermin.com/"><img src="/usermin_logo.gif" width="99" height="32" border="0" alt="Webmin home page"></td> <td width="100%" nowrap><a href="http://www.opencountry.com/webmin/" target=_new><img src="/images/top_bar/oc_logo.gif" width="268" height="32" border="0" alt="OpenCountry home page"></a></td><td width="84" nowrap><a href='/session_login.cgi?logout=1'><img src="/images/top_bar/logout.jpg" width=84 height="31" border="0" alt="Logout"></td><td width="3" nowrap> <div align="right"><img src="/images/top_bar/right.jpg" width="3" height="32"></div> </td> </tr> </table>< Anything more than 5 to delete gives the same. Regards Rodney" Mark |
|
From: Jamie C. <jca...@we...> - 2006-07-31 05:57:59
|
On 30/Jul/2006 01:05 Obantec Support wrote .. > > ----- Original Message ----- > From: "Jamie Cameron" <jca...@we...> > To: "Webmin users list" <web...@li...> > Sent: Saturday, July 29, 2006 8:08 PM > Subject: Re: [webmin-l] update on previous issue deleting spam via usermin > > > > On 28/Jul/2006 02:31 Obantec Support wrote .. > > > > > > ----- Original Message ----- > > > From: "Jamie Cameron" <jca...@we...> > > > To: "Webmin users list" <web...@li...> > > > Cc: "Obantec Support" <su...@ob...> > > > Sent: Friday, July 28, 2006 12:56 AM > > > Subject: Re: [webmin-l] update on previous issue deleting spam via > usermin > > > > > > > > > > On 26/Jul/2006 01:34 Obantec Support wrote .. > > > > > Hi Jamie > > > > > > > > > > My client only has IE 6 and does not want to use another browser. > he > > > sent > > > > > me > > > > > this screen shot > > > > > > > > > > http://www.mds.cc/images/usermin/spamdel.jpg which points to a > script > > > issue? > > > > > > > > > > his report below (where he says Spam Assassin he means Read Mail > > > > > > > > > > " > > > > > Further to my last on Usermin problems, Having worked my way through > > > > > deleting some 40 spam emails on Spam Assasin>Spam Mail in 5s and > > > sometimes > > > > > 4s, as allowed, on trying to delete the last 11, I get the following > > > Server > > > > > Error 500 screen:- > > > > > <image removed see above url> > > > > > On further attempts to access Spam Mail, I get the same response. > > > > > > > > > > Something here is really broken! > > > > > > > > > > Regards > > > > > Rodney" > > > > > > > > > > i too have seen this and also server not found when deleting more > than > > > > > 5 or > > > > > 6 mails sometimes. > > > > > > > > There is a fix I am investigating for this.. > > > > Try editing the file /etc/usermin/mailbox/config , and changing the > line > > > > index_dbm=0 to index_dbm=2. Let me know if that helps .. > > > > > > > > - Jamie > > > > > > > > > > > > > > > > -- > > > > No virus found in this incoming message. > > > > Checked by AVG Anti-Virus. > > > > Version: 7.1.394 / Virus Database: 268.10.4/402 - Release Date: > 27/07/2006 > > > > > > > > > > > > > > Hi Jamie > > > > > > i have made the mod and ask my customer for feedback. > > > > > > while i was testing i got an old problem of server not found when > deleting > > > 7 > > > or more mails. > > > i have uploaded a very poor quality vid. > > > > > > step 1 i selected 5 mails and deleted ok > > > step 2 i selected 6 mails and deleted ok > > > step 3 i selected 7 mails and as you see a white screen which is server > > > not > > > found. > > > > > > any more than 7 i get the same result. if i hit back and select less > then > > > its fine. > > > > > > http://www.mds.cc/usermin/vid.php > > > > Wow, a video bug report - that sets new heights in thorougness! > > I think you are seeing a different problem here, which I believe > > has been addressed in the 1.224 version of Usermin, available from > > http://www.webmin.com/devel.html . > > > > Would it be possible for you to install this and re-try deletion of > > 7 or more emails? I'm having trouble tracking this down, as it never > > happens for me, even when running IE. > > > > - Jamie > > > > ------------------------------------------------------------------------- > > Take Surveys. Earn Cash. Influence the Future of IT > > Join SourceForge.net's Techsay panel and you'll get the chance to share > your > > opinions on IT & business topics through brief surveys -- and earn cash > > http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV > > - > > Forwarded by the Webmin mailing list at > web...@li... > > To remove yourself from this list, go to > > http://lists.sourceforge.net/lists/listinfo/webadmin-list > > > > > > > Hi Jamie > > i thought a video was the best way to show what i was seeing. > > UG to dev version and still have same issues. i have asked my customer > to > try on his PC as he is using XP pro where as i use 2000 > > Firefox works for me 7+ or select all / delete without any errors so i > ruled > out DNS issues unless IE is buggy in that area. This is definately an IE-specific issue .. I would be interested to know if you see it on XP as well, or only on 2000. - Jamie |
|
From: Jamie C. <jca...@we...> - 2006-07-31 05:42:12
|
On 30/Jul/2006 18:53 Robert Moskowitz wrote .. > Jamie Cameron wrote: > > On 27/Jul/2006 21:01 Robert Moskowitz wrote .. > > > >> Well, > >> > >> I have finally gotten TinyCA2 up and working! Many things got in the > >> way; but it is now up and running on my notebook (running Centos 4.3). > >> > >> > >> But the server cert, I suspect I DO have to keep it informed, so WHEN > I > >> move it to a better directory than my home directory, I will have to > >> update the file location in the SSL module. > >> > >> > >> Now about that file being password protected.... > >> > >> When I supplied Webmin with the cert location (I put the cert and > >> private key in a single file), the update failed with a message that > >> webmin did not restart. > >> > >> So from a terminal window I issued: /etc/webmin/start > >> > >> And was asked: > >> > >> Enter PEM pass phrase: > >> > >> So either I have to live with being asked for the PEM pass phrase > >> everytime I start Webmin (reasonable for running it occationally on > my > >> notebook), or creat the server cert without a passphrase? > >> > >> I can see that needing a passphrase on a server would require that said > >> passphrase be somewhere on the filesystem (or in a token) anyway, so > >> just put it in a root controled directory and don't passphrase protect > >> it? What does Webmin do what it creates its own cert? > >> > > > > Webmin always creates non-password-protected cert files, to avoid the > problem > > of the openssl library prompting for the password at startup time. I > suppose > > I could add code to allow a password to be specified in Webmin's config > files > > somewhere (like Apache does), but security-wise this would be no different > > from not having a passphrase at all! > > > > Basically, I recommend creating certs without a passphrase, if you want > to > > use them with a web server than can be started automatically at boot > time. > I cannot see how to get TinyCA to create a server cert without a > password. When I leave the password field blank, I get a error about no > password.... > > So until I can get the author to accommodate non-passworded server > certs, I worked out the following: > > echo password > /etc/webmin/start > > I can put that into the webmin start script. I guess you really mean echo password | /etc/webmin/start right? I looked in the SSL Perl library for a way of automating this so that the passphrase can be in the Webmin configuration, but there doesn't seem to be any :-( - Jamie |
|
From: Jamie C. <jca...@we...> - 2006-07-31 05:29:25
|
On 30/Jul/2006 18:38 Murray Trainer wrote .. > On Sat, 2006-07-29 at 11:54 -0700, Jamie Cameron wrote: > > On 25/Jul/2006 23:42 Murray Trainer wrote .. > > > On Tue, 2006-07-25 at 09:49 -0700, Jamie Cameron wrote: > > > > On 25/Jul/2006 01:50 Murray Trainer wrote .. > > > > > Hi Jamie, > > > > > > > > > > When I add a user with a totally numeric userid like 12345678 the > quotas > > > > > appear normal via repquota -s /home but when I look in the Filesystem > > > > > Quotas module I get two entries for the user, ie 12345678 and #12345678. > > > > > The first one displays the correct disk usage and the second shows > > > > > none. > > > > > > > > Adding users with names like that is a bad idea, as the quota commands > > > will > > > > get confused between UIDs and usernames. For example, if you run > : > > > > > > > > edquota -t 12345678 > > > > > > > > it may set the quotas for the user named 12345678, or with UID 12345678. > > > > Because Webmin just calls thse commands, it cannot handle this situation > > > > as you'd expect. > > > > > > Edquota should probably be fixed but as a workaround could you run > > > edquota with the numeric id of the user as the argument instead of > the > > > name to avoid this problem? > > > > That won't work though .. > > I checked into this further, and found that if you run edquota with a > numeric username, it will always assume this this is a UID, even if no user with > that ID exists. > > > > - Jamie > > Exactly, not sure if you got my point though. I meant that if edquota > always assumes numeric usernames are UID numbers then if you run edquota > with the UID number it would always behave as expected. Doesn't matter > for now as we have stopped fully numeric userid's from being created > anyway. It would probably be a pain for you to change this and > potentially break the module on some types of systems. Personally I > think edquota should be fixed - I noticed that HP have already done that > on their version of Unix. Doh! You are absolutely correct .. I was somehow thinking that edquota was working the other way around. I will update Webmin in the next release to always use UIDs, which will solve this problem. - Jamie |
|
From: Robert M. <rg...@ht...> - 2006-07-31 01:53:58
|
Jamie Cameron wrote: > On 27/Jul/2006 21:01 Robert Moskowitz wrote .. > >> Well, >> >> I have finally gotten TinyCA2 up and working! Many things got in the >> way; but it is now up and running on my notebook (running Centos 4.3). >> >> >> But the server cert, I suspect I DO have to keep it informed, so WHEN I >> move it to a better directory than my home directory, I will have to >> update the file location in the SSL module. >> >> >> Now about that file being password protected.... >> >> When I supplied Webmin with the cert location (I put the cert and >> private key in a single file), the update failed with a message that >> webmin did not restart. >> >> So from a terminal window I issued: /etc/webmin/start >> >> And was asked: >> >> Enter PEM pass phrase: >> >> So either I have to live with being asked for the PEM pass phrase >> everytime I start Webmin (reasonable for running it occationally on my >> notebook), or creat the server cert without a passphrase? >> >> I can see that needing a passphrase on a server would require that said >> passphrase be somewhere on the filesystem (or in a token) anyway, so >> just put it in a root controled directory and don't passphrase protect >> it? What does Webmin do what it creates its own cert? >> > > Webmin always creates non-password-protected cert files, to avoid the problem > of the openssl library prompting for the password at startup time. I suppose > I could add code to allow a password to be specified in Webmin's config files > somewhere (like Apache does), but security-wise this would be no different > from not having a passphrase at all! > > Basically, I recommend creating certs without a passphrase, if you want to > use them with a web server than can be started automatically at boot time. I cannot see how to get TinyCA to create a server cert without a password. When I leave the password field blank, I get a error about no password.... So until I can get the author to accommodate non-passworded server certs, I worked out the following: echo password > /etc/webmin/start I can put that into the webmin start script. |
|
From: Murray T. <mtr...@ce...> - 2006-07-31 01:38:40
|
On Sat, 2006-07-29 at 11:54 -0700, Jamie Cameron wrote: > On 25/Jul/2006 23:42 Murray Trainer wrote .. > > On Tue, 2006-07-25 at 09:49 -0700, Jamie Cameron wrote: > > > On 25/Jul/2006 01:50 Murray Trainer wrote .. > > > > Hi Jamie, > > > > > > > > When I add a user with a totally numeric userid like 12345678 the quotas > > > > appear normal via repquota -s /home but when I look in the Filesystem > > > > Quotas module I get two entries for the user, ie 12345678 and #12345678. > > > > The first one displays the correct disk usage and the second shows > > > > none. > > > > > > Adding users with names like that is a bad idea, as the quota commands > > will > > > get confused between UIDs and usernames. For example, if you run : > > > > > > edquota -t 12345678 > > > > > > it may set the quotas for the user named 12345678, or with UID 12345678. > > > Because Webmin just calls thse commands, it cannot handle this situation > > > as you'd expect. > > > > Edquota should probably be fixed but as a workaround could you run > > edquota with the numeric id of the user as the argument instead of the > > name to avoid this problem? > > That won't work though .. > I checked into this further, and found that if you run edquota with a numeric > username, it will always assume this this is a UID, even if no user with that > ID exists. > > - Jamie Exactly, not sure if you got my point though. I meant that if edquota always assumes numeric usernames are UID numbers then if you run edquota with the UID number it would always behave as expected. Doesn't matter for now as we have stopped fully numeric userid's from being created anyway. It would probably be a pain for you to change this and potentially break the module on some types of systems. Personally I think edquota should be fixed - I noticed that HP have already done that on their version of Unix. Murray |