Your message dated Thu, 8 Oct 2015 21:01:42 +0200
with message-id <[email protected]>
and subject line Re: Bug#795459: Please close this bug
has caused the Debian Bug report #795459,
regarding exim4: Security problem: cannot symlink client.passwd to secure 
storage
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
795459: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=795459
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: exim4
Version: 4.84-8
Severity: normal

Dear Maintainer,

- might be an upstream issue

* I would like to store passwd.client in an encrypted folder.

* Cannot use hard-links to different fs, sym-links are silently ignored
* by exim.

* As a result I get a security problem because I cannot use a secure,
* encrypted folder to store the passwords.

Did somebody try to do something good by blocking symlinks? Anyhow, you
end up with an insecure configuration (clear text passwords in unsecure
storage).

Thanks
Jürgen

-- Package-specific info:
Exim version 4.84 #3 built 17-Feb-2015 17:45:49
Copyright (c) University of Cambridge, 1995 - 2014
(c) The Exim Maintainers and contributors in ACKNOWLEDGMENTS file, 2007 - 2014
Berkeley DB: Berkeley DB 5.3.28: (September  9, 2013)
Support for: crypteq iconv() IPv6 GnuTLS move_frozen_messages DKIM PRDR OCSP
Lookups (built-in): lsearch wildlsearch nwildlsearch iplsearch cdb dbm dbmjz 
dbmnz dnsdb dsearch nis nis0 passwd
Authenticators: cram_md5 plaintext
Routers: accept dnslookup ipliteral manualroute queryprogram redirect
Transports: appendfile/maildir/mailstore autoreply lmtp pipe smtp
Fixed never_users: 0
Size of off_t: 8
Configuration file is /var/lib/exim4/config.autogenerated

-- System Information:
Debian Release: 8.1
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.16.0-4-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US, LC_CTYPE=de_DE.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages exim4 depends on:
ii  debconf [debconf-2.0]  1.5.56
ii  exim4-base             4.84-8
ii  exim4-daemon-light     4.84-8

exim4 recommends no packages.

exim4 suggests no packages.

-- debconf information excluded

--- End Message ---
--- Begin Message ---
On 2015-10-08 Juergen Pfennig <[email protected]> wrote:
> Hello,

> The received information was helpful. I had a permission problem (some crypto 
> file systems do not implement uids).

> Could you close this bug please?

Hello,

thanks for the followup, closing.

cu Andreas
-- 
`What a good friend you are to him, Dr. Maturin. His other friends are
so grateful to you.'
`I sew his ears on from time to time, sure'

--- End Message ---

Reply via email to