thanks for clarifications Alessadro. but it seems easy if we look from
the socket directory access, but ..

> The socket file is srwxrwxrwx root root in both cases, but the parent 
> directory
> on the locally built server is:
> drwxr-x--- courier courier authdaemon
> whilst on the Debian server it is:
> drwxr-xr-x courier courier authdaemon

anyone that have directory access wil can use authtest..
in debian is just a extra 755 but so any user that have access to
courier group will get information.. still are a hole security so
authtest must be acceded only by admins users.. or i mean only by root
and courier users

i changed and suggest the authtest and any other admin tool must be
only accessed by root and courier user!



>
>
> hth
> Ale
> --
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
> _______________________________________________
> courier-users mailing list
> courier-us...@lists.sourceforge.net
> Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users

Reply via email to