Mark Sapiro wrote:
> This is a normal message. It probably should specify the list but it
> doesn't. It has nothing to do with public/private archives. It has to
> do with whether the membership roster is available to anyone or not.
> I.e., the Privacy options...->Subscription rules->private_roster
> setting. If the roster is not available to anyone, we are concerned
> about invalid login attempts to the options page.
> 
> If, for example, we just said 'invalid password' to the user who
> attempts to login with a bad password, someone could use that response
> to verify whether or not an address was subscribed to the list, thus
> at least partially defeating the privacy of the membership list, so we
> just tell the user the login is unsuccessful, but not why, and we log
> the event in 'mischief' in case it is really part of an attempt to
> probe the membership list.
> 
> In most cases, these log entries are really legitimate options page
> login attempts by members who forgot or mistyped their password.

Hi Mark,

Thank you.  I see the error was on my lack of clearly reading the error 
message.  ;-)

Thanks,

-Jim P.

------------------------------------------------------
Mailman-Users mailing list
Mailman-Users@python.org
http://mail.python.org/mailman/listinfo/mailman-users
Mailman FAQ: http://www.python.org/cgi-bin/faqw-mm.py
Searchable Archives: http://www.mail-archive.com/mailman-users%40python.org/
Unsubscribe: 
http://mail.python.org/mailman/options/mailman-users/archive%40jab.org

Security Policy: 
http://www.python.org/cgi-bin/faqw-mm.py?req=show&file=faq01.027.htp

Reply via email to