Bug#402010: How to deal with #402010?

2008-04-05 Thread sean finney
hi, a few more ideas for you to think about: - create a user specific to the package, and 1: use a setuid wrapper binary for doing all ldap communications or 2: use some kind of user-restricted fastcgi type setup instead of standard apache mod_php/python/whatever or 3: run a seperate

Bug#402010: How to deal with #402010?

2008-04-05 Thread Cajus Pollmeier
The problem is that these aspects are not packagable as some kind of fire and forget installation. I'd prefer the way Roland proposed, using some kind of # cat /etc/apache2/conf.d/gosa.conf Alias /gosa /usr/share/gosa/html Location /gosa include /etc/gosa/gosa.secrets /Location #

Bug#402010: How to deal with #402010?

2008-04-05 Thread sean finney
hi, On Saturday 05 April 2008 11:26:14 am Cajus Pollmeier wrote: The problem is that these aspects are not packagable as some kind of fire and forget installation. I'd prefer the way Roland proposed, using some kind of option 3 could work out of the box, though it just requires more initial

Bug#402010: How to deal with #402010?

2008-04-05 Thread Cajus Pollmeier
Am 05.04.2008 um 11:59 schrieb sean finney: hi, On Saturday 05 April 2008 11:26:14 am Cajus Pollmeier wrote: The problem is that these aspects are not packagable as some kind of fire and forget installation. I'd prefer the way Roland proposed, using some kind of option 3 could work out of

Bug#402010: How to deal with #402010?

2008-04-04 Thread Roland Mas
Cajus Pollmeier, 2008-04-04 09:18:37 +0200 : Hi, my position to this bug is written down in the bugtracker and I don't consider this a bug. Any opinions about what to do with it? It would apply to virtually any kind of web application accessing some kind of database/ldap passwords somewhere

Bug#402010: How to deal with #402010?

2008-04-04 Thread Cajus Pollmeier
Am Freitag, 4. April 2008 11:50:42 schrieb Holger Levsen: Hi, On Friday 04 April 2008 09:18, Cajus Pollmeier wrote: to virtually any kind of web application accessing some kind of database/ldap passwords somewhere in the filesystem. I dont consider a web application which is used to

Bug#402010: How to deal with #402010?

2008-04-04 Thread Holger Levsen
Hi, On Friday 04 April 2008 09:18, Cajus Pollmeier wrote: to virtually any kind of web application accessing some kind of database/ldap passwords somewhere in the filesystem. I dont consider a web application which is used to configure the LDAP database and FAI configuration (to install and

Bug#402010: How to deal with #402010?

2008-04-04 Thread Jon Dowland
On Fri, Apr 04, 2008 at 12:22:05PM +0200, Cajus Pollmeier wrote: As said - I'm not responsible for the webserver setup of other people. Sure, I can put it inside the README and close this bug - waiting until the next one comes around and urges me to do something about it again. Ah wait, I can

Bug#402010: How to deal with #402010?

2008-04-04 Thread Holger Levsen
Hi, On Friday 04 April 2008 12:22, you wrote: In this bug are several suggestions how to implement a way better mechanism to deal with the password then the current one. If you read the comments, I'll see that it is not possible to use these suggestions. Besides maybe the last one, but