Gosa risking passwords being logged by sudo (Was: Is LWAT completely broken in Squeeze?)

2010-08-23 Thread Petter Reinholdtsen
[Finn-Arne Johansen] > Well, I had a lot of lines in the log with usernames/passwords when > creating users. Maybe it was because I had added a user in > /etc/sudoers ? The fix for this is to change gosa and the hooks to pass the passwords in the environment or using stdin, to make sure the passwo

Re: Is LWAT completely broken in Squeeze?

2010-08-23 Thread Petter Reinholdtsen
[Finn-Arne Johansen] > To answer the original question: > Is LWAT completetly broken in Squeeze? > The answer is no. > There has been changes in the setup in debian-edu, which calls for > (slightly) different config-file for lwat, and for new templates. Actually, for Debian Edu, the answer is yes

Re: Is LWAT completely broken in Squeeze?

2010-08-23 Thread Finn-Arne Johansen
On 24. aug. 2010 02:26, Andreas B. Mundt wrote: >> 2. The addition of kerberos calls for some hooks. gosa tries to solve >> this by setting passwords using sudo, which thankfully fails, or else >> everyone with access to the auth-file could read all the passwords given >> to each user. not that muc

Re: ldap/gosa postcreation and kerberos password synchronization

2010-08-23 Thread Finn-Arne Johansen
On 23. aug. 2010 21:00, Andreas B. Mundt wrote: >> what if the gosa web server is not the homedirectory server, and maybe >> even not the ldap-server ? >> What about other users that create php-scripts that also calls the gosa >> sudo-tools for debian, changing passowrds for the teachers and admins

Re: Is LWAT completely broken in Squeeze?

2010-08-23 Thread Andreas B. Mundt
Hi, On Mon, Aug 23, 2010 at 06:42:58PM +0200, Finn-Arne Johansen wrote: > On 13. aug. 2010 13:12, Holger Levsen wrote: > > On Montag, 2. August 2010, Finn-Arne Johansen wrote: [...] > >> release a 0.18 which works with squeeze. > >> > >> Not sure if all patches will make it into 0.18, though. > >>

Re: ldap/gosa postcreation and kerberos password synchronization

2010-08-23 Thread Andreas B. Mundt
Hi, On Mon, Aug 23, 2010 at 06:24:45PM +0200, Finn-Arne Johansen wrote: > On 12. mai 2010 19:26, Andreas B. Mundt wrote: > > I am currently thinking about how to handle the post-creation, > > post-password-change and related stuff properly. > > > > So far, I use the draft-script attached below whi

debian-edu-config_1.443~svn68794_i386.changes ACCEPTED

2010-08-23 Thread Skolelinux archive Installer
Accepted: debian-edu-config_1.443~svn68794.dsc to pool/local/d/debian-edu-config/debian-edu-config_1.443~svn68794.dsc debian-edu-config_1.443~svn68794.tar.gz to pool/local/d/debian-edu-config/debian-edu-config_1.443~svn68794.tar.gz debian-edu-config_1.443~svn68794_all.deb to pool/local/d/deb

Re: Is LWAT completely broken in Squeeze?

2010-08-23 Thread Finn-Arne Johansen
On 13. aug. 2010 13:12, Holger Levsen wrote: > Hi Finn-Arne, > > On Montag, 2. August 2010, Finn-Arne Johansen wrote: >> Last time i checked, I had no problem getting it to work. The plan is to >> release a 0.18 which works with squeeze. >> >> Not sure if all patches will make it into 0.18, though

Re: ldap/gosa postcreation and kerberos password synchronization

2010-08-23 Thread Finn-Arne Johansen
On 12. mai 2010 19:26, Andreas B. Mundt wrote: > I am currently thinking about how to handle the post-creation, > post-password-change and related stuff properly. > > So far, I use the draft-script attached below which is run by the gosa > postcreation hook (www-data added to sudoers file) to handl

Re: Gnash 0.8.8 backported to Lenny

2010-08-23 Thread Petter Reinholdtsen
[Petter Reinholdtsen] > Visiting http://www2.nrk.no/spill/?spill=jokernord > and > http://www.aftenposten.no/video/article3497522.ece > gave me the > graphis but no sound. No idea what is going on, but I saw the missing > sound issue with my build as well. I found the cause of the missing sound.