Re: [Dovecot] Security issue #5: mail_extra_groups setting is often used insecurely

2008-03-04 Thread Karsten Bräckelmann
On Tue, 2008-03-04 at 23:41 +0100, Karsten Bräckelmann wrote: > On Wed, 2008-03-05 at 00:29 +0200, Timo Sirainen wrote: > > Oh, this is actually harmless. You can get rid of it (and improve the > > performance) by setting dotlock_use_excl=yes. > > > > But maybe I should release v1.0.12 anyway wit

Re: [Dovecot] Security issue #5: mail_extra_groups setting is often used insecurely

2008-03-04 Thread Timo Sirainen
On Tue, 2008-03-04 at 23:41 +0100, Karsten Bräckelmann wrote: > On Wed, 2008-03-05 at 00:29 +0200, Timo Sirainen wrote: > > > > > a) Upgrade to v1.0.11 and use the new mail_privileged_group setting > > > > instead of mail_extra_groups. > > > > > > We tried this but now the mail.log has a number o

Re: [Dovecot] Security issue #5: mail_extra_groups setting is often used insecurely

2008-03-04 Thread Karsten Bräckelmann
On Wed, 2008-03-05 at 00:29 +0200, Timo Sirainen wrote: > > > a) Upgrade to v1.0.11 and use the new mail_privileged_group setting > > > instead of mail_extra_groups. > > > > We tried this but now the mail.log has a number of lines : > > « dovecot: IMAP(someuser): open(/var/mail/.temp.) failed

Re: [Dovecot] Security issue #5: mail_extra_groups setting is often used insecurely

2008-03-04 Thread Karsten Bräckelmann
On Tue, 2008-03-04 at 08:35 +0200, Timo Sirainen wrote: > mail_extra_groups=mail setting is often used insecurely to give Dovecot > access to create dotlocks to /var/mail directory. If you don't use > mboxes in /var/mail, make sure this setting is cleared. > > If you do use /var/mail mboxes and Do

Re: [Dovecot] Security issue #5: mail_extra_groups setting is often used insecurely

2008-03-04 Thread Timo Sirainen
On Tue, 2008-03-04 at 13:42 +0100, Benoit Branciard wrote: > Timo Sirainen a écrit : > >>> 2a) mbox: Any files/directories under mail group-writable directories > >>> can be created/deleted/renamed by symlinking the directory under > >>> ~/mail/. For example ln -s /var/mail ~/mail/var, DELETE var/r

Re: [Dovecot] Security issue #5: mail_extra_groups setting is often used insecurely

2008-03-04 Thread Benoit Branciard
Timo Sirainen a écrit : 2a) mbox: Any files/directories under mail group-writable directories can be created/deleted/renamed by symlinking the directory under ~/mail/. For example ln -s /var/mail ~/mail/var, DELETE var/root will happily delete root's mailbox. This I hadn't thought about before.

Re: [Dovecot] Security issue #5: mail_extra_groups setting is often used insecurely

2008-03-04 Thread Timo Sirainen
On Mar 4, 2008, at 10:50 AM, Benoit Branciard wrote: Timo Sirainen a écrit : mail_extra_groups=mail setting is often used insecurely to give Dovecot access to create dotlocks to /var/mail directory. If you don't use mboxes in /var/mail, make sure this setting is cleared. [...] 2a) mbox: Any f

Re: [Dovecot] Security issue #5: mail_extra_groups setting is often used insecurely

2008-03-04 Thread Odhiambo Washington
On Tue, Mar 4, 2008 at 9:50 AM, Timo Sirainen <[EMAIL PROTECTED]> wrote: > And one more thing: v1.0.rc2 will be released in a day or two with this > change but I'd rather fix a few more bugs before that. If you need it > already, use the nightly snapshot: > http://dovecot.org/nightly/dovecot-lates

Re: [Dovecot] Security issue #5: mail_extra_groups setting is often used insecurely

2008-03-04 Thread Benoit Branciard
Timo Sirainen a écrit : mail_extra_groups=mail setting is often used insecurely to give Dovecot access to create dotlocks to /var/mail directory. If you don't use mboxes in /var/mail, make sure this setting is cleared. [...] 2a) mbox: Any files/directories under mail group-writable directories ca

Re: [Dovecot] Security issue #5: mail_extra_groups setting is often used insecurely

2008-03-03 Thread Timo Sirainen
And one more thing: v1.0.rc2 will be released in a day or two with this change but I'd rather fix a few more bugs before that. If you need it already, use the nightly snapshot: http://dovecot.org/nightly/dovecot-latest.tar.gz signature.asc Description: This is a digitally signed message part

Re: [Dovecot] Security issue #5: mail_extra_groups setting is often used insecurely

2008-03-03 Thread Timo Sirainen
Oh, forgot to mention: Thanks to John Rowe for bugging me about this until I did more than just add some warning comments to dovecot-example.conf. :) signature.asc Description: This is a digitally signed message part

[Dovecot] Security issue #5: mail_extra_groups setting is often used insecurely

2008-03-03 Thread Timo Sirainen
mail_extra_groups=mail setting is often used insecurely to give Dovecot access to create dotlocks to /var/mail directory. If you don't use mboxes in /var/mail, make sure this setting is cleared. If you do use /var/mail mboxes and Dovecot gives permission errors without it, do one of the following