FS#17326 - [ssmtp] setgid mail

Attached to Project: Arch Linux
Opened by Olivier Mehani (shtrom) - Monday, 30 November 2009, 09:54 GMT
Last edited by Pierre Schmitz (Pierre) - Saturday, 16 May 2015, 14:44 GMT
Task Type Feature Request
Category Packages: Extra
Status Closed
Assigned To Pierre Schmitz (Pierre)
Ionut Biru (wonder)
Tom Gundersen (tomegun)
Architecture All
Severity Low
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

When configuring ssmtp from ssmtp.conf, the AuthUser and AuthPass parameter allow te specify credentials to identify to the upstream SMTP relay. It is desirable that this information is not readable by local users. A solution is to `chmod 600` said configuration file. This causes the problem that a local user trying to send email using ssmtp can't read the configuration file anymore.

A solution would be to `chgrp mail /etc/ssmtp.conf`, and give read rights to group mail (640), then `chgrp mail /usr/sbin/ssmtp` and make the binary setgid (chmod g+s).

This way, users can't read the file except when using ssmtp itself, and mail delivery works.

As a side note, maybe would it be wiser to dedicate a specific group (_ssmtp ?) rather than using group mail.
This task depends upon

Closed by  Pierre Schmitz (Pierre)
Saturday, 16 May 2015, 14:44 GMT
Reason for closing:  No response
Comment by Gerardo Exequiel Pozzi (djgera) - Sunday, 04 July 2010, 06:40 GMT
Assigned to Orphan Team.
Comment by Alexander F. Rødseth (xyproto) - Sunday, 11 November 2012, 21:18 GMT
Nothing has happened here for a while. Assigning to last packager.
Comment by Pierre Schmitz (Pierre) - Saturday, 02 November 2013, 22:51 GMT
This package has no maintainer and I have no interest in looking into this issue.
Comment by Alexander F. Rødseth (xyproto) - Saturday, 02 November 2013, 23:13 GMT
Since there is no interest for the orphan ssmtp package, couldn't it be moved to [community] or AUR?
Comment by Olivier Mehani (shtrom) - Sunday, 03 November 2013, 03:21 GMT
I could take up maintainership. I have some experience with AUR, but I'm happy to get myself up to speed if it seems more relevant to keep the package in some other repository.
Comment by Alexander F. Rødseth (xyproto) - Monday, 04 November 2013, 08:46 GMT
Roman Kyrylych is no longer active, he's a "fellow". Please move this package to [community] or AUR if there is not interest for it.

Assigning to the three last packagers.

Loading...