summaryrefslogtreecommitdiffstats
path: root/zarb-ml/mageia-dev/2011-September/008334.html
diff options
context:
space:
mode:
Diffstat (limited to 'zarb-ml/mageia-dev/2011-September/008334.html')
-rw-r--r--zarb-ml/mageia-dev/2011-September/008334.html187
1 files changed, 187 insertions, 0 deletions
diff --git a/zarb-ml/mageia-dev/2011-September/008334.html b/zarb-ml/mageia-dev/2011-September/008334.html
new file mode 100644
index 000000000..c414edc16
--- /dev/null
+++ b/zarb-ml/mageia-dev/2011-September/008334.html
@@ -0,0 +1,187 @@
+<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
+<HTML>
+ <HEAD>
+ <TITLE> [Mageia-dev] [RFC] msec (nail) can't send reports to local users accounts - require an MTA?
+ </TITLE>
+ <LINK REL="Index" HREF="index.html" >
+ <LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20%5BRFC%5D%20msec%20%28nail%29%20can%27t%20send%20reports%20to%20local%0A%20users%20accounts%20-%20require%20an%20MTA%3F&In-Reply-To=%3C4E7C47A2.4040507%40arcor.de%3E">
+ <META NAME="robots" CONTENT="index,nofollow">
+ <META http-equiv="Content-Type" content="text/html; charset=us-ascii">
+ <LINK REL="Previous" HREF="008326.html">
+ <LINK REL="Next" HREF="008337.html">
+ </HEAD>
+ <BODY BGCOLOR="#ffffff">
+ <H1>[Mageia-dev] [RFC] msec (nail) can't send reports to local users accounts - require an MTA?</H1>
+ <B>Florian Hubold</B>
+ <A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20%5BRFC%5D%20msec%20%28nail%29%20can%27t%20send%20reports%20to%20local%0A%20users%20accounts%20-%20require%20an%20MTA%3F&In-Reply-To=%3C4E7C47A2.4040507%40arcor.de%3E"
+ TITLE="[Mageia-dev] [RFC] msec (nail) can't send reports to local users accounts - require an MTA?">doktor5000 at arcor.de
+ </A><BR>
+ <I>Fri Sep 23 10:47:30 CEST 2011</I>
+ <P><UL>
+ <LI>Previous message: <A HREF="008326.html">[Mageia-dev] [RFC] msec (nail) can't send reports to local users accounts - require an MTA?
+</A></li>
+ <LI>Next message: <A HREF="008337.html">[Mageia-dev] [RFC] msec (nail) can't send reports to local users accounts - require an MTA?
+</A></li>
+ <LI> <B>Messages sorted by:</B>
+ <a href="date.html#8334">[ date ]</a>
+ <a href="thread.html#8334">[ thread ]</a>
+ <a href="subject.html#8334">[ subject ]</a>
+ <a href="author.html#8334">[ author ]</a>
+ </LI>
+ </UL>
+ <HR>
+<!--beginarticle-->
+<PRE>Am 22.09.2011 23:11, schrieb andre999:
+&gt;<i> Florian Hubold a &#233;crit :
+</I>&gt;&gt;<i> Am 22.09.2011 00:09, schrieb Luc Menut:
+</I>&gt;&gt;&gt;<i> Le 21/09/2011 20:35, Florian Hubold a &#233;crit :
+</I>&gt;&gt;&gt;&gt;<i> Hello,
+</I>&gt;&gt;&gt;&gt;<i>
+</I>&gt;&gt;&gt;&gt;<i> during validation of validation of msec/sectool update candidates,
+</I>&gt;&gt;&gt;&gt;<i> a problem showed up: <A HREF="https://bugs.mageia.org/show_bug.cgi?id=1621">https://bugs.mageia.org/show_bug.cgi?id=1621</A>
+</I>&gt;&gt;&gt;<i> ...
+</I>&gt;&gt;&gt;&gt;<i> But if we want security reports to be sent to local users if they
+</I>&gt;&gt;&gt;&gt;<i> specify so, how to proceed further?
+</I>&gt;&gt;&gt;<i>
+</I>&gt;&gt;&gt;<i> msec can work very well without sending these reports by email; all
+</I>&gt;&gt;&gt;<i> the security's reports are available in /var/log/security, and msec
+</I>&gt;&gt;&gt;<i> notifies the user about this at each time it runs, so sendmail is
+</I>&gt;&gt;&gt;<i> absolutely not mandatory.
+</I>&gt;&gt;&gt;<i> So I think that msec shouldn't have a Requires on sendmail-command,
+</I>&gt;&gt;&gt;<i> eventually it can be a Suggest.
+</I>&gt;&gt;&gt;<i>
+</I>&gt;&gt;&gt;<i> But perhaps we could/should change the configuration of msec to not
+</I>&gt;&gt;&gt;<i> send email by default, by adding MAIL_WARN=no in
+</I>&gt;&gt;&gt;<i> /etc/security/msec/security.conf.
+</I>&gt;&gt;&gt;<i>
+</I>&gt;&gt;<i> So, to summarize, there happen to be multiple solutions here:
+</I>&gt;&gt;<i>
+</I>&gt;&gt;<i> 1. do NOT require an MTA, let users manually read reports from
+</I>&gt;&gt;<i> /var/log/security
+</I>&gt;&gt;<i> maybe even remove nail from msec Requires as it is currently
+</I>&gt;&gt;<i> non-functional.
+</I>&gt;<i>
+</I>&gt;<i> Reading from /var/log/security is not especially user-friendly, and will be
+</I>&gt;<i> ignored by less savy users.
+</I>Less savvy users might also not want to read security reports, also it would
+mean they
+can't interpret them properly or fix the cause of reported problems, no?
+&gt;<i>
+</I>&gt;&gt;<i> Also Luc's proposal cited above could be realized.
+</I>&gt;<i>
+</I>&gt;<i> see below.
+</I>&gt;<i>
+</I>&gt;&gt;<i> 2. do require sendmail-command, which will pose a problem to users
+</I>&gt;&gt;<i> installing from the CLI, because they are presented with a choice:
+</I>&gt;&gt;<i>
+</I>&gt;&gt;<i> One of the following packages is required:
+</I>&gt;&gt;<i> 1 dma
+</I>&gt;&gt;<i> 2 ssmtp
+</I>&gt;&gt;<i> 3 postfix
+</I>&gt;&gt;<i> 4 sendmail
+</I>&gt;&gt;<i> 5 msmtp
+</I>&gt;&gt;<i> Please make a selection:
+</I>&gt;&gt;<i>
+</I>&gt;&gt;<i> Additionally this will force an MTA onto every default installation and
+</I>&gt;&gt;<i> every
+</I>&gt;&gt;<i> installation that currently has msec installed.
+</I>&gt;<i>
+</I>&gt;<i> Solution 3 avoids the complication of choosing, with virtually no disadvantage.
+</I>&gt;<i>
+</I>&gt;&gt;<i> 3. do require dma, which is a rather minimal MTA, and delivers without
+</I>&gt;&gt;<i> configuration
+</I>&gt;&gt;<i> Please see <A HREF="https://bugs.mageia.org/show_bug.cgi?id=2255#c36">https://bugs.mageia.org/show_bug.cgi?id=2255#c36</A> for details.
+</I>&gt;&gt;<i> This would also allow coexistence with an already-installed MTA, IIUC.
+</I>&gt;<i>
+</I>&gt;<i> (dragonfly mail agent)
+</I>&gt;<i> If this works, I'd say that it is the best solution, since it is very compact
+</I>&gt;<i> (64k), and virtually every system will have the DNS it requires installed.
+</I>&gt;<i> (Unless of course they don't have Internet or network access. In which case
+</I>&gt;<i> msec would not be particularly important.)
+</I>&gt;<i> Note that it is only at version 0.2 (or 0.3 upstream), so we should test it
+</I>&gt;<i> carefully.
+</I>&gt;<i>
+</I>&gt;&gt;<i> 4. Try to fix nail, which is required by msec and so in every default
+</I>&gt;&gt;<i> installation,
+</I>&gt;&gt;<i> so that it is able to deliver mail by itself, without sendmail.
+</I>&gt;<i>
+</I>&gt;<i> Solution #3 seems much better in every respect.
+</I>&gt;<i>
+</I>&gt;&gt;<i> Please give your votes.
+</I>&gt;<i>
+</I>&gt;<i> Solution 3, with changes/verifications noted below.
+</I>&gt;<i> Since it is much simpler for the end-user to always have the capability to
+</I>&gt;<i> send security alerts if an email address is entered, without installing
+</I>&gt;<i> anything extra.
+</I>&gt;<i>
+</I>&gt;<i> There are 2 options at the bottom of the first security page of msec, which
+</I>&gt;<i> should already realise Luc's proposals. They may have to be fixed.
+</I>&gt;<i>
+</I>&gt;<i> a) An option to send a security alert by email, where one enters the email
+</I>&gt;<i> address. By default it is checked.
+</I>&gt;<i> However, if no valid format email address is entered, an email should _not_
+</I>&gt;<i> be sent.
+</I>&gt;<i> As well, we should display something similar to
+</I>&gt;<i> &quot;(Enter {userid}@localhost for a local user.)&quot;,
+</I>&gt;<i> to help ensure that the user enters a valid local address.
+</I>&gt;<i> (Note that there are multi-line descriptions for all the other options above
+</I>&gt;<i> on the same page, so this would fit nicely.)
+</I>&gt;<i>
+</I>&gt;<i> b) An option to display security alerts on the desktop. Again, checked by
+</I>&gt;<i> default. They should probably remain visible until the user dismisses them.
+</I>&gt;<i> (They currently display for a few seconds, then disappear.)
+</I>&gt;<i>
+</I>&gt;<i> My 2 cents :)
+</I>&gt;<i>
+</I>Feel free to send patches for a) and b).
+</PRE>
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+<!--endarticle-->
+ <HR>
+ <P><UL>
+ <!--threads-->
+ <LI>Previous message: <A HREF="008326.html">[Mageia-dev] [RFC] msec (nail) can't send reports to local users accounts - require an MTA?
+</A></li>
+ <LI>Next message: <A HREF="008337.html">[Mageia-dev] [RFC] msec (nail) can't send reports to local users accounts - require an MTA?
+</A></li>
+ <LI> <B>Messages sorted by:</B>
+ <a href="date.html#8334">[ date ]</a>
+ <a href="thread.html#8334">[ thread ]</a>
+ <a href="subject.html#8334">[ subject ]</a>
+ <a href="author.html#8334">[ author ]</a>
+ </LI>
+ </UL>
+
+<hr>
+<a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev
+mailing list</a><br>
+</body></html>