dovecot-1.1: Added a warning comment to mail_extra_groups.

dovecot at dovecot.org dovecot at dovecot.org
Sat Feb 16 16:24:12 EET 2008


details:   http://hg.dovecot.org/dovecot-1.1/rev/39c2f2adfed1
changeset: 7256:39c2f2adfed1
user:      Timo Sirainen <tss at iki.fi>
date:      Sat Feb 16 16:24:20 2008 +0200
description:
Added a warning comment to mail_extra_groups.

diffstat:

1 file changed, 3 insertions(+)
dovecot-example.conf |    3 +++

diffs (13 lines):

diff -r cd7eeb8cc7fc -r 39c2f2adfed1 dovecot-example.conf
--- a/dovecot-example.conf	Sat Feb 16 16:17:17 2008 +0200
+++ b/dovecot-example.conf	Sat Feb 16 16:24:20 2008 +0200
@@ -271,6 +271,9 @@
 
 # Grant access to these extra groups for mail processes. Typical use would be
 # to give "mail" group write access to /var/mail to be able to create dotlocks.
+# WARNING: If your users can create symlinks, this will allow the users to
+# read any files that are group-readable by one of these groups! Make sure at
+# least all the common mailboxes have 0600 permissions (or a different group).
 #mail_extra_groups =
 
 # Allow full filesystem access to clients. There's no access checks other than


More information about the dovecot-cvs mailing list