[Dovecot] Maildir owner importance

Timo Sirainen tss at iki.fi
Wed Dec 29 13:21:56 EET 2004


On Wed, 2004-12-29 at 13:06 +0200, Timo Sirainen wrote:
> first_valid_gid / last_valid_gid aren't really that important to change.
> They are only extra checks to prevent accidental use of eg. some daemon
> accounts due to unset passwords. So if you are using only virtual users
> and not /etc/passwd at all, it's rather useless to change them.

first/last_valid_uid I mean. The first/last_valid_gid are even less
useful. But sure, setting them can prevent some damage if dovecot-auth
has a security hole.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
URL: <http://dovecot.org/pipermail/dovecot/attachments/20041229/f110fa5d/attachment-0001.bin>


More information about the dovecot mailing list