Your message dated Wed, 28 Sep 2005 11:04:51 +0200
with message-id <[EMAIL PROTECTED]>
and subject line bug closed
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 13 May 2005 05:07:44 +0000
>From [EMAIL PROTECTED] Thu May 12 22:07:44 2005
Return-path: <[EMAIL PROTECTED]>
Received: from www.thaiopensource.org (thaiopensource.org) [61.19.242.42] 
        by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
        id 1DWSOm-0000hU-00; Thu, 12 May 2005 22:07:44 -0700
Received: from localhost (localhost.localdomain [127.0.0.1])
        by thaiopensource.org (Postfix) with ESMTP id D7253364063
        for <[EMAIL PROTECTED]>; Fri, 13 May 2005 12:04:50 +0700 (ICT)
Received: from thaiopensource.org ([127.0.0.1])
        by localhost (truffle [127.0.0.1]) (amavisd-new, port 10024)
        with ESMTP id 26965-05 for <[EMAIL PROTECTED]>;
        Fri, 13 May 2005 12:04:50 +0700 (ICT)
Received: by thaiopensource.org (Postfix, from userid 1000)
        id 8935E364076; Fri, 13 May 2005 12:04:50 +0700 (ICT)
Date: Fri, 13 May 2005 12:04:50 +0700
To: Debian Bug Tracking System <[EMAIL PROTECTED]>
Subject: backup-manager: secure repository
Message-ID: <[EMAIL PROTECTED]>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.5.9i
From: [EMAIL PROTECTED] (Jeroen Vermeulen)
X-Virus-Scanned: by amavisd-new-20030616-p10 (Debian) at sipa.or.th
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
        (1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE 
        autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 


Package: backup-manager
Version: 0.5.7-1
Severity: wishlist


Creating a world-readable repository would be a serious security breach.
I may be mistaken, but AFAICS the installation script fails to check
this or warn about it.  It doesn't enforce it in any case; I just
realized I had a world-readable repository in a working setup.

Are there any steps that can be taken to encourage secure configuration,
e.g. creating the repository at installation time with root-only access
rights, or chmod'ing it if it already exists?  Or alternatively, create
the backups with root-only access rights and/or encrypt them.

-- System Information:
Debian Release: 3.1
  APT prefers testing
  APT policy: (500, 'testing'), (50, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.6.11-1-686-smp
Locale: LANG=en_US, LC_CTYPE=en_US (charmap=ISO-8859-1)

Versions of packages backup-manager depends on:
ii  debconf                       1.4.30.13  Debian configuration
management sy
ii  gzip                          1.3.5-9    The GNU compression utility

-- debconf information excluded

--D8DB857414F.1115959689/localhost.localdomain--


---------------------------------------
Received: (at 308897-done) by bugs.debian.org; 28 Sep 2005 09:07:35 +0000
>From [EMAIL PROTECTED] Wed Sep 28 02:07:35 2005
Return-path: <[EMAIL PROTECTED]>
Received: from www.sukria.net [81.56.73.92] 
        by spohr.debian.org with esmtp (Exim 3.36 1 (Debian))
        id 1EKXuY-0004aB-00; Wed, 28 Sep 2005 02:07:34 -0700
Received: by www.sukria.net (Postfix, from userid 1000)
        id 1638621EF79; Wed, 28 Sep 2005 11:04:51 +0200 (CEST)
Date: Wed, 28 Sep 2005 11:04:51 +0200
From: Alexis Sukrieh <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED], [EMAIL PROTECTED]
Subject: bug closed
Message-ID: <[EMAIL PROTECTED]>
Mime-Version: 1.0
Content-Type: text/plain; charset=iso-8859-15
Content-Disposition: inline
X-Editor: Vim http://www.vim.org/
X-Operating-System: Linux/2.6.8-powerpc (ppc)
X-Uptime: 11:03:33 up 15:29,  9 users,  load average: 0.08, 0.02, 0.00
X-PGP-ID: 1EE5DD34
User-Agent: Mutt/1.5.9i
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
        (1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Level: 
X-Spam-Status: No, hits=-3.0 required=4.0 tests=BAYES_00 autolearn=no 
        version=2.60-bugs.debian.org_2005_01_02

Those bugs are closed in sarge now, and they are not open in etch and
sid.


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to