Re: [Dovecot] Question re: filesystem permissions

2014-01-08 Thread Steffen Kaiser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Wed, 8 Jan 2014, Charles Marcus wrote: On 2014-01-07 1:46 PM, Charles Marcus wrote: Anyway this is the default for Dovecot quite some time, so reckon someone gave it a thought... *What* is the default. Are you saying all of the permissions I

Re: [Dovecot] Question re: filesystem permissions

2014-01-08 Thread Charles Marcus
On 2014-01-07 1:46 PM, Charles Marcus wrote: Anyway this is the default for Dovecot quite some time, so reckon someone gave it a thought... *What* is the default. Are you saying all of the permissions I showed are correct except the ones you mentioned? But most importantly - *where is this

Re: [Dovecot] Question re: filesystem permissions

2014-01-07 Thread Charles Marcus
On 2014-01-07 9:30 AM, Thomas Leuxner wrote: * Charles Marcus 2014.01.07 15:05: Ok, thanks Thomas... but I'm really looking for what Timo says is the correct and proper permissions for a virtual setup like this. I suggest you don't start posts 'Hi all' then going forward. Well, that wasn't

Re: [Dovecot] Question re: filesystem permissions

2014-01-07 Thread Thomas Leuxner
* Charles Marcus 2014.01.07 15:05: > Ok, thanks Thomas... but I'm really looking for what Timo says is > the correct and proper permissions for a virtual setup like this. I suggest you don't start posts 'Hi all' then going forward. Anyway this is the default for Dovecot quite some time, so reck

Re: [Dovecot] Question re: filesystem permissions

2014-01-07 Thread Charles Marcus
On 2014-01-07 8:42 AM, Thomas Leuxner wrote: * Charles Marcus 2014.01.06 21:23: Hi Charles, /var/vmail/example1.com 777 $ ls -al /var/vmail/domains/leuxner.net/ drwx--S--- 4 vmail vmail 4096 Sep 8 18:22 tlx Suffices to have rwx for the 'vmail' user only IMHO. Note the 'setgid bit (2700

Re: [Dovecot] Question re: filesystem permissions

2014-01-07 Thread Thomas Leuxner
* Charles Marcus 2014.01.06 21:23: Hi Charles, > /var/vmail/example1.com 777 $ ls -al /var/vmail/domains/leuxner.net/ drwx--S--- 4 vmail vmail 4096 Sep 8 18:22 tlx Suffices to have rwx for the 'vmail' user only IMHO. Note the 'setgid bit (2700) inheriting the group 'vmail' across dirs. Re

[Dovecot] Question re: filesystem permissions

2014-01-06 Thread Charles Marcus
Hi all, I want to make sure the filesystems are correct/optimal and secure as possible. This is a virtual hosting setup only (no system users), and dovecot is currently running in high performance mode (I'm thinking I want to change that too, so wondering if that would affect the permissions