Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 167762 - spamassassin (spamd) is running root account in default install.
Summary: spamassassin (spamd) is running root account in default install.
Status: RESOLVED WORKSFORME
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Perl team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-02-20 17:29 UTC by Eero Volotinen
Modified: 2008-02-27 18:22 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Eero Volotinen 2007-02-20 17:29:55 UTC
spamassassin (spamd) is running root account in default install. looks like big security hole to me?

Reproducible: Always
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2007-02-20 17:41:47 UTC
So read the notes in /etc/conf.d/spamd and configure it to run as another user according to your needs? There's really no good default user for this, dunno what are you expecting here.
Comment 2 Eero Volotinen 2007-02-20 17:51:12 UTC
instead of running it root that can be really big security hole,
ebuild should create user like spamd and run spamd as it.
Comment 3 Jakub Moc (RETIRED) gentoo-dev 2007-02-20 17:55:34 UTC
Except that it won't work for tons of users... You need to configure stuff as fit for your particular configuration, MTA etc. etc. If you have no clue then chances are you shouldn't be running such daemons at all.
Comment 4 Eero Volotinen 2007-02-20 19:05:57 UTC
.. but at least isn't security hole by default. If someone need to run it as root, he can configure it by hand.

other distributions run spamd as spamd by default.

Comment 5 Samuli Suominen (RETIRED) gentoo-dev 2007-02-20 19:13:16 UTC
Option that selects username in spamd conf.d file could be null by default, and init.d script refuse to start without user setting it. Some other daemons allready 
do this, IIRC.
Comment 6 Janne Pikkarainen 2007-05-03 12:47:09 UTC
I agree that some kind of solution for running spamd as some other account as root would be a must-have. A small configure-hell is better than long-running security-hell, right?
Comment 7 Jakub Moc (RETIRED) gentoo-dev 2008-02-27 18:22:33 UTC
Here's a plan, go configure this as you want. Closing a dead bug.