Skip to Content.
Sympa Menu

devel - [sympa-developpers] Usage of "cookie" configuration parameter

Subject: Developers of Sympa

List archive

Chronological Thread  
  • From: "Stefan Hornburg (Racke)" <address@concealed>
  • To: address@concealed
  • Subject: [sympa-developpers] Usage of "cookie" configuration parameter
  • Date: Mon, 11 Jan 2021 09:26:09 +0100

Hello,

config schema says about "cookie":

This allows generated authentication keys to differ from a site to another.
It is also used for encryption of user
passwords stored in the database. The presence of this string is one reason
why access to \"sympa.conf\" needs to be
restricted to the \"sympa\" user.\nNote that changing this parameter will
break all HTTP cookies stored in users'
browsers, as well as all user passwords and lists X509 private keys. To
prevent a catastrophe, Sympa refuses to start if
this \"cookie\" parameter was changed."

Is this still in use? It is not present in the skeleton sympa.conf and Sympa
seems to work fine without it.

I need to know that so I can determine whether I can eliminate it from the
Debian package.

Regards
Racke

--
Ecommerce and Linux consulting + Perl and web application programming.
Debian and Sympa administration. Provisioning with Ansible.

Attachment: OpenPGP_signature
Description: OpenPGP digital signature



  • [sympa-developpers] Usage of "cookie" configuration parameter, Stefan Hornburg (Racke), 01/11/2021

Archive powered by MHonArc 2.6.19+.

Top of Page