Subject: The mailing list for listmasters using Sympa
List archive
Re: [sympa-users] Is initial account password only intended for first login ?
- From: address@concealed
- To: Peter Farmer <address@concealed>
- Cc: address@concealed
- Subject: Re: [sympa-users] Is initial account password only intended for first login ?
- Date: Thu, 12 Oct 2006 17:36:49 +0200
Peter Farmer wrote:
SYMPAthisers,True : the password is computed (predictable) so there is no need to store it anywhere unless the user as some other attributes. Of course this is a security issue : if some one catch the parameter cookie in sympa.conf, he can create user/password couple. In addition password are stored with reversible encryption : this is another security issue.
What is the intended lifespan of the inital password sent to new accounts ?
Can a user just continue to use it or are they required to change it within a
given period of time (as a confirmation of the email address ?)
After account creation it seems to be valid for general use of the account
including posting. But an entry does not appear in the users database table
for the account until its password is changed.
And more significanty the account seems to disappear (expire ?) after a coupleNot at all. We want to change this in a way described in sympa project direction : http://www.sympa.org/wiki/doku.php?id=project_direction (see section authentication and section sessionning)
of days if I dont subscribe to a list straight away !
So from the observed behaviour , I am presuming users are required to update
their password to complete the opt-in process ?
This is a wiki (Dokuwiki) . Please log in (using your email and sympa password) in ordre to add comment to this page.
Regards
Serge
-
[sympa-users] Is initial account password only intended for first login ?,
Peter Farmer, 10/12/2006
- Re: [sympa-users] Is initial account password only intended for first login ?, serge . aumont, 10/12/2006
- Re: [sympa-users] Is initial account password only intended for first login ?, Olivier Salaün - CRU, 10/20/2006
Archive powered by MHonArc 2.6.19+.