Skip to Content.
Sympa Menu

en - RE: [sympa-users] Can listmasters/owners issue SET listname DIGEST for a user?

Subject: The mailing list for listmasters using Sympa

List archive

Chronological Thread  
  • From: Steve Shipway <address@concealed>
  • To: "Roger B.A. Klorese" <address@concealed>, "address@concealed" <address@concealed>
  • Subject: RE: [sympa-users] Can listmasters/owners issue SET listname DIGEST for a user?
  • Date: Sun, 2 Mar 2014 06:03:47 +0000

> Is it possible to add a new subscriber directly into (non-default)
> digest format, or to add a user and set their format, by mail as
> listmaster, owner, or moderator, as opposed to depending on them to do
> it for themselves?
...
>Thanks. That, and password approval for admin commands, are significant
>gaps to other list managers.

As you likely know, it is really trivial to forge email, and so allowing
admin commands to be submitted via email (as opposed to the
MD5-hash-authenticaiton-based moderation commands) would be amazingly
insecure, unless you also mandate S/MIME signatures... so I would not want
to have the majority of admin commands able to be done purely via email, or
at least I'd want to be able to disable it.

By 'password approval for admin commands', do you mean asking for
re-authentication by admins when they do a major command via the web? This
would be a good idea, if it were possible to define which commands need the
additional authentication. However, it might cause issues with sites such as
ours which use an external auth mechanism (two-factor via Shibboleth), as in
this case it would not be able to use the web server to handle authentication.

Steve

Steve Shipway
University of Auckland ITS
UNIX Systems Design Lead
address@concealed
Ph: +64 9 373 7599 ext 86487





Archive powered by MHonArc 2.6.19+.

Top of Page