Skip to Content.
Sympa Menu

en - Re: [sympa-users] Can listmasters/owners issue SET listname DIGEST for a user?

Subject: The mailing list for listmasters using Sympa

List archive

Chronological Thread  
  • From: "Roger B.A. Klorese" <address@concealed>
  • To: Steve Shipway <address@concealed>
  • Cc: "address@concealed" <address@concealed>
  • Subject: Re: [sympa-users] Can listmasters/owners issue SET listname DIGEST for a user?
  • Date: Sat, 1 Mar 2014 23:44:37 -0800

<address@concealed> wrote:

> As you likely know, it is really trivial to forge email, and so allowing
> admin commands to be submitted via email (as opposed to the
> MD5-hash-authenticaiton-based moderation commands) would be amazingly
> insecure, unless you also mandate S/MIME signatures...

Or, simply, passwords in the email. Non-academic civilians who just want to
chat about their country dancing have no idea what an S/MIME signature is -
usually their email accounts are at Gmail or Yahoo or even AOL.


> By 'password approval for admin commands', do you mean asking for
> re-authentication by admins when they do a major command via the web?

No. I mean allowing a password to be sent with the command. The extra
confirmation cycle is viewed as unnecessary hassle.


> However, it might cause issues with sites such as ours which use an
> external auth mechanism (two-factor via Shibboleth), as in this case it
> would not be able to use the web server to handle authentication.

Again, civilians, and especially, civilians who want to admin exclusively by
email and not use the web interface.



Archive powered by MHonArc 2.6.19+.

Top of Page