Mercurial > dovecot > original-hg > dovecot-1.2
changeset 7695:5b4e578372f7 HEAD
Added a warning comment to mail_extra_groups.
author | Timo Sirainen <tss@iki.fi> |
---|---|
date | Sat, 16 Feb 2008 16:24:21 +0200 |
parents | 5d4efb4fb414 |
children | f3508f678485 |
files | dovecot-example.conf |
diffstat | 1 files changed, 3 insertions(+), 0 deletions(-) [+] |
line wrap: on
line diff
--- a/dovecot-example.conf Sat Feb 16 16:17:14 2008 +0200 +++ b/dovecot-example.conf Sat Feb 16 16:24:21 2008 +0200 @@ -271,6 +271,9 @@ # Grant access to these extra groups for mail processes. Typical use would be # to give "mail" group write access to /var/mail to be able to create dotlocks. +# WARNING: If your users can create symlinks, this will allow the users to +# read any files that are group-readable by one of these groups! Make sure at +# least all the common mailboxes have 0600 permissions (or a different group). #mail_extra_groups = # Allow full filesystem access to clients. There's no access checks other than