[Mageia-sysadm] Various sympa woes

Michael Scherer misc at zarb.org
Fri Mar 11 02:29:27 CET 2011


Hi,

While debugging various stuff related to smtp, I have notice some
various things : 
- people can subscribe to sympa without using a identity account. I
think we wanted to disable this possibility, but I am not sure. People
cannot change anything, the only possibility is to later unsubscribe. 

While I think this provides a easy way to participate to discussion,
this also could cause trouble as we have enabled the REVIEW command ( as
this was the first thing request by i18n people who are currently using
sympa, like 3 requests in the 4 first hour  ). And so I fear that some
spammer could have automated mail harvesting on sympa.

People can only subscribe and unsubscribe using the web interface and
cannot change much. On the other hand, I think they can change config
using the mail interface, and there isn't much to change if not admin or
moderators. 

If someone later subscribe to identity, it should also be painless,
since ( and that's the 2nd issue ), sympa use email as primary key.

We can decide to do nothing, we can remove this from the templates, or
we could ( not sure ) restrict login to people in the ldap.

2nd issue, email. If someone change email in catdap, he is basically
screwed on sympa side, and admins must change it. As i suspect people
will soon start to use new aliases, we should maybe start to think of
it.

3rd issue, not related to this, but while I am speaking of sympa, it
seems that sympa interface mismanage its cache from time to time. And
so, the index page is wrong. If someone want to look at the bug tracker,
this would be helpful. 

I propose that the first step to resolution would be to find when does
it occurs, maybe using a basic perl script to monitor and send mail ?


-- 
Michael Scherer



More information about the Mageia-sysadm mailing list