data:image/s3,"s3://crabby-images/a6b0d/a6b0d3c038d80a02c24ec81df5a18166a5db4448" alt=""
I trying to find out if mailman uses the md5 checksum or this has to be set up with the installation. Any help on this would be greatly appreciated. I have not been able to find it so far.
data:image/s3,"s3://crabby-images/56955/56955022e6aae170f66577e20fb3ce4d8949255c" alt=""
Melinda Gilmore wrote:
I trying to find out if mailman uses the md5 checksum or this has to be set up with the installation. Any help on this would be greatly appreciated. I have not been able to find it so far.
I'm not sure what you're asking, but old versions of Mailman used to use 'crypt' or 'md5' to encrypt list admin and moderator passwords and site and list creator passwords, but it currently uses 'sha'. It will still try 'crypt' and 'md5' on the supplied password if 'sha' doesn't match, and if it gets a 'crypt' or 'md5' match, it will migrate the encrypted password to 'sha'.
In order to compute 'crypt', 'md5' and 'sha' checksums, it uses the builtin Python modules.
-- Mark Sapiro <mark@msapiro.net> The highway is for gamblers, San Francisco Bay Area, California better use your sense - B. Dylan
data:image/s3,"s3://crabby-images/56955/56955022e6aae170f66577e20fb3ce4d8949255c" alt=""
Mark Sapiro wrote:
Melinda Gilmore wrote:
I trying to find out if mailman uses the md5 checksum or this has to be set up with the installation. Any help on this would be greatly appreciated. I have not been able to find it so far.
I'm not sure what you're asking, ...
It occurs to me that what you are asking is if Mailman stores passwords in encrypted form.
The answer is yes (but using sha, not md5) for site, list creator, list admin and list moderator passwords.
The answer is no for list member passwords in current Mailman, but this will change in Mailman 3.0.
It would be complicated to change Mailman 2.1 to encrypt list member passwords because the periodic and on-demand password reminder would have to be replaced with an on-demand password reset or something similar.
-- Mark Sapiro <mark@msapiro.net> The highway is for gamblers, San Francisco Bay Area, California better use your sense - B. Dylan
data:image/s3,"s3://crabby-images/500b6/500b6db67c37c4615bc60a35e5ade42e0af5ac6f" alt=""
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
On Apr 25, 2008, at 11:45 AM, Mark Sapiro wrote:
It would be complicated to change Mailman 2.1 to encrypt list member passwords because the periodic and on-demand password reminder would have to be replaced with an on-demand password reset or something similar.
Although in 2.2 we should kill off monthly password reminders,
implementing a password reset instead, and encrypt user passwords
too. In 3.0 #1 and #3 is done, but not #2.
- -Barry
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.8 (Darwin)
iEYEARECAAYFAkgR/dEACgkQ2YZpQepbvXF1MACaAkDoEejI+z65u9IpsZRKn3mp eyAAniG+mkxOcQv9NNwseRkZmctPP4du =HiXZ -----END PGP SIGNATURE-----
data:image/s3,"s3://crabby-images/a6b0d/a6b0d3c038d80a02c24ec81df5a18166a5db4448" alt=""
What I mean by Checksum is a message bounce like this.
he following message was not processed due to the following reasons: processed.
- The body of the message has a checksum matching those messages already
-----Original Message----- From: Mark Sapiro [mailto:mark@msapiro.net] Sent: Friday, April 25, 2008 11:27 AM To: Melinda Gilmore; mailman-users@python.org Subject: Re: [Mailman-Users] checksums
Melinda Gilmore wrote:
I trying to find out if mailman uses the md5 checksum or this has to be set up with the installation. Any help on this would be greatly appreciated. I have not been able to find it so far.
I'm not sure what you're asking, but old versions of Mailman used to use 'crypt' or 'md5' to encrypt list admin and moderator passwords and site and list creator passwords, but it currently uses 'sha'. It will still try 'crypt' and 'md5' on the supplied password if 'sha' doesn't match, and if it gets a 'crypt' or 'md5' match, it will migrate the encrypted password to 'sha'.
In order to compute 'crypt', 'md5' and 'sha' checksums, it uses the builtin Python modules.
-- Mark Sapiro <mark@msapiro.net> The highway is for gamblers, San Francisco Bay Area, California better use your sense - B. Dylan
data:image/s3,"s3://crabby-images/56955/56955022e6aae170f66577e20fb3ce4d8949255c" alt=""
Melinda Gilmore wrote:
What I mean by Checksum is a message bounce like this.
he following message was not processed due to the following reasons: processed.
- The body of the message has a checksum matching those messages already
Mailman doesn't do this. The only thing close is pipermail attempts to avoid duplicate archive messages, but that's based on message-id, not a checksum.
-- Mark Sapiro <mark@msapiro.net> The highway is for gamblers, San Francisco Bay Area, California better use your sense - B. Dylan
data:image/s3,"s3://crabby-images/c33f1/c33f1e2ef1c82af484de7c3cefd2d10b5928f698" alt=""
Melinda Gilmore wrote:
What I mean by Checksum is a message bounce like this.
he following message was not processed due to the following reasons: processed.
- The body of the message has a checksum matching those messages already
This is an error from Listserv (see <http://8help.osu.edu/33266.html>). This has nothing to do with Mailman.
-- Brad Knowles <brad@python.org> Member of the Python.org Postmaster Team, & Co-moderator of the mailman-users and mailman-developers mailing lists
data:image/s3,"s3://crabby-images/ec664/ec664667bb9cea54a75167301127704b33289f23" alt=""
Melinda Gilmore wrote:
I trying to find out if mailman uses the md5 checksum or this has to be set up with the installation. Any help on this would be greatly appreciated. I have not been able to find it so far.
What do you mean by "uses the md5 checksum"?
-- Brad Knowles <brad@shub-internet.org> LinkedIn Profile: <http://tinyurl.com/y8kpxu>
participants (5)
-
Barry Warsaw
-
Brad Knowles
-
Brad Knowles
-
Mark Sapiro
-
Melinda Gilmore