On Monday 27 August 2007, Ludovic Drolez wrote: > I've just added a new db_subst with an empty value in the postinst. It > should fix the problem. (db_subst "backuppc/configuration-note" "pass" > "")
I've taken a look at the code and IMO you should also db_reset the variable immediately after the the db_go in backuppc.config. That seems by far the most natural place to do it and ensures the password is visible only for the shortest time possible. Note that the db_reset in the postinst is still needed to reset values for existing installations on upgrade, but that could then be dropped after lenny has been released. Are you also planning to fix this issue for stable? IMO it should be. Cheers, FJP
signature.asc
Description: This is a digitally signed message part.