Bug#773237: dovecot-core: Potentially dangerous modification of a configuration file

2014-12-15 Thread Santiago Vila
retitle 773237 dovecot-core: should not use ucf for 10-ssl.conf and modify the file at the same time thanks This is a better title. It's not really that modifying 10-ssl.conf is "dangerous", it's simply not the right thing to do. If we take a newly installed wheezy system, accept the 10-ssl.con

Bug#773237: dovecot-core: Potentially dangerous modification of a configuration file

2014-12-15 Thread Santiago Vila
On Mon, Dec 15, 2014 at 10:02:56PM +0100, Santiago Vila wrote: > Suppose I had the old configuration file served by puppet. The upgrade > modifies the file, then puppet restores the file to its original state. > Then the next upgrade will change the file to the new ucf default, > which may be compl

Bug#773237: dovecot-core: Potentially dangerous modification of a configuration file

2014-12-15 Thread Santiago Vila
Package: dovecot-core Version: 1:2.2.13-11 Severity: serious The postinst for this package has a line like this one: echo \# old config >> /etc/dovecot/conf.d/10-ssl.conf Please *don't* do that. It does not only violate the spirit of policy (user changes should be preserved), it is also