insecure database configuation

Bug #584562 reported by ceg
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
openerp-server (Ubuntu)
Confirmed
Undecided
Unassigned
Nominated for Maverick by agent 8131

Bug Description

Binary package hint: openerp-server

README.debian advices to create an openerp database user like this:

#su - postgres -c "createuser --createdb --no-createrole --pwprompt openerp"

However this advice (and any debconf postinst configuration should probably also contain the "--no-superuser" option, so crateuser does not ask and make the user a superuser. (The openerp user does not need to be able to mess with the whole postgres setup.)

Revision history for this message
agent 8131 (agent-8131) wrote :

Agreed. The documentation /usr/share/doc/openerp-server/README.Debian should be updated to add the "--no-superuser" option.

Changed in openerp-server (Ubuntu):
status: New → Confirmed
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.