[ML-General] Anyone else having trouble changing their Mailman settings?

Arthur Arthur at cd-net.net
Sat May 7 11:35:15 CDT 2016


Hey folks,

I'd like to check with you all and see if Mailman is working correctly.

You can check if you can change your settings at
http://lists.makerslocal.org//mailman/options/general/  Yes, I know it has
two slashes after the domain name, but I'm just a regular user looking at
the page.

I'd appreciate it if someone would double check my findings, since I can't
seem to get things to work correctly.


   - Mailman refuses to save any settings, and just bounces a user back to
   the password screen when clicking save, or trying to view all subscriptions.
      - Steps to Reproduce:  Log in, then click "List my other
      subscriptions"
      - Mitigation:  ????? (I have no clue)
   - No HTTPS, so passwords are sent in plain text over the air.
      - Steps to Reproduce:  Try to visit the https page and, recieve a
      certificate error.
      - Mitigation:  Switch to HTTPS only, with a valid (default trusted)
      certificate
   - Passwords are stored in plain text on the server.
      - Steps to Reproduce:  Request a password reminder, which just
      E-Mails your password to you!
      - Mitigation:  Update to Mailman 3.  Mailman 2 does not support
      password hashing.


While the security issues are a big deal, my problem is I can't do things
like set digest mode, or change any settings for that matter.  I'd
appreciate it if someone else would check and see if they're having the
same issues.

-- 
Sincerely,
Arthur Moore
(256) 277-1001
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.makerslocal.org/pipermail/general/attachments/20160507/f90e82aa/attachment.html>


More information about the general mailing list