Re: 2.8.0 and newly strict checking

From: Murray S. Kucherawy <>
Date: Tue, 5 Mar 2013 22:21:23 -0800 (PST)

On Tue, 5 Mar 2013, Doug Barton wrote:
> I already described what failed, and what worked. If you try testing it
> with that environment and cannot reproduce the failure let me know, and
> I will try to find time to try this patch, but it may be a while.

Here's what I tried. I even used your filenames.

medusa# ls -ld / /var /var/db /var/db/opendkim /var/db/opendkim/
drwxr-xr-x 27 root wheel 1024 May 3 2012 /
drwxr-xr-x 25 root wheel 512 Feb 26 09:06 /var
drwxr-xr-x 18 root wheel 512 Mar 5 22:06 /var/db
drwx------ 2 root wheel 512 Mar 5 22:07 /var/db/opendkim
-r-------- 1 opendkim mail 887 Mar 5 12:05 /var/db/opendkim/

medusa# id opendkim
uid=1106(opendkim) gid=6(mail) groups=6(mail)

medusa# cat ~msk/git/OpenDKIM/conf
Mode s
KeyFile /var/db/opendkim/
Selector bar
UserID opendkim

medusa# ~msk/git/OpenDKIM/opendkim/opendkim -x ~msk/git/OpenDKIM/conf -n

No error was produced. Further, no error was produced when I added other
users to that group as a test. It did fail if I turned on the group read
bit, since there are other users in /etc/passwd with the same group.

Apart from the differing uid, did I miss a step in reproducing your
configuration here? Your report didn't include your configuration file,
so that part was improvised, but the rest is the same as what, as you
pointed out, you already told me.

