Does not need to be immediate given that he'll be on board for the next 2 weeks or so but as Philippe is departing we need to change the mailman master password since he has it.
Description
Related Objects
- Mentioned Here
- T109534: Overhaul Mailman documentation
Event Timeline
Indeed, we are going to change it anyways as part of the migration and that should happen within the same timeframe.
@Jalexander also to make things easier for Daniel, to clear up uncertainty and document something relating to mailman correctly (T109534 as an irrelevant quip), who outside of operations has/needs the password?
This is more about keeping things open and also tracking in future and being able to put names to people with access if needed than mindless re distributions in an ad hoc way (as noted with Erik's off board). Bonus points as well - who has the list creator password?
Thanks.
For the master password the only people I have ever known to have the master password outside of ops is Erik, Philippe and myself. After Philippe's departure I would probably say Maggie should have it too if for no other reason then bus factor ness on our side.
Re the list creator password: In most cases recently that has been an ops controlled item. Traditionally Alex Zariv and Casey Brown had the password in addition to you. I'm not sure they ever got it after it was reset with Erik, so it may just be you right now :).
Can I suggest that it may be a good idea to keep a central always-up-to-date list of people who should have the master/list creation passwords? And in an ideal world, all list admin passwords too?
@Krenair: You can, and I agree with your proposal. Unfortunately, the mailman passwords have a horrible habit of being distributed beyond that list.
List admin passwords are set per the list admins, and then shared as they see fit. There is no way (that I am aware of) to track that until mailman3 (when permissions change from password to user based.)
Edit Addition: I hate shared passwords.
I would like to see such a list as well. That would remove all ambiguity who should have it when we need to change it. (for master and list creator). All admin passwords should not be kept in a central location though, that's just too much overhead to keep centralized. Listadmins should be free to change them at will and have to share a single password with other admins of the same list. Moderator passwords can be set by admins and shared for an additional layer of list mods who can help moderate mail but don't have all list admin functions.
Also I suggest these lists (of who has them) be kept someplace public. If its simply a public listing, not any kind of software maintained list, perhaps wikitech on the mailing list landing page? https://wikitech.wikimedia.org/wiki/Lists.wikimedia.org
Hasn't everyone with the master password (and perhaps the list creator password at this point?) signed a Non-Disclosure Agreement?
So; on record we have the following:
Site password:
- Ops
- James
- Philippe
List creator password:
- Me
I don't think it's really that related to NDA or not. It's about having a definitive list of people who ought to have it because they need it. We should try and avoid using it for just convenience, for example where using list creator would be enough to achieve the same thing.
What's the planned timeline for the migration/change? Still planned for this coming week?
To my knowledge, we've still not rescheduled the migration. It was aborted last Wednesday due to technical issues. Will get another time rolling soon though.
Done! I added this section:
https://wikitech.wikimedia.org/wiki/Mailman#Who_has_the_passwords.3F
Ok, i used this opportunity to reset the master (site) password and also the list creator password.
I updated the file that ops has access to.
I gave the new list creator pass to John by putting it in his home on the server itself.
@Jalexander I put the new master password in a file in your home directory on bast1001, mm_site_password and GPG encrypted it with your newest key i got from key servers. Does that work?
@Jalexander So i put on that wiki page that it's "planned" to give the password also to Maggie. Do you wanna share it with her?
There is a central secure password store in ops now (which I'm sure access could be expanded for the "bus factor"), which would probably work better for the "bus factor" from the point of view of remember who has passwords when they are needed to be update and the security of these passwords.
Maybe just a thought for future master password resets.
That should work; thanks Daniel. Slight possibility that I'll need to contact you offline for a redo on the file (I has a computer crash recently, not 100% sure the key servers and my private key are up to date) but will check when i get back into SF tonight and let you know off task.
Also, yes, I can share with Maggie securely.