These forums are locked and archived, but all topics have been migrated to the new forum. You can search for this topic on the new forum: Search for Security suggestions on the new forum.
Hello, I was trying the other days to create a sub-server (aka a subdomain) with a separate extra-administrator, a very common scenario I guess - but a first for me. I never encountered so many issues with Virtualmin. So this are the things that are wrong:
Now: I know technically why this is happening, but it is not a good procedure. There isn't one good reason for a logged in user to see the other users password, in no scenario. Who needs an "extra admin" who knows the admins user and password?
FTP was a problem also but I gave up Virtualmin in that respect for while now - everything is manual. Solved all of these but took me hours. Never mind the paranoia :)
Thank you - hope was only my case.
you should make this a bug issue in the tracker so Jamie can do something about it.
I don't think it's a bug strictly speaking, more of a wish of changing the default behavior of Virtualmin in these respects. I solved these by disabling the installed scripts for the extra admin and by modifying the mails Virtualmin is sending - no password.
I couldn't find a way to get rid of the resend signup mail in the left menu.
Don't take the name of root in vain...
I'm sorry to see that no one takes interest in this :( Am I the only one who thinks this is an issue?
Don't take the name of root in vain...
Howdy,
The tracker Ronald mentioned is a good place for things like this :-)
With that, Jamie can review your concerns and go over some possible ways of handling that.
-Eric