From: Quentin Campbell
Date: 2006-11-03 09:13:38 -0500
Subject: Re: ...failed to open "/etc/mail/access.db": Permission denied

Thank you for that. I have now done things "by the book" and all appears
to be OK for the weekend when the systems will be unattended.

Although I do not recollect having done so, I had obviously read the
Notes section for milter-ahead 1.3 because I had the "smmsp" entry in
/etc/group correctly set up.

However I did not bother with the Notes for 1.5 because of course 1.3
had been working OK! :-((

I was also doing a "create then move" for 'access.db' in the nightly
build script which presumably lost the original smmsp group entry for
the file that I would have added when I first installed milter-ahead.

This all begs the question however as to why 'access.db' continued to be
accessible on one set of machines and not another and why the problem
was apparently triggered by updating milter-ahead and milter-link.

Not your problem to try to answer I hasten to add. If I can find any
useful answers I will let you know.   

Thanks again for the rapid response and assistance.


>Quentin Campbell wrote:
>> The permissions on /etc/mail/access.db on ALL my gateways has ALWAYS
>> been:
>> -rw-r-----  1 root root 49152 Nov  3 05:01 /etc/mail/access.db
>> -rw-r-----  1 root root 49152 Nov  2 05:01 /etc/mail/access.db-
>> As a temporary measure I guess I can make the permissions 
>644 after the
>> rebuild but need to do this _before_ the milters detect that 
>> has changed.
>Please check the Notes section of the documentation which covers file 
>permissions and ownership:
>If you have a makefile or script that rebuilds access.db, be sure to 
>maintain the permissions and ownership.
>Also have a look at this article concerning access.db updates:
