From johnf@sac.sfbay.sun.com Thu May 22 16:27:41 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4MNRegX014095
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 22 May 2008 16:27:41 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4MNRc4w029308;
	Fri, 23 May 2008 00:27:40 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1A00C01MI3NS00@nwk-avmta-1.sfbay.Sun.COM>; Thu,
 22 May 2008 16:27:39 -0700 (PDT)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1A00L31MI3A860@nwk-avmta-1.sfbay.Sun.COM>; Thu,
 22 May 2008 16:27:39 -0700 (PDT)
Received: from sac.sfbay.sun.com (new-sac.SFBay.Sun.COM [129.146.175.65])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m4MNRbq0018774; Thu, 22 May 2008 16:27:37 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4MNRZtt014090; Thu,
 22 May 2008 16:27:35 -0700 (PDT)
Received: (from johnf@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id m4MNRZIw014086; Thu,
 22 May 2008 16:27:35 -0700 (PDT)
Date: Thu, 22 May 2008 16:27:35 -0700 (PDT)
From: John Fischer <johnf@sac.sfbay.sun.com>
Subject: ejabberd instant messaging server [PSARC/2008/340 FastTrack timeout
 05/29/2008]
To: PSARC-ext@sun.com
Cc: Raymond.Xiong@sun.com, John.Fischer@sun.com
Message-id: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 3092


Template Version: @(#)sac_nextcase 1.66 04/17/08 SMI
This information is Copyright 2008 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 ejabberd instant messaging server
    1.2. Name of Document Author/Supplier:
	 Author:  Raymond Xiong
    1.3  Date of This Document:
	22 May, 2008
4. Technical Description
Summary
=======

        ejabberd[1] is a leading open source XMPP/Jabber instant
        messaging server. It is written in Erlang/OTP. Among
        other features, it is distributed, fault-tolerant, and 
        clusterable. Ejabberd is the IM server running on
        jabber.org.

        ejabberd-2.0.0 will be integrated into SFW consolidation
        as part of this proposal, and will be installed as
        SUNWejabberdr and SUNWejabberdu.

        This project requests a minor release binding.

Discussion
==========
	
	On OpenSolaris, the public interface to start and stop
	ejabberd will be SMF and the service will be named:

	    svc:/network/xmpp:ejabberd

	Note that user will still need ejabberdctl(1M) for other
	administration tasks(ie., user management).

	ejabberd listens on three TCP ports by default: 

	    5222 - standard port for jabber-client protocol
	    5269 - standard port for jabber-server protocol for
                   server to server connections
	    5280 - port for ejabberd web-based admin

Dependencies
============
        
        Erlang/OTP R10B9+ (LSARC/2008/210 R12B1)
        OpenSSL 0.9.6+ (snv_84 version 0.9.8a)
        libexpat 1.95+ (snv_84 version 2.0.1)
        Zlib 1.2.3+ (snv_84 version 1.2.3)

Interfaces
==========

        Exported Interfaces
        -------------------
        NAME                  STABILITY                 NOTES

        SUNWejabberdu         Uncommitted               Package
        /usr/sbin/ejabberdctl Uncommitted               Command
        /usr/lib/ejabberd/    Project Private Directory Ejabberd Modules
        SUNWejabberdr                 Uncommitted       Package
        /etc/ejabberd/ejabberd.cfg    Uncommitted       ejabberd Config File 
        /etc/ejabberd/ejabberdctl.cfg Uncommitted       ejabberdctl Config File 
        /etc/ejabberd/inetrc          Uncommitted       Host Resolver Config
        /var/log/ejabberd/            Uncommitted       Log Files Directory

        Imported Interfaces
        -------------------
        NAME                  STABILITY                 NOTES

        Erlang/OTP            Uncommitted               LSARC/2008/210
        OpenSSL               External/Volatile         PSARC/2003/500
        Expat Library         External/Volatile         LSARC/2004/324
        Zlib                  Committed                 PSARC2006/537
        
References
==========

        [1] http://www.ejabberd.im/
            http://www.process-one.net/en/ejabberd/
            http://www.ejabberd.im/protocols

        RFE ID# 6671871

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		SFW
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From John.Fischer@Sun.COM Thu May 22 16:47:07 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4MNl6Ex014775
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 22 May 2008 16:47:06 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4MNl4I7006169
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Fri, 23 May 2008 00:47:05 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1A00E0DNEF6A00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 22 May 2008 16:47:03 -0700 (PDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1A0086XNEEJ8E0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 22 May 2008 16:47:03 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m4MNl2IQ028248	for
 <psarc-ext@sun.com>; Thu, 22 May 2008 23:47:02 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K1A00501NAFG700@mail-amer.sun.com>
 (original mail from John.Fischer@Sun.COM)
 for psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 22 May 2008 17:47:02 -0600 (MDT)
Received: from 129.145.154.70 ([129.145.154.70])
 by mail-amer.sun.com (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
 2007)) with ESMTPSA id <0K1A00EDBNEDQB80@mail-amer.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 22 May 2008 17:47:02 -0600 (MDT)
Date: Thu, 22 May 2008 16:47:01 -0700
From: John Fischer <John.Fischer@Sun.COM>
Subject: PSARC/2008/340 - ejabberd instant messaging server
Sender: John.Fischer@Sun.COM
To: PSARC-ext@Sun.COM
Cc: John Fischer <John.Fischer@Sun.COM>, Raymond.Xiong@Sun.COM
Reply-to: John.Fischer@Sun.COM
Message-id: <1211500021.33265.27.camel@sr1-umpk-19>
MIME-version: 1.0
X-Mailer: Ximian Evolution 1.4.6.301
Content-type: multipart/mixed; boundary="Boundary_(ID_zjSsu3oB8gdfm0D5gHdChw)"
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 3463


--Boundary_(ID_zjSsu3oB8gdfm0D5gHdChw)
Content-type: text/plain
Content-transfer-encoding: 7BIT

PSARC,

I am sponsoring this fast track for Raymond Xiong of the Core
technologies team in Beijing.  The case directory contains
this proposal and man page.  I have set the timer for Thursday
May 29th, 2008.  This case will also need to create a contracts
for OpenSSL and the Expat library.

This project proposes to integrate ejabberd into a Minor
release of Solaris.  The interfaces are being declared 
Uncommitted.  The project team is supplying an SMF service
named svc:/network/xmpp:ejabberd which is similar to how
the apache2 service is named.

Thanks,

John



--Boundary_(ID_zjSsu3oB8gdfm0D5gHdChw)
Content-type: text/plain; charset=ASCII; name=proposal.txt
Content-transfer-encoding: 7BIT
Content-disposition: attachment; filename=proposal.txt

Summary
=======

        ejabberd[1] is a leading open source XMPP/Jabber instant
        messaging server. It is written in Erlang/OTP. Among
        other features, it is distributed, fault-tolerant, and 
        clusterable. Ejabberd is the IM server running on
        jabber.org.

        ejabberd-2.0.0 will be integrated into SFW consolidation
        as part of this proposal, and will be installed as
        SUNWejabberdr and SUNWejabberdu.

        This project requests a minor release binding.

Discussion
==========
	
	On OpenSolaris, the public interface to start and stop
	ejabberd will be SMF and the service will be named:

	    svc:/network/xmpp:ejabberd

	Note that user will still need ejabberdctl(1M) for other
	administration tasks(ie., user management).

	ejabberd listens on three TCP ports by default: 

	    5222 - standard port for jabber-client protocol
	    5269 - standard port for jabber-server protocol for
                   server to server connections
	    5280 - port for ejabberd web-based admin

Dependencies
============
        
        Erlang/OTP R10B9+ (LSARC/2008/210 R12B1)
        OpenSSL 0.9.6+ (snv_84 version 0.9.8a)
        libexpat 1.95+ (snv_84 version 2.0.1)
        Zlib 1.2.3+ (snv_84 version 1.2.3)

Interfaces
==========

        Exported Interfaces
        -------------------
        NAME                  STABILITY                 NOTES

        SUNWejabberdu         Uncommitted               Package
        /usr/sbin/ejabberdctl Uncommitted               Command
        /usr/lib/ejabberd/    Project Private Directory Ejabberd Modules
        SUNWejabberdr                 Uncommitted       Package
        /etc/ejabberd/ejabberd.cfg    Uncommitted       ejabberd Config File 
        /etc/ejabberd/ejabberdctl.cfg Uncommitted       ejabberdctl Config File 
        /etc/ejabberd/inetrc          Uncommitted       Host Resolver Config
        /var/log/ejabberd/            Uncommitted       Log Files Directory

        Imported Interfaces
        -------------------
        NAME                  STABILITY                 NOTES

        Erlang/OTP            Uncommitted               LSARC/2008/210
        OpenSSL               External/Volatile         PSARC/2003/500
        Expat Library         External/Volatile         LSARC/2004/324
        Zlib                  Committed                 PSARC2006/537
        
References
==========

        [1] http://www.ejabberd.im/
            http://www.process-one.net/en/ejabberd/
            http://www.ejabberd.im/protocols

        RFE ID# 6671871

--Boundary_(ID_zjSsu3oB8gdfm0D5gHdChw)--

From Darren.Moffat@sun.com Fri May 23 03:05:12 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4NA5BjY029658
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 23 May 2008 03:05:11 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4NA56C6020586
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 23 May 2008 11:05:10 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1B00L01G0KBH00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 23 May 2008 03:05:08 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1B003R6G0J20E0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 23 May 2008 03:05:07 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe1.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4NA56Jh025510	for
 <PSARC-ext@sun.com>; Fri, 23 May 2008 10:05:06 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K1B00901FNSA600@fe-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 23 May 2008 11:05:06 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K1B00D3VG0HPL10@fe-emea-09.sun.com>; Fri,
 23 May 2008 11:05:06 +0100 (BST)
Date: Fri, 23 May 2008 11:05:05 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
Sender: Darren.Moffat@sun.com
To: John Fischer <johnf@sac.sfbay.sun.com>
Cc: PSARC-ext@sun.com, Raymond.Xiong@sun.com, John.Fischer@sun.com
Message-id: <483696D1.3000704@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.12 (X11/20080326)
Status: RO
Content-Length: 1288

John Fischer wrote:
> ==========
> 	
> 	On OpenSolaris, the public interface to start and stop
> 	ejabberd will be SMF and the service will be named:
> 
> 	    svc:/network/xmpp:ejabberd
> 
> 	Note that user will still need ejabberdctl(1M) for other
> 	administration tasks(ie., user management).
> 
> 	ejabberd listens on three TCP ports by default: 
> 
> 	    5222 - standard port for jabber-client protocol
> 	    5269 - standard port for jabber-server protocol for
>                    server to server connections
> 	    5280 - port for ejabberd web-based admin

I assume you don't actually mean "in a default install" but "When 
ejabberd is explicitly enabled".  I'm assuming (hopefully) that ejabberd 
service is delivered disabled.

What SMF method credential use ejabberd run with ?  I'm assuming it is 
running as the daemon (or noaccess) user with no additional privileges. 
  Given it is running on ports > 1024 it shouldn't need any privileges.
[Strong HINT: I will derail this case if the answer is that it is 
running as root with all privileges]

Which uid/gid owns the default log file location ?

Which RBAC profile is the /usr/sbin/ejabberdctl in ?

What new authorisations are added (and to which RBAC profile) for the 
SMF level administration ?

-- 
Darren J Moffat

From Raymond.Xiong@Sun.COM Mon May 26 04:28:37 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4QBSafk014879
	for <psarc-ext@sac.sfbay.Sun.COM>; Mon, 26 May 2008 04:28:37 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4QBSZGg010442
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Mon, 26 May 2008 19:28:35 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1H009013VMLX00@brm-avmta-1.central.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@sun.com); Mon, 26 May 2008 05:28:34 -0600 (MDT)
Received: from dm-singapore-02.singapore.sun.com ([129.158.71.102])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1H00JGJ3VLO960@brm-avmta-1.central.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@sun.com); Mon,
 26 May 2008 05:28:34 -0600 (MDT)
Received: from sineb-smtp-1.singapore.sun.com
 (sineb-smtp-1.Singapore.Sun.COM [129.158.123.4])
	by dm-singapore-02.singapore.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m4QBSWQj010133	for <PSARC-ext@Sun.COM>; Mon,
 26 May 2008 19:28:32 +0800 (SGT)
Received: from phys-sedge2-1.singapore.sun.com
 (phys-sedge2-1.Singapore.Sun.COM [129.158.123.14])
	by sineb-smtp-1.singapore.sun.com (8.13.6+Sun/8.12.9)
 with ESMTP id m4QBgVae029743	for <@smarthost.sun.com:PSARC-ext@sun.com>; Mon,
 26 May 2008 11:42:31 +0000 (GMT)
Received: from localhost ([129.158.219.68]) by sedge2-mail1.singapore.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPA id <0K1H00GFF3VESTC0@sedge2-mail1.singapore.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 26 May 2008 19:28:27 +0800 (SGT)
Date: Mon, 26 May 2008 19:23:15 +0800
From: Raymond Xiong <Raymond.Xiong@Sun.COM>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <483696D1.3000704@Sun.COM>
To: Darren J Moffat <Darren.Moffat@Sun.COM>
Cc: John Fischer <johnf@sac.sfbay.sun.com>, PSARC-ext@Sun.COM,
        John.Fischer@Sun.COM
Message-id: <20080526112314.GA825@Sun.Com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM>
User-Agent: Mutt/1.5.11
Status: RO
Content-Length: 2478

On 05/23/08, Darren J Moffat wrote:
> John Fischer wrote:
> >==========
> >	
> >	On OpenSolaris, the public interface to start and stop
> >	ejabberd will be SMF and the service will be named:
> >
> >	    svc:/network/xmpp:ejabberd
> >
> >	Note that user will still need ejabberdctl(1M) for other
> >	administration tasks(ie., user management).
> >
> >	ejabberd listens on three TCP ports by default: 
> >
> >	    5222 - standard port for jabber-client protocol
> >	    5269 - standard port for jabber-server protocol for
> >                   server to server connections
> >	    5280 - port for ejabberd web-based admin
> 
> I assume you don't actually mean "in a default install" but "When 
> ejabberd is explicitly enabled".  I'm assuming (hopefully) that ejabberd 
> service is delivered disabled.
 
Yes. ejabberd service will be disabled by default. The above ports
are default values and can be changed in its configuration.

> What SMF method credential use ejabberd run with ?  I'm assuming it is 
> running as the daemon (or noaccess) user with no additional privileges. 
>  Given it is running on ports > 1024 it shouldn't need any privileges.
> [Strong HINT: I will derail this case if the answer is that it is 
> running as root with all privileges]
> 
> Which uid/gid owns the default log file location ?
> 
> Which RBAC profile is the /usr/sbin/ejabberdctl in ?
> 
> What new authorisations are added (and to which RBAC profile) for the 
> SMF level administration ?

Thanks for pointing out those issues(I wasn't aware of them).
I'd like to propose the following more:

- a new user "ejabberd"(uid: 96) and a new group "ejabberd"(gid: 96)
  will be added for running ejabbered service. 

  (Notes: 1) I noticied mysql service uses "mysql" user, and postgresql
   service uses "postgres" role. So I suppose it is OK to use either
   user or role for this purpose. 2) svctag's uid is 95. So I use 96
   for ejabberd.)

- "ejabberd" user will be associated with "Ejabberd Administration"
  profile, which includes solaris.smf.manage.ejabberd and 
  solaris.smf.value.ejabberd authorizations.

- The above two authorizations are required for executing methods 
  in ejabberd service manifest. 

Note that ejabberd's initial configuration data are stored in config
files under /etc/ejabberd, so even with above proposal, root user is
still required for editting those config files(I suppose that is OK).

Please let me know if I missed anything.

-- 
Regards,
Raymond

From Darren.Moffat@Sun.COM Tue May 27 03:49:27 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4RAnQSm011841
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 27 May 2008 03:49:27 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com (gmp-eb-inf-2.EU.Sun.COM [192.18.6.24])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4RAnPSJ020009
	for <PSARC-ext@sun.com>; Tue, 27 May 2008 11:49:25 +0100 (BST)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe1.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4RAnK7r014708
	for <PSARC-ext@Sun.COM>; Tue, 27 May 2008 10:49:20 GMT
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K1I00M01WC6LP00@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Tue,
 27 May 2008 11:49:20 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K1I00D2LWPXRS10@fe-emea-10.sun.com>; Tue,
 27 May 2008 11:49:10 +0100 (BST)
Date: Tue, 27 May 2008 11:49:09 +0100
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <20080526112314.GA825@Sun.Com>
Sender: Darren.Moffat@Sun.COM
To: Raymond Xiong <Raymond.Xiong@Sun.COM>
Cc: John Fischer <johnf@sac.sfbay.sun.com>, PSARC-ext@Sun.COM,
        John.Fischer@Sun.COM
Message-id: <483BE725.3010805@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080507)
Status: RO
Content-Length: 2739

Raymond Xiong wrote:
> On 05/23/08, Darren J Moffat wrote:
>> John Fischer wrote:
>>> ==========
>>> 	
>>> 	On OpenSolaris, the public interface to start and stop
>>> 	ejabberd will be SMF and the service will be named:
>>>
>>> 	    svc:/network/xmpp:ejabberd
>>>
>>> 	Note that user will still need ejabberdctl(1M) for other
>>> 	administration tasks(ie., user management).
>>>
>>> 	ejabberd listens on three TCP ports by default: 
>>>
>>> 	    5222 - standard port for jabber-client protocol
>>> 	    5269 - standard port for jabber-server protocol for
>>>                   server to server connections
>>> 	    5280 - port for ejabberd web-based admin
>> I assume you don't actually mean "in a default install" but "When 
>> ejabberd is explicitly enabled".  I'm assuming (hopefully) that ejabberd 
>> service is delivered disabled.
>  
> Yes. ejabberd service will be disabled by default. The above ports
> are default values and can be changed in its configuration.
> 
>> What SMF method credential use ejabberd run with ?  I'm assuming it is 
>> running as the daemon (or noaccess) user with no additional privileges. 
>>  Given it is running on ports > 1024 it shouldn't need any privileges.
>> [Strong HINT: I will derail this case if the answer is that it is 
>> running as root with all privileges]
>>
>> Which uid/gid owns the default log file location ?
>>
>> Which RBAC profile is the /usr/sbin/ejabberdctl in ?
>>
>> What new authorisations are added (and to which RBAC profile) for the 
>> SMF level administration ?
> 
> Thanks for pointing out those issues(I wasn't aware of them).
> I'd like to propose the following more:
> 
> - a new user "ejabberd"(uid: 96) and a new group "ejabberd"(gid: 96)
>   will be added for running ejabbered service. 
> 
>   (Notes: 1) I noticied mysql service uses "mysql" user, and postgresql
>    service uses "postgres" role. So I suppose it is OK to use either
>    user or role for this purpose. 2) svctag's uid is 95. So I use 96
>    for ejabberd.)

I don't see why a new user account is actually necessary in this case so 
no I don't think it is oay.

> - "ejabberd" user will be associated with "Ejabberd Administration"
>   profile, which includes solaris.smf.manage.ejabberd and 
>   solaris.smf.value.ejabberd authorizations.
> 
> - The above two authorizations are required for executing methods 
>   in ejabberd service manifest. 
> 
> Note that ejabberd's initial configuration data are stored in config
> files under /etc/ejabberd, so even with above proposal, root user is
> still required for editting those config files(I suppose that is OK).

Given the above I see no rationale for having an ejabberd user/role 
instead of using the daemon account.

-- 
Darren J Moffat

From Raymond.Xiong@sun.com Wed May 28 01:45:38 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4S8jc27023414
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 28 May 2008 01:45:38 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4S8jbrx022796
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Wed, 28 May 2008 01:45:38 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1K0091FLO2QL00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@sun.com); Wed, 28 May 2008 01:45:38 -0700 (PDT)
Received: from dm-singapore-01.singapore.sun.com ([129.158.71.101])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1K00MWRLO1EJB0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@sun.com); Wed,
 28 May 2008 01:45:37 -0700 (PDT)
Received: from sineb-smtp-1.singapore.sun.com
 (sineb-smtp-1.Singapore.Sun.COM [129.158.123.4])
	by dm-singapore-01.singapore.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m4S8jaL3020251	for <PSARC-ext@Sun.COM>; Wed,
 28 May 2008 16:45:36 +0800 (SGT)
Received: from phys-sedge2-1.singapore.sun.com
 (phys-sedge2-1.Singapore.Sun.COM [129.158.123.14])
	by sineb-smtp-1.singapore.sun.com (8.13.6+Sun/8.12.9)
 with ESMTP id m4S8xaWE015726	for <@smarthost.sun.com:PSARC-ext@sun.com>; Wed,
 28 May 2008 08:59:36 +0000 (GMT)
Received: from localhost ([129.158.219.68]) by sedge2-mail1.singapore.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPA id <0K1K003LHLNUN420@sedge2-mail1.singapore.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 28 May 2008 16:45:31 +0800 (SGT)
Date: Wed, 28 May 2008 16:40:18 +0800
From: Raymond Xiong <Raymond.Xiong@sun.com>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <483BE725.3010805@Sun.COM>
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: John.Fischer@sun.com, PSARC-ext@sun.com
Message-id: <20080528084017.GA1421@Sun.Com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
 <483BE725.3010805@Sun.COM>
User-Agent: Mutt/1.5.11
Status: RO
Content-Length: 3996

On 05/27/08, Darren J Moffat wrote:
> Raymond Xiong wrote:
> > On 05/23/08, Darren J Moffat wrote:
> >> John Fischer wrote:
> >>> ==========
> >>> 	
> >>> 	On OpenSolaris, the public interface to start and stop
> >>> 	ejabberd will be SMF and the service will be named:
> >>>
> >>> 	    svc:/network/xmpp:ejabberd
> >>>
> >>> 	Note that user will still need ejabberdctl(1M) for other
> >>> 	administration tasks(ie., user management).
> >>>
> >>> 	ejabberd listens on three TCP ports by default: 
> >>>
> >>> 	    5222 - standard port for jabber-client protocol
> >>> 	    5269 - standard port for jabber-server protocol for
> >>>                   server to server connections
> >>> 	    5280 - port for ejabberd web-based admin
> >> I assume you don't actually mean "in a default install" but "When 
> >> ejabberd is explicitly enabled".  I'm assuming (hopefully) that ejabberd 
> >> service is delivered disabled.
> >  
> > Yes. ejabberd service will be disabled by default. The above ports
> > are default values and can be changed in its configuration.
> > 
> >> What SMF method credential use ejabberd run with ?  I'm assuming it is 
> >> running as the daemon (or noaccess) user with no additional privileges. 
> >>  Given it is running on ports > 1024 it shouldn't need any privileges.
> >> [Strong HINT: I will derail this case if the answer is that it is 
> >> running as root with all privileges]
> >>
> >> Which uid/gid owns the default log file location ?
> >>
> >> Which RBAC profile is the /usr/sbin/ejabberdctl in ?
> >>
> >> What new authorisations are added (and to which RBAC profile) for the 
> >> SMF level administration ?
> > 
> > Thanks for pointing out those issues(I wasn't aware of them).
> > I'd like to propose the following more:
> > 
> > - a new user "ejabberd"(uid: 96) and a new group "ejabberd"(gid: 96)
> >   will be added for running ejabbered service. 
> > 
> >   (Notes: 1) I noticied mysql service uses "mysql" user, and postgresql
> >    service uses "postgres" role. So I suppose it is OK to use either
> >    user or role for this purpose. 2) svctag's uid is 95. So I use 96
> >    for ejabberd.)
> 
> I don't see why a new user account is actually necessary in this case so 
> no I don't think it is oay.
> 
> > - "ejabberd" user will be associated with "Ejabberd Administration"
> >   profile, which includes solaris.smf.manage.ejabberd and 
> >   solaris.smf.value.ejabberd authorizations.
> > 
> > - The above two authorizations are required for executing methods 
> >   in ejabberd service manifest. 
> > 
> > Note that ejabberd's initial configuration data are stored in config
> > files under /etc/ejabberd, so even with above proposal, root user is
> > still required for editting those config files(I suppose that is OK).
> 
> Given the above I see no rationale for having an ejabberd user/role 
> instead of using the daemon account.

Darren,

Here is my new proposal:

  - Method credential for ejabberd SMF service will be "daemon" user
    and "daemon" group. So, all files generated at runtime will have
    daemon as their uid and gid.

  - A new profile "Ejabberd Administration" will be created, which 
    includes two authorizations: solaris.smf.manage.ejabberd and
    solaris.smf.value.ejabberd. The profile will also have 
    "euid=1;egid=1" execution attribute for ejabberdctl(1M) command.

  - The above two authorizations are required to invoke ejabbered 
    service methods.

So by default, only root will be able to start/stop ejabberd. For any
other users/roles, they will need to have "Ejabberd Administration" 
profile for that.

ejabberdctl(1M) is used for other administration tasks. What it does
is to attach a remote shell the specified Erlang node(that is, an 
Erlang VM) and sends command to ejabberd modules. Because Erlang 
protects acess to nodes with a cookie file, which is only accessible
by the one who starts the server, so I assign "euid=1;egid=1" attribute
to the command in the profile.
 
Thanks,
Raymond

From Darren.Moffat@sun.com Wed May 28 02:49:14 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4S9nDki024636
	for <psarc-ext@sac.sfbay.Sun.COM>; Wed, 28 May 2008 02:49:13 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m4S9mikY012775
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 28 May 2008 17:49:12 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1K00L01OLXLA00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.COM); Wed, 28 May 2008 03:49:09 -0600 (MDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1K00J66OLWC620@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.COM); Wed,
 28 May 2008 03:49:09 -0600 (MDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe1.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m4S9n8OO006318	for
 <PSARC-ext@Sun.COM>; Wed, 28 May 2008 09:49:08 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K1K00101N2QZW00@fe-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM)
 for PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Wed,
 28 May 2008 10:49:08 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K1K005WQOLNQ3B0@fe-emea-09.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Wed, 28 May 2008 10:49:00 +0100 (BST)
Date: Wed, 28 May 2008 10:48:59 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <20080528084017.GA1421@Sun.Com>
Sender: Darren.Moffat@sun.com
To: Raymond Xiong <Raymond.Xiong@sun.com>
Cc: John.Fischer@sun.com, PSARC-ext@sun.com
Message-id: <483D2A8B.1090806@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
 <483BE725.3010805@Sun.COM> <20080528084017.GA1421@Sun.Com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080507)
Status: RO
Content-Length: 1309

Raymond Xiong wrote:
> Here is my new proposal:
> 
>   - Method credential for ejabberd SMF service will be "daemon" user
>     and "daemon" group. So, all files generated at runtime will have
>     daemon as their uid and gid.
> 
>   - A new profile "Ejabberd Administration" will be created, which 
>     includes two authorizations: solaris.smf.manage.ejabberd and
>     solaris.smf.value.ejabberd. The profile will also have 
>     "euid=1;egid=1" execution attribute for ejabberdctl(1M) command.
> 
>   - The above two authorizations are required to invoke ejabbered 
>     service methods.
> 
> So by default, only root will be able to start/stop ejabberd. For any
> other users/roles, they will need to have "Ejabberd Administration" 
> profile for that.

That all sounds fine.

> ejabberdctl(1M) is used for other administration tasks. What it does
> is to attach a remote shell the specified Erlang node(that is, an 
> Erlang VM) and sends command to ejabberd modules. Because Erlang 
> protects acess to nodes with a cookie file, which is only accessible
> by the one who starts the server, so I assign "euid=1;egid=1" attribute
> to the command in the profile.

What underlying OS transport mechanism is used for this ? TCP, doors, 
UNIX domain sockets, pipes, shared memory ?

-- 
Darren J Moffat

From Raymond.Xiong@Sun.COM Wed May 28 09:50:23 2008
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4SGoNQX007022
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 28 May 2008 09:50:23 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m4SGoNmR016393
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Wed, 28 May 2008 09:50:23 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1L0020783YB800@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Wed, 28 May 2008 09:50:22 -0700 (PDT)
Received: from dm-singapore-01.singapore.sun.com ([129.158.71.101])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1L00K3Y83VY150@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Wed,
 28 May 2008 09:50:20 -0700 (PDT)
Received: from sineb-smtp-1.singapore.sun.com
 (sineb-smtp-1.Singapore.Sun.COM [129.158.123.4])
	by dm-singapore-01.singapore.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m4SGoI0T029666	for <PSARC-ext@Sun.COM>; Thu,
 29 May 2008 00:50:18 +0800 (SGT)
Received: from phys-sedge2-1.singapore.sun.com
 (phys-sedge2-1.Singapore.Sun.COM [129.158.123.14])
	by sineb-smtp-1.singapore.sun.com (8.13.6+Sun/8.12.9)
 with ESMTP id m4SH4INf026841	for <@smarthost.sun.com:PSARC-ext@Sun.COM>; Wed,
 28 May 2008 17:04:18 +0000 (GMT)
Received: from localhost ([129.158.219.68]) by sedge2-mail1.singapore.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPA id <0K1L004B983O2I90@sedge2-mail1.singapore.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Thu,
 29 May 2008 00:50:13 +0800 (SGT)
Date: Thu, 29 May 2008 00:45:00 +0800
From: Raymond Xiong <Raymond.Xiong@Sun.COM>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <483D2A8B.1090806@Sun.COM>
To: Darren J Moffat <Darren.Moffat@Sun.COM>
Cc: John.Fischer@Sun.COM, PSARC-ext@Sun.COM
Message-id: <20080528164459.GA20621@Sun.Com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
 <483BE725.3010805@Sun.COM> <20080528084017.GA1421@Sun.Com>
 <483D2A8B.1090806@Sun.COM>
User-Agent: Mutt/1.5.11
Status: RO
Content-Length: 1798

On 05/28/08, Darren J Moffat wrote:
> 
> >ejabberdctl(1M) is used for other administration tasks. What it does
> >is to attach a remote shell the specified Erlang node(that is, an 
> >Erlang VM) and sends command to ejabberd modules. Because Erlang 
> >protects acess to nodes with a cookie file, which is only accessible
> >by the one who starts the server, so I assign "euid=1;egid=1" attribute
> >to the command in the profile.
> 
> What underlying OS transport mechanism is used for this ? TCP, doors, 
> UNIX domain sockets, pipes, shared memory ?

I just realized what I described on how ejabberdctl worked was 
inaccurate. Ejabberd administration is implemented as an Erlang
application too. For most administration tasks, ejabberdctl(1M)
script actually starts a separate Erlang node to run that 
application, which then may communicate with ejabberd server 
application running in another node.

The inter-node communication is authenticated with cookie, which
is a shared secret among all nodes(I didn't find any document
dicussing the details, but I read somewhere the cookie's clear
text is not sent over network. So it may be used as a key to 
encrypt a random challenge value to create a response for 
authentication.) All messages sent on network are not encrypted.

Although I am not sure, I think the underlying OS transport 
mechanism used for inter-node communication is TCP, because nodes
can run on different machines. Below is pfiles output for the 
port ejabberd server listens on for inter-node communcation(
it is not the ports I metioned in FastTrack):

   8: S_IFSOCK mode:0666 dev:293,0 ino:9441 uid:0 gid:0 size:0
      O_RDWR|O_NONBLOCK
        SOCK_STREAM
        SO_SNDBUF(49152),SO_RCVBUF(49152)
        sockname: AF_INET 0.0.0.0  port: 33523

-- 
Regards,
Raymond

From sommerfeld@sun.com Wed May 28 20:46:31 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m4T3kVhc005040
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 28 May 2008 20:46:31 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m4T3kIIT001801;
	Thu, 29 May 2008 04:46:19 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1M00B032H7EQ00@brm-avmta-1.central.sun.com>; Wed,
 28 May 2008 21:46:19 -0600 (MDT)
Received: from localhost.east.sun.com ([129.148.19.3])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1M00MKB2H6WE30@brm-avmta-1.central.sun.com>; Wed,
 28 May 2008 21:46:18 -0600 (MDT)
Received: from localhost.east.sun.com (localhost [127.0.0.1])
	by localhost.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id m4T3kGb9002161;
 Wed, 28 May 2008 23:46:16 -0400 (EDT)
Received: (from sommerfeld@localhost)	by localhost.east.sun.com
 (8.14.3+Sun/8.14.3/Submit) id m4T3kGcI002160; Wed,
 28 May 2008 23:46:16 -0400 (EDT)
Date: Wed, 28 May 2008 15:55:10 -0700
From: Bill Sommerfeld <sommerfeld@sun.com>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
	timeout 05/29/2008]
In-reply-to: <483BE725.3010805@Sun.COM>
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Raymond Xiong <Raymond.Xiong@sun.com>,
        John Fischer <johnf@sac.sfbay.sun.com>, PSARC-ext@sun.com,
        John.Fischer@sun.com
Message-id: <1212015310.1128.22.camel@localhost>
MIME-version: 1.0
X-Mailer: Evolution 2.12.2
Content-type: text/plain
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
 <483BE725.3010805@Sun.COM>
X-Authentication-warning: localhost.east.sun.com: sommerfeld set sender to
 sommerfeld@sun.com using -f
Status: RO
Content-Length: 685


On Tue, 2008-05-27 at 11:49 +0100, Darren J Moffat wrote:
....
> >>> 	Note that user will still need ejabberdctl(1M) for other
> >>> 	administration tasks(ie., user management).

this implies that ejabberd has its own user database.  Where is that
user database stored and how is it protected?

> > Note that ejabberd's initial configuration data are stored in config
> > files under /etc/ejabberd, so even with above proposal, root user is
> > still required for editting those config files(I suppose that is OK).
> 
> Given the above I see no rationale for having an ejabberd user/role 
> instead of using the daemon account.

who owns the ejabberd user database?

					- Bill






From Raymond.Xiong@sun.com Mon Jun  2 03:03:14 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m52A3DGA002272
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 2 Jun 2008 03:03:13 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m52A31nE008080;
	Mon, 2 Jun 2008 11:03:12 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1T00101YL9AR00@brm-avmta-1.central.sun.com>; Mon,
 02 Jun 2008 04:03:09 -0600 (MDT)
Received: from dm-singapore-01.singapore.sun.com ([129.158.71.101])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1T00FNIYL8RC80@brm-avmta-1.central.sun.com>; Mon,
 02 Jun 2008 04:03:09 -0600 (MDT)
Received: from sineb-smtp-1.singapore.sun.com
 (sineb-smtp-1.Singapore.Sun.COM [129.158.123.4])
	by dm-singapore-01.singapore.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m52A379P003187; Mon, 02 Jun 2008 18:03:07 +0800 (SGT)
Received: from phys-sedge2-1.singapore.sun.com
 (phys-sedge2-1.Singapore.Sun.COM [129.158.123.14])
	by sineb-smtp-1.singapore.sun.com (8.13.6+Sun/8.12.9)
 with ESMTP id m52AH9gi007306; Mon, 02 Jun 2008 10:17:09 +0000 (GMT)
Received: from localhost ([129.158.219.68]) by sedge2-mail1.singapore.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPA id <0K1T0008QYL1CW30@sedge2-mail1.singapore.sun.com>; Mon,
 02 Jun 2008 18:03:02 +0800 (SGT)
Date: Mon, 02 Jun 2008 17:57:44 +0800
From: Raymond Xiong <Raymond.Xiong@sun.com>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <1212015310.1128.22.camel@localhost>
To: Bill Sommerfeld <sommerfeld@sun.com>
Cc: Darren J Moffat <Darren.Moffat@sun.com>, PSARC-ext@sun.com,
        John.Fischer@sun.com
Message-id: <20080602095743.GA673@Sun.Com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
 <483BE725.3010805@Sun.COM> <1212015310.1128.22.camel@localhost>
User-Agent: Mutt/1.5.11
Status: RO
Content-Length: 792

On 05/28/08, Bill Sommerfeld wrote:
> 
> On Tue, 2008-05-27 at 11:49 +0100, Darren J Moffat wrote:
> ....
> > >>> 	Note that user will still need ejabberdctl(1M) for other
> > >>> 	administration tasks(ie., user management).
> 
> this implies that ejabberd has its own user database.  Where is that
> user database stored and how is it protected?
 
Yes, ejabberd can store user data in Mnesia(an internal database 
provied as part of Erlang/OTP), MySQL(via native driver), PostgreSQL
(via native driver), or any other ODBC-compatible database(via odbc 
driver provided by Erlang/OTP).

For this FastTrack, only Mnesia support will be implemented. This is 
partly because Erlang/OTP as proposed in LSARC/2008/210 won't have
odbc support(because there isn't a odbc library on OpenSolaris yet).

From what I read and my experiments results, Mnesia doesn't have
Status: RO

something like database administator for access control. So, anyone
who has access to a node(an Erlang VM) where the database is running
can access and manipulate all data stored in it. 

Erlang uses "all or nothing" security model. Access to a node is 
authenticated with cookies(this is known insecure and should be used
only in a secure network environment). Once an user has acess to 
a node, he can do anything, like shuting down the node, or removing 
all files on the system if the node is running as root.

Mnesia on-disk files will be placed under /usr/lib/ejabberd/db/ejabberd
(you may notice I didn't list the directory in FastTrack, because it
is typically created automatically). All data files under this subdir
are owned by daemon, and have 600 as their permissions.

> > > Note that ejabberd's initial configuration data are stored in config
> > > files under /etc/ejabberd, so even with above proposal, root user is
> > > still required for editting those config files(I suppose that is OK).
> > 
> > Given the above I see no rationale for having an ejabberd user/role 
> > instead of using the daemon account.
> 
> who owns the ejabberd user database?

It is owned by daemon user in that:

  - on-disk files are owned by daemon and their permission are 600.
  - ejabberd server runs as daemon user, and loads those data.
  - any user who connects to the node can access those data. But to
    connect the node, the user must have access to a cookie file, which
    is owned and can only be read by daemon. 

Two more notes on user authentication:

1) ejabberd also supports PAM authentication. So it is possible to 
use UNIX accounts for ejabberd user authentication(though I don't think
this was recommended in its manual). For various reason, this feature
won't be supported in my package. 

2) I actually don't know what's the most widely used way for ejabbered 
user authentication. I think we can first integrate ejabberd using 
its default authentication method(that is, using mnesia), and add 
support for other methods if there are need for them.

Thanks.
Raymond

From Darren.Moffat@sun.com Mon Jun  2 03:09:52 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m52A9p3T002614
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 2 Jun 2008 03:09:51 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m52A9nOX010949;
	Mon, 2 Jun 2008 11:09:50 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1T00103YWCSO00@brm-avmta-1.central.sun.com>; Mon,
 02 Jun 2008 04:09:48 -0600 (MDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1T00F9CYWBRC90@brm-avmta-1.central.sun.com>; Mon,
 02 Jun 2008 04:09:48 -0600 (MDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe1.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m52A9l6b006392; Mon,
 02 Jun 2008 10:09:47 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K1T00101W1ILI00@fe-emea-09.sun.com>
 (original mail from Darren.Moffat@Sun.COM); Mon,
 02 Jun 2008 11:09:47 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-09.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K1T00M1QYW475E0@fe-emea-09.sun.com>; Mon,
 02 Jun 2008 11:09:41 +0100 (BST)
Date: Mon, 02 Jun 2008 11:09:40 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <20080602095743.GA673@Sun.Com>
Sender: Darren.Moffat@sun.com
To: Raymond Xiong <Raymond.Xiong@sun.com>
Cc: Bill Sommerfeld <sommerfeld@sun.com>, PSARC-ext@sun.com,
        John.Fischer@sun.com
Message-id: <4843C6E4.4040008@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
 <483BE725.3010805@Sun.COM> <1212015310.1128.22.camel@localhost>
 <20080602095743.GA673@Sun.Com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080507)
Status: RO
Content-Length: 521

Raymond Xiong wrote:
> Mnesia on-disk files will be placed under /usr/lib/ejabberd/db/ejabberd
> (you may notice I didn't list the directory in FastTrack, because it
> is typically created automatically). All data files under this subdir
> are owned by daemon, and have 600 as their permissions.

That needs to change to somewhere under /var or /etc you can not assume 
/usr/ or subdirs of it are writable.  This would break the use of 
ejabberd in the default zone or diskless client configuration.

-- 
Darren J Moffat

From Darren.Moffat@sun.com Mon Jun  2 03:12:42 2008
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m52ACfPg002795
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 2 Jun 2008 03:12:41 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m52ACfbk026896;
	Mon, 2 Jun 2008 03:12:41 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1T0020NZ151J00@brm-avmta-1.central.sun.com>; Mon,
 02 Jun 2008 04:12:41 -0600 (MDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1T00FRPZ13RI90@brm-avmta-1.central.sun.com>; Mon,
 02 Jun 2008 04:12:39 -0600 (MDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe1.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id m52ACcVD006843; Mon,
 02 Jun 2008 10:12:38 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K1T00J01YC11K00@fe-emea-10.sun.com>
 (original mail from Darren.Moffat@Sun.COM); Mon,
 02 Jun 2008 11:12:38 +0100 (BST)
Received: from [129.156.173.21] by fe-emea-10.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K1T00503Z0W6B90@fe-emea-10.sun.com>; Mon,
 02 Jun 2008 11:12:33 +0100 (BST)
Date: Mon, 02 Jun 2008 11:12:32 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <20080602095743.GA673@Sun.Com>
Sender: Darren.Moffat@sun.com
To: Raymond Xiong <Raymond.Xiong@sun.com>
Cc: Bill Sommerfeld <sommerfeld@sun.com>, PSARC-ext@sun.com,
        John.Fischer@sun.com
Message-id: <4843C790.6090607@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
 <483BE725.3010805@Sun.COM> <1212015310.1128.22.camel@localhost>
 <20080602095743.GA673@Sun.Com>
User-Agent: Thunderbird 2.0.0.14 (X11/20080507)
Status: RO
Content-Length: 859

Raymond Xiong wrote:
> Two more notes on user authentication:
> 
> 1) ejabberd also supports PAM authentication. So it is possible to 
> use UNIX accounts for ejabberd user authentication(though I don't think
> this was recommended in its manual). For various reason, this feature
> won't be supported in my package. 

Actually that might be a much better idea because it opens up a lot of 
scope for better authentication.

Given that Solaris invented PAM I find it very strange to integrate 
something that has PAM support available but to disable it.

Running with PAM will, unfortunately, require that the daemon run with 
all privileges during authentication.

I think unfortunately this case is getting to the point that it should 
come for full review (sadly it looked like it was converging).  I'm not 
derailing yet but I might.

-- 
Darren J Moffat

From Nicolas.Williams@sun.com Mon Jun  2 08:52:38 2008
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m52Fqcjk010566
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 2 Jun 2008 08:52:38 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m52FqWBQ021727;
	Mon, 2 Jun 2008 08:52:34 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1U0030BERMP000@brm-avmta-1.central.sun.com>; Mon,
 02 Jun 2008 09:52:34 -0600 (MDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1U00LHJERLLD60@brm-avmta-1.central.sun.com>; Mon,
 02 Jun 2008 09:52:33 -0600 (MDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m52FqX0j005091;
 Mon, 02 Jun 2008 10:52:33 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m52FqXtS005090; Mon,
 02 Jun 2008 10:52:33 -0500 (CDT)
Date: Mon, 02 Jun 2008 10:52:33 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <4843C790.6090607@Sun.COM>
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Raymond Xiong <Raymond.Xiong@sun.com>,
        Bill Sommerfeld <sommerfeld@sun.com>, PSARC-ext@sun.com,
        John.Fischer@sun.com
Mail-followup-to: Darren J Moffat <Darren.Moffat@Sun.COM>,
 Raymond Xiong <Raymond.Xiong@sun.com>, Bill Sommerfeld <sommerfeld@sun.com>,
 PSARC-ext@sun.com, John.Fischer@sun.com
Message-id: <20080602155232.GR2735@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
 <483BE725.3010805@Sun.COM> <1212015310.1128.22.camel@localhost>
 <20080602095743.GA673@Sun.Com> <4843C790.6090607@Sun.COM>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 1068

On Mon, Jun 02, 2008 at 11:12:32AM +0100, Darren J Moffat wrote:
> Raymond Xiong wrote:
> >Two more notes on user authentication:
> >
> >1) ejabberd also supports PAM authentication. So it is possible to 
> >use UNIX accounts for ejabberd user authentication(though I don't think
> >this was recommended in its manual). For various reason, this feature
> >won't be supported in my package. 
> 
> Actually that might be a much better idea because it opens up a lot of 
> scope for better authentication.
> 
> Given that Solaris invented PAM I find it very strange to integrate 
> something that has PAM support available but to disable it.
> 
> Running with PAM will, unfortunately, require that the daemon run with 
> all privileges during authentication.

XMPP supports SASL for user authentication.  ejabberd ought to support
that.  ejabberd should get the ability to authenticate users via Unix
credentials through libsasl, not through PAM directly.  (Of course,
IIRC, our libsasl doesn't provide a way to do this, but that wouldn't be
ejabberd's fault!)

Nico
-- 

From Raymond.Xiong@sun.com Tue Jun  3 05:02:34 2008
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m53C2YWf021076
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 3 Jun 2008 05:02:34 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m53C2WHn031179;
	Tue, 3 Jun 2008 06:02:34 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1V00I0VYSAH000@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 03 Jun 2008 05:02:34 -0700 (PDT)
Received: from dm-singapore-02.singapore.sun.com ([129.158.71.102])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1V00BDDYS68830@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 03 Jun 2008 05:02:31 -0700 (PDT)
Received: from sineb-smtp-1.singapore.sun.com
 (sineb-smtp-1.Singapore.Sun.COM [129.158.123.4])
	by dm-singapore-02.singapore.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m53C2U0X019448; Tue, 03 Jun 2008 20:02:30 +0800 (SGT)
Received: from phys-sedge2-1.singapore.sun.com
 (phys-sedge2-1.Singapore.Sun.COM [129.158.123.14])
	by sineb-smtp-1.singapore.sun.com (8.13.6+Sun/8.12.9)
 with ESMTP id m53CGX60011451; Tue, 03 Jun 2008 12:16:33 +0000 (GMT)
Received: from localhost ([129.158.219.68]) by sedge2-mail1.singapore.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPA id <0K1V00BDKYS03C80@sedge2-mail1.singapore.sun.com>; Tue,
 03 Jun 2008 20:02:24 +0800 (SGT)
Date: Tue, 03 Jun 2008 19:57:06 +0800
From: Raymond Xiong <Raymond.Xiong@sun.com>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <20080602155232.GR2735@Sun.COM>
To: Darren J Moffat <Darren.Moffat@sun.com>,
        Bill Sommerfeld <sommerfeld@sun.com>, PSARC-ext@sun.com,
        John.Fischer@sun.com
Message-id: <20080603115705.GA16530@Sun.Com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
 <483BE725.3010805@Sun.COM> <1212015310.1128.22.camel@localhost>
 <20080602095743.GA673@Sun.Com> <4843C790.6090607@Sun.COM>
 <20080602155232.GR2735@Sun.COM>
User-Agent: Mutt/1.5.11
Status: RO
Content-Length: 2892

On 06/02/08, Nicolas Williams wrote:
> On Mon, Jun 02, 2008 at 11:12:32AM +0100, Darren J Moffat wrote:
> > Raymond Xiong wrote:
> > >Two more notes on user authentication:
> > >
> > >1) ejabberd also supports PAM authentication. So it is possible to 
> > >use UNIX accounts for ejabberd user authentication(though I don't think
> > >this was recommended in its manual). For various reason, this feature
> > >won't be supported in my package. 
> > 
> > Actually that might be a much better idea because it opens up a lot of 
> > scope for better authentication.
> > 
> > Given that Solaris invented PAM I find it very strange to integrate 
> > something that has PAM support available but to disable it.
> > 
> > Running with PAM will, unfortunately, require that the daemon run with 
> > all privileges during authentication.
> 
> XMPP supports SASL for user authentication.  ejabberd ought to support
> that.  ejabberd should get the ability to authenticate users via Unix
> credentials through libsasl, not through PAM directly.  (Of course,
> IIRC, our libsasl doesn't provide a way to do this, but that wouldn't be
> ejabberd's fault!)
> 

ejabberd supports SASL(actually it always uses SASL so that client 
that doesn't support SASL cannot connect to it), but unfortunately
it only suports very limited mechanisms: digest-md5, plain, and 
anonymous. 

That is due to the fact that, rather than rely on native C library,
ejabberd implements SASL by its own. I googled on this topic but 
found very few discussion on it. I don't think there are active 
development to improve this either.

So, the way I understand it, to authenticate ejabberd users via 
UNIX credentials or other PAM authentication services, PAM needs 
to be configured explicitly(although SASL is always used). It 
seems the current SASL support in ejabberd is more like a way
to transfer password on network than an authentication framework.

BTW, XMPP(and ejabberd) also supports TLS to encrypt all the XML
messages(including messages for authentication). That is an 
optional feature and can be configured. (I think SASL is also
an optional feature, but it cannot be configured for ejabberd).

Regarding ejabberd support for PAM authentication, I have tried
that and it seems work. To perform PAM authentication, ejabberd
uses an external C program. To solve the root privileges issue,
the manual suggested to use setuid approach(see "PAM authentication"
in section 3.1.4 on following link). 

  http://www.process-one.net/docs/ejabberd/guide_en.html

I guess setuid is probably not allowed, but I think we can do it
by setting that C program's execution attritute in "Ejabberd
Administration" profile as root.

Another thing I am not sure is what PAM authentication service 
name will be used for ejabberd. I used "other" in my experiments.
Do we need a new "ejabberd" service name for that? 

-- 
Regards,
Raymond

From Nicolas.Williams@sun.com Tue Jun  3 07:28:46 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m53ESkMV024475
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 3 Jun 2008 07:28:46 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m53ESg9g004025;
	Tue, 3 Jun 2008 07:28:42 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1W00J2J5JUDV00@brm-avmta-1.central.sun.com>; Tue,
 03 Jun 2008 08:28:42 -0600 (MDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1W00F6R5JTEV30@brm-avmta-1.central.sun.com>; Tue,
 03 Jun 2008 08:28:41 -0600 (MDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1) with ESMTP id m53ESf6Y005587;
 Tue, 03 Jun 2008 09:28:41 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.1+Sun/8.14.1/Submit) id m53ESejL005586; Tue,
 03 Jun 2008 09:28:40 -0500 (CDT)
Date: Tue, 03 Jun 2008 09:28:40 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <20080603115705.GA16530@Sun.Com>
To: Raymond Xiong <Raymond.Xiong@sun.com>
Cc: Darren J Moffat <Darren.Moffat@sun.com>,
        Bill Sommerfeld <sommerfeld@sun.com>, PSARC-ext@sun.com,
        John.Fischer@sun.com
Mail-followup-to: Raymond Xiong <Raymond.Xiong@Sun.COM>,
 Darren J Moffat <Darren.Moffat@sun.com>, Bill Sommerfeld <sommerfeld@sun.com>,
 PSARC-ext@sun.com, John.Fischer@sun.com
Message-id: <20080603142840.GM2735@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
 <483BE725.3010805@Sun.COM> <1212015310.1128.22.camel@localhost>
 <20080602095743.GA673@Sun.Com> <4843C790.6090607@Sun.COM>
 <20080602155232.GR2735@Sun.COM> <20080603115705.GA16530@Sun.Com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 1716

On Tue, Jun 03, 2008 at 07:57:06PM +0800, Raymond Xiong wrote:
> ejabberd supports SASL(actually it always uses SASL so that client 
> that doesn't support SASL cannot connect to it), but unfortunately
> it only suports very limited mechanisms: digest-md5, plain, and 
> anonymous. 

That's fine.  SASL/GSSAPI support would be very nice too, but that's
another case.

> That is due to the fact that, rather than rely on native C library,
> ejabberd implements SASL by its own. I googled on this topic but 
> found very few discussion on it. I don't think there are active 
> development to improve this either.

Is the TLS layer also implemented natively by ejabberd?

> So, the way I understand it, to authenticate ejabberd users via 
> UNIX credentials or other PAM authentication services, PAM needs 
> to be configured explicitly(although SASL is always used). It 
> seems the current SASL support in ejabberd is more like a way
> to transfer password on network than an authentication framework.

Right.  I'm supporting your decision to disable this.

> BTW, XMPP(and ejabberd) also supports TLS to encrypt all the XML
> messages(including messages for authentication). That is an 
> optional feature and can be configured. (I think SASL is also
> an optional feature, but it cannot be configured for ejabberd).

Does ejabberd use OpenSSL?

> Regarding ejabberd support for PAM authentication, I have tried
> that and it seems work. To perform PAM authentication, ejabberd
> uses an external C program. To solve the root privileges issue,
> the manual suggested to use setuid approach(see "PAM authentication"
> in section 3.1.4 on following link). 

Please leave PAM support disabled / compiled out.

Nico
-- 

From James.Walker@sun.com Tue Jun  3 08:36:52 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m53FaqZA026136
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 3 Jun 2008 08:36:52 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m53Fapgj029521
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 3 Jun 2008 08:36:51 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1W00G018PDPR00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 03 Jun 2008 08:36:49 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1W00FRG8PDI700@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 03 Jun 2008 08:36:49 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id m53Fankt017139	for
 <PSARC-ext@sun.com>; Tue, 03 Jun 2008 15:36:49 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 id <0K1W00F017IMVB00@mail-amer.sun.com>
 (original mail from James.Walker@Sun.COM)
 for PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 03 Jun 2008 09:36:49 -0600 (MDT)
Received: from [172.20.25.153] by mail-amer.sun.com
 (Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
 with ESMTPSA id <0K1W00KPX8P1VTF0@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 03 Jun 2008 09:36:37 -0600 (MDT)
Date: Tue, 03 Jun 2008 09:41:04 -0600
From: Jim Walker <James.Walker@sun.com>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <20080603142840.GM2735@Sun.COM>
Sender: James.Walker@sun.com
To: Raymond Xiong <Raymond.Xiong@sun.com>, PSARC-ext@sun.com,
        John.Fischer@sun.com
Reply-to: James.Walker@sun.com
Message-id: <48456610.9000203@sun.com>
Organization: Sun Microsystems, Inc.
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
 <483BE725.3010805@Sun.COM> <1212015310.1128.22.camel@localhost>
 <20080602095743.GA673@Sun.Com> <4843C790.6090607@Sun.COM>
 <20080602155232.GR2735@Sun.COM> <20080603115705.GA16530@Sun.Com>
 <20080603142840.GM2735@Sun.COM>
User-Agent: Thunderbird 2.0.0.12 (X11/20080326)
Status: RO
Content-Length: 328

Nicolas Williams wrote:
> 
> Does ejabberd use OpenSSL?
> 

Yes. Raymond has an approved OpenSSL contract for ejabberd.

There should be a contract-19 doc here for ejabberd. There's a space
for it:
http://sac.eng.sun.com/Archives/CaseLog/arc/PSARC/2003/500/contracts/

Raymond, John,

Can you update the materials?

Thanks,
Jim

From Raymond.Xiong@sun.com Wed Jun  4 09:11:53 2008
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m54GBqJM025875
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 4 Jun 2008 09:11:52 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id m54GBlI3026279;
	Wed, 4 Jun 2008 17:11:51 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1Y00L034ZQCU00@brm-avmta-1.central.sun.com>; Wed,
 04 Jun 2008 10:11:50 -0600 (MDT)
Received: from dm-singapore-01.singapore.sun.com ([129.158.71.101])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1Y008SX4ZODEC0@brm-avmta-1.central.sun.com>; Wed,
 04 Jun 2008 10:11:49 -0600 (MDT)
Received: from sineb-smtp-1.singapore.sun.com
 (sineb-smtp-1.Singapore.Sun.COM [129.158.123.4])
	by dm-singapore-01.singapore.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m54GBmig010960; Thu, 05 Jun 2008 00:11:48 +0800 (SGT)
Received: from phys-sedge2-1.singapore.sun.com
 (phys-sedge2-1.Singapore.Sun.COM [129.158.123.14])
	by sineb-smtp-1.singapore.sun.com (8.13.6+Sun/8.12.9)
 with ESMTP id m54GPowT019395; Wed, 04 Jun 2008 16:25:50 +0000 (GMT)
Received: from localhost ([129.158.219.68]) by sedge2-mail1.singapore.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPA id <0K1Y002FF4ZISFF0@sedge2-mail1.singapore.sun.com>; Thu,
 05 Jun 2008 00:11:43 +0800 (SGT)
Date: Thu, 05 Jun 2008 00:06:23 +0800
From: Raymond Xiong <Raymond.Xiong@sun.com>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <4843C6E4.4040008@Sun.COM>
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Bill Sommerfeld <sommerfeld@sun.com>, PSARC-ext@sun.com,
        John.Fischer@sun.com
Message-id: <20080604160622.GA17024@Sun.Com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
 <483BE725.3010805@Sun.COM> <1212015310.1128.22.camel@localhost>
 <20080602095743.GA673@Sun.Com> <4843C6E4.4040008@Sun.COM>
User-Agent: Mutt/1.5.11
Status: RO
Content-Length: 1191

On 06/02/08, Darren J Moffat wrote:
> Raymond Xiong wrote:
> >Mnesia on-disk files will be placed under /usr/lib/ejabberd/db/ejabberd
> >(you may notice I didn't list the directory in FastTrack, because it
> >is typically created automatically). All data files under this subdir
> >are owned by daemon, and have 600 as their permissions.
> 
> That needs to change to somewhere under /var or /etc you can not assume 
> /usr/ or subdirs of it are writable.  This would break the use of 
> ejabberd in the default zone or diskless client configuration.

Thanks for the catch. I will place ejabberd database files under
/var/db/ejabberd. For your convenience, below are new files/dirs 
introduced by ejabberd:

   /usr/sbin/ejabberdctl  -  command
   /usr/lib/ejabberd/     -  ejabberd private directory(read only)
   /etc/ejabberd/         -  directory for ejabberd config files
   /var/log/ejabberd/     -  directory for ejabberd log files
   /var/db/ejabberd/      -  directory for ejabberd mnesia db files

Both /var/db/ejabberd and /var/log/ejabberd will be owned by daemon.
Permission of /var/db/ejabberd will be 700, and permission of
/var/log/ejabberd will be 755.

-- 
Regards,
Raymond

From Raymond.Xiong@sun.com Wed Jun  4 09:35:07 2008
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m54GZ7Qt028182
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 4 Jun 2008 09:35:07 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id m54GZ2m5008872;
	Wed, 4 Jun 2008 09:35:06 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1Y00M1362IY600@brm-avmta-1.central.sun.com>; Wed,
 04 Jun 2008 10:35:06 -0600 (MDT)
Received: from dm-singapore-02.singapore.sun.com ([129.158.71.102])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1Y008H162FD5E0@brm-avmta-1.central.sun.com>; Wed,
 04 Jun 2008 10:35:04 -0600 (MDT)
Received: from sineb-smtp-1.singapore.sun.com
 (sineb-smtp-1.Singapore.Sun.COM [129.158.123.4])
	by dm-singapore-02.singapore.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m54GZ3nL017202; Thu, 05 Jun 2008 00:35:03 +0800 (SGT)
Received: from phys-sedge2-1.singapore.sun.com
 (phys-sedge2-1.Singapore.Sun.COM [129.158.123.14])
	by sineb-smtp-1.singapore.sun.com (8.13.6+Sun/8.12.9)
 with ESMTP id m54Gn538019898; Wed, 04 Jun 2008 16:49:05 +0000 (GMT)
Received: from localhost ([129.158.219.68]) by sedge2-mail1.singapore.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPA id <0K1Y00LVO628JY10@sedge2-mail1.singapore.sun.com>; Thu,
 05 Jun 2008 00:34:57 +0800 (SGT)
Date: Thu, 05 Jun 2008 00:29:37 +0800
From: Raymond Xiong <Raymond.Xiong@sun.com>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <20080603142840.GM2735@Sun.COM>
To: PSARC-ext@sun.com
Cc: Darren J Moffat <Darren.Moffat@sun.com>,
        Bill Sommerfeld <sommerfeld@sun.com>, John.Fischer@sun.com
Message-id: <20080604162937.GB17024@Sun.Com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200805222327.m4MNRZIw014086@sac.sfbay.sun.com>
 <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
 <483BE725.3010805@Sun.COM> <1212015310.1128.22.camel@localhost>
 <20080602095743.GA673@Sun.Com> <4843C790.6090607@Sun.COM>
 <20080602155232.GR2735@Sun.COM> <20080603115705.GA16530@Sun.Com>
 <20080603142840.GM2735@Sun.COM>
User-Agent: Mutt/1.5.11
Status: RO
Content-Length: 866

On 06/03/08, Nicolas Williams wrote:
> > That is due to the fact that, rather than rely on native C library,
> > ejabberd implements SASL by its own. I googled on this topic but 
> > found very few discussion on it. I don't think there are active 
> > development to improve this either.
> 
> Is the TLS layer also implemented natively by ejabberd?

No, it uses OpenSSL library. 

Erlang has a SSL library(it uses OpenSSL's crypto library but 
implement the protocol with Erlang). For unclear reason, ejabberd
doesn't use it.

> > BTW, XMPP(and ejabberd) also supports TLS to encrypt all the XML
> > messages(including messages for authentication). That is an 
> > optional feature and can be configured. (I think SASL is also
> > an optional feature, but it cannot be configured for ejabberd).
> 
> Does ejabberd use OpenSSL?

Yes, see above.

-- 
Regards,
Raymond

From Raymond.Xiong@sun.com Wed Jun  4 09:37:25 2008
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id m54GbOC5028410
	for <psarc-ext@sac.sfbay.Sun.COM>; Wed, 4 Jun 2008 09:37:25 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id m54GbFWB021202
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Thu, 5 Jun 2008 00:37:23 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0K1Y00H016697R00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.com); Wed, 04 Jun 2008 09:37:21 -0700 (PDT)
Received: from dm-singapore-02.singapore.sun.com ([129.158.71.102])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0K1Y00GCK6684A10@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.com); Wed,
 04 Jun 2008 09:37:21 -0700 (PDT)
Received: from sineb-smtp-1.singapore.sun.com
 (sineb-smtp-1.Singapore.Sun.COM [129.158.123.4])
	by dm-singapore-02.singapore.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id m54GbABR017984	for <PSARC-ext@Sun.COM>; Thu,
 05 Jun 2008 00:37:10 +0800 (SGT)
Received: from phys-sedge2-1.singapore.sun.com
 (phys-sedge2-1.Singapore.Sun.COM [129.158.123.14])
	by sineb-smtp-1.singapore.sun.com (8.13.6+Sun/8.12.9)
 with ESMTP id m54GpCjc019944	for <@smarthost.sun.com:PSARC-ext@Sun.com>; Wed,
 04 Jun 2008 16:51:12 +0000 (GMT)
Received: from localhost ([129.158.219.68]) by sedge2-mail1.singapore.sun.com
 (Sun Java System Messaging Server 6.2-6.01 (built Apr  3 2006))
 with ESMTPA id <0K1Y00L5B65RJY20@sedge2-mail1.singapore.sun.com> for
 PSARC-ext@Sun.com (ORCPT PSARC-ext@Sun.com); Thu,
 05 Jun 2008 00:37:04 +0800 (SGT)
Date: Thu, 05 Jun 2008 00:31:44 +0800
From: Raymond Xiong <Raymond.Xiong@sun.com>
Subject: Re: ejabberd instant messaging server [PSARC/2008/340 FastTrack
 timeout 05/29/2008]
In-reply-to: <48456610.9000203@sun.com>
To: Jim Walker <James.Walker@sun.com>
Cc: PSARC-ext@sun.com, John.Fischer@sun.com
Message-id: <20080604163144.GC17024@Sun.Com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <483696D1.3000704@Sun.COM> <20080526112314.GA825@Sun.Com>
 <483BE725.3010805@Sun.COM> <1212015310.1128.22.camel@localhost>
 <20080602095743.GA673@Sun.Com> <4843C790.6090607@Sun.COM>
 <20080602155232.GR2735@Sun.COM> <20080603115705.GA16530@Sun.Com>
 <20080603142840.GM2735@Sun.COM> <48456610.9000203@sun.com>
User-Agent: Mutt/1.5.11
Status: RO
Content-Length: 438

On 06/03/08, Jim Walker wrote:
> Nicolas Williams wrote:
> >
> >Does ejabberd use OpenSSL?
> >
> 
> Yes. Raymond has an approved OpenSSL contract for ejabberd.
> 
> There should be a contract-19 doc here for ejabberd. There's a space
> for it:
> http://sac.eng.sun.com/Archives/CaseLog/arc/PSARC/2003/500/contracts/
> 
> Raymond, John,
> 
> Can you update the materials?

Jim,

I will contact John offline for this.

-- 
Regards,
Raymond

From James.Walker@sun.com Mon May 18 14:03:15 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4IL3Ep7011456;
	Mon, 18 May 2009 14:03:14 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n4IL34wQ024020;
	Mon, 18 May 2009 22:03:13 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJU00I1TYHC1500@brm-avmta-1.central.sun.com>; Mon,
 18 May 2009 15:03:12 -0600 (MDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJU00B8DYHCG6A0@brm-avmta-1.central.sun.com>; Mon,
 18 May 2009 15:03:12 -0600 (MDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n4IL3Cxh024950; Mon,
 18 May 2009 21:03:12 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KJU00600V7KLP00@mail-amer.sun.com>; Mon, 18 May 2009 15:03:12 -0600 (MDT)
Received: from [172.20.25.153] ([unknown] [172.20.25.153])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KJU00LELYGP6T80@mail-amer.sun.com>; Mon,
 18 May 2009 15:02:50 -0600 (MDT)
Date: Mon, 18 May 2009 15:13:59 -0600
From: Jim Walker <James.Walker@sun.com>
Subject: ejabberd [LSARC/2008/218 closed superceded by PSARC/2008/340]
Sender: James.Walker@sun.com
To: LSARC-ext@sun.com, PSARC-ext@sun.com
Reply-to: James.Walker@sun.com
Message-id: <4A11CF97.4000708@sun.com>
Organization: Sun Microsystems, Inc.
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.14 (X11/20080728)
x_sac_archived: LSARC/2008/218
Status: RO
Content-Length: 143

Housekeeping...

I'm closing the orphaned ejabberd LSARC/2008/218 case
which was superceded by PSARC/2008/340 which was
approved.

Cheers,
Jim

From James.Walker@sun.com Mon May 18 14:03:15 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4IL3Ep7011456;
	Mon, 18 May 2009 14:03:14 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n4IL34wQ024020;
	Mon, 18 May 2009 22:03:13 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJU00I1TYHC1500@brm-avmta-1.central.sun.com>; Mon,
 18 May 2009 15:03:12 -0600 (MDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJU00B8DYHCG6A0@brm-avmta-1.central.sun.com>; Mon,
 18 May 2009 15:03:12 -0600 (MDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n4IL3Cxh024950; Mon,
 18 May 2009 21:03:12 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KJU00600V7KLP00@mail-amer.sun.com>; Mon, 18 May 2009 15:03:12 -0600 (MDT)
Received: from [172.20.25.153] ([unknown] [172.20.25.153])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KJU00LELYGP6T80@mail-amer.sun.com>; Mon,
 18 May 2009 15:02:50 -0600 (MDT)
Date: Mon, 18 May 2009 15:13:59 -0600
From: Jim Walker <James.Walker@sun.com>
Subject: ejabberd [LSARC/2008/218 closed superceded by PSARC/2008/340]
Sender: James.Walker@sun.com
To: LSARC-ext@sun.com, PSARC-ext@sun.com
Reply-to: James.Walker@sun.com
Message-id: <4A11CF97.4000708@sun.com>
Organization: Sun Microsystems, Inc.
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.14 (X11/20080728)
Status: RO
Content-Length: 143

Housekeeping...

I'm closing the orphaned ejabberd LSARC/2008/218 case
which was superceded by PSARC/2008/340 which was
approved.

Cheers,
Jim

