Commit b826be3d authored by Nilgun Belma Buguner's avatar Nilgun Belma Buguner
Browse files

pre-translation improvements

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@698397 13f79535-47bb-0310-9956-ffa450edef68
parent 63f2e1ed
Loading
Loading
Loading
Loading
+39 −27
Changes for docs/manual/suexec.xml: 39 added lines, 27 removed lines.
Original line number Diff line number Diff line
@@ -29,7 +29,7 @@
    Apache users the ability
    to run <strong>CGI</strong> and <strong>SSI</strong> programs
    under user IDs different from the user ID of the calling
    web-server. Normally, when a CGI or SSI program executes, it
    web server. Normally, when a CGI or SSI program executes, it
    runs as the same user who is running the web server.</p>

    <p>Used properly, this feature can reduce
@@ -250,7 +250,8 @@
        <p class="indent">
          If the request is for a regular portion of the server, is
          the requested directory within suEXEC's document root? If
          the request is for a UserDir, is the requested directory
          the request is for a <directive module="mod_userdir"
          >UserDir</directive>, is the requested directory
          within the directory configured as suEXEC's userdir (see
          <a href="#install">suEXEC's configuration options</a>)?
        </p>
@@ -378,13 +379,15 @@
      directories where suEXEC access should be allowed. All
      executables under this directory will be executable by suEXEC
      as the user so they should be "safe" programs. If you are
      using a "simple" UserDir directive (ie. one without a "*" in
      it) this should be set to the same value. suEXEC will not
      work properly in cases where the UserDir directive points to
      using a "simple" <directive module="mod_userdir">UserDir</directive>
      directive (ie. one without a "*" in it) this should be set to the same
      value. suEXEC will not work properly in cases where the <directive
      module="mod_userdir">UserDir</directive> directive points to
      a location that is not the same as the user's home directory
      as referenced in the passwd file. Default value is
      "public_html".<br />
       If you have virtual hosts with a different UserDir for each,
      as referenced in the <code>passwd</code> file. Default value is
      "<code>public_html</code>".<br />
      If you have virtual hosts with a different <directive
      module="mod_userdir">UserDir</directive> for each,
      you will need to define them to all reside in one parent
      directory; then name that parent directory here. <strong>If
      this is not defined properly, "~userdir" cgi requests will
@@ -393,12 +396,13 @@
      <dt><code>--with-suexec-docroot=<em>DIR</em></code></dt>

      <dd>Define as the DocumentRoot set for Apache. This will be
      the only hierarchy (aside from UserDirs) that can be used for
      suEXEC behavior. The default directory is the <code>--datadir</code>
      value with the suffix "/htdocs", <em>e.g.</em> if you configure
      with "<code>--datadir=/home/apache</code>" the directory
      "/home/apache/htdocs" is used as document root for the suEXEC
      wrapper.</dd>
      the only hierarchy (aside from <directive module="mod_userdir"
      >UserDir</directive>s) that can be used for suEXEC behavior. The
      default directory is the <code>--datadir</code> value with the suffix
      "<code>/htdocs</code>", <em>e.g.</em> if you configure with
      "<code>--datadir=/home/apache</code>" the directory
      "<code>/home/apache/htdocs</code>" is used as document root for the
      suEXEC wrapper.</dd>

      <dt><code>--with-suexec-uidmin=<em>UID</em></code></dt>

@@ -417,35 +421,41 @@
      <dd>This defines the filename to which all suEXEC
      transactions and errors are logged (useful for auditing and
      debugging purposes). By default the logfile is named
      "suexec_log" and located in your standard logfile directory
      (<code>--logfiledir</code>).</dd>
      "<code>suexec_log</code>" and located in your standard logfile
      directory (<code>--logfiledir</code>).</dd>

      <dt><code>--with-suexec-safepath=<em>PATH</em></code></dt>

      <dd>Define a safe PATH environment to pass to CGI
      executables. Default value is
      "/usr/local/bin:/usr/bin:/bin".</dd>
      "<code>/usr/local/bin:/usr/bin:/bin</code>".</dd>
    </dl>

    <p><strong>Compiling and installing the suEXEC
    wrapper</strong><br />
     If you have enabled the suEXEC feature with the
    <section>
      <title>Compiling and installing the suEXEC wrapper</title>

      <p>If you have enabled the suEXEC feature with the
      <code>--enable-suexec</code> option the <code>suexec</code> binary
      (together with Apache itself) is automatically built if you execute
    the <code>make</code> command.<br />
     After all components have been built you can execute the
      the <code>make</code> command.</p>

      <p>After all components have been built you can execute the
      command <code>make install</code> to install them. The binary image
      <code>suexec</code> is installed in the directory defined by the
      <code>--sbindir</code> option. The default location is
    "/usr/local/apache2/bin/suexec".<br />
     Please note that you need <strong><em>root
      "/usr/local/apache2/bin/suexec".</p>

      <p>Please note that you need <strong><em>root
      privileges</em></strong> for the installation step. In order
      for the wrapper to set the user ID, it must be installed as
      owner <code><em>root</em></code> and must have the setuserid
      execution bit set for file modes.</p>
    </section>

    <p><strong>Setting paranoid permissions</strong><br />
    Although the suEXEC wrapper will check to ensure that its
    <section>
      <title>Setting paranoid permissions</title>

      <p>Although the suEXEC wrapper will check to ensure that its
      caller is the correct user as specified with the
      <code>--with-suexec-caller</code> <program>configure</program>
      option, there is
@@ -455,7 +465,7 @@
      filesystem permissions to ensure that only the group Apache
      runs as may execute suEXEC.</p>

    <p>If for example, your web-server is configured to run as:</p>
      <p>If for example, your web server is configured to run as:</p>

      <example>
          User www<br />
@@ -473,6 +483,8 @@
      <p>This will ensure that only the group Apache runs as can even
      execute the suEXEC wrapper.</p>
    </section>
</section>


<section id="enable"><title>Enabling &amp; Disabling
    suEXEC</title>