Loading docs/manual/suexec.xml +39 −27 Changes for docs/manual/suexec.xml: 39 added lines, 27 removed lines. Original line number Diff line number Diff line Loading @@ -29,7 +29,7 @@ Apache users the ability to run <strong>CGI</strong> and <strong>SSI</strong> programs under user IDs different from the user ID of the calling web-server. Normally, when a CGI or SSI program executes, it web server. Normally, when a CGI or SSI program executes, it runs as the same user who is running the web server.</p> <p>Used properly, this feature can reduce Loading Loading @@ -250,7 +250,8 @@ <p class="indent"> If the request is for a regular portion of the server, is the requested directory within suEXEC's document root? If the request is for a UserDir, is the requested directory the request is for a <directive module="mod_userdir" >UserDir</directive>, is the requested directory within the directory configured as suEXEC's userdir (see <a href="#install">suEXEC's configuration options</a>)? </p> Loading Loading @@ -378,13 +379,15 @@ directories where suEXEC access should be allowed. All executables under this directory will be executable by suEXEC as the user so they should be "safe" programs. If you are using a "simple" UserDir directive (ie. one without a "*" in it) this should be set to the same value. suEXEC will not work properly in cases where the UserDir directive points to using a "simple" <directive module="mod_userdir">UserDir</directive> directive (ie. one without a "*" in it) this should be set to the same value. suEXEC will not work properly in cases where the <directive module="mod_userdir">UserDir</directive> directive points to a location that is not the same as the user's home directory as referenced in the passwd file. Default value is "public_html".<br /> If you have virtual hosts with a different UserDir for each, as referenced in the <code>passwd</code> file. Default value is "<code>public_html</code>".<br /> If you have virtual hosts with a different <directive module="mod_userdir">UserDir</directive> for each, you will need to define them to all reside in one parent directory; then name that parent directory here. <strong>If this is not defined properly, "~userdir" cgi requests will Loading @@ -393,12 +396,13 @@ <dt><code>--with-suexec-docroot=<em>DIR</em></code></dt> <dd>Define as the DocumentRoot set for Apache. This will be the only hierarchy (aside from UserDirs) that can be used for suEXEC behavior. The default directory is the <code>--datadir</code> value with the suffix "/htdocs", <em>e.g.</em> if you configure with "<code>--datadir=/home/apache</code>" the directory "/home/apache/htdocs" is used as document root for the suEXEC wrapper.</dd> the only hierarchy (aside from <directive module="mod_userdir" >UserDir</directive>s) that can be used for suEXEC behavior. The default directory is the <code>--datadir</code> value with the suffix "<code>/htdocs</code>", <em>e.g.</em> if you configure with "<code>--datadir=/home/apache</code>" the directory "<code>/home/apache/htdocs</code>" is used as document root for the suEXEC wrapper.</dd> <dt><code>--with-suexec-uidmin=<em>UID</em></code></dt> Loading @@ -417,35 +421,41 @@ <dd>This defines the filename to which all suEXEC transactions and errors are logged (useful for auditing and debugging purposes). By default the logfile is named "suexec_log" and located in your standard logfile directory (<code>--logfiledir</code>).</dd> "<code>suexec_log</code>" and located in your standard logfile directory (<code>--logfiledir</code>).</dd> <dt><code>--with-suexec-safepath=<em>PATH</em></code></dt> <dd>Define a safe PATH environment to pass to CGI executables. Default value is "/usr/local/bin:/usr/bin:/bin".</dd> "<code>/usr/local/bin:/usr/bin:/bin</code>".</dd> </dl> <p><strong>Compiling and installing the suEXEC wrapper</strong><br /> If you have enabled the suEXEC feature with the <section> <title>Compiling and installing the suEXEC wrapper</title> <p>If you have enabled the suEXEC feature with the <code>--enable-suexec</code> option the <code>suexec</code> binary (together with Apache itself) is automatically built if you execute the <code>make</code> command.<br /> After all components have been built you can execute the the <code>make</code> command.</p> <p>After all components have been built you can execute the command <code>make install</code> to install them. The binary image <code>suexec</code> is installed in the directory defined by the <code>--sbindir</code> option. The default location is "/usr/local/apache2/bin/suexec".<br /> Please note that you need <strong><em>root "/usr/local/apache2/bin/suexec".</p> <p>Please note that you need <strong><em>root privileges</em></strong> for the installation step. In order for the wrapper to set the user ID, it must be installed as owner <code><em>root</em></code> and must have the setuserid execution bit set for file modes.</p> </section> <p><strong>Setting paranoid permissions</strong><br /> Although the suEXEC wrapper will check to ensure that its <section> <title>Setting paranoid permissions</title> <p>Although the suEXEC wrapper will check to ensure that its caller is the correct user as specified with the <code>--with-suexec-caller</code> <program>configure</program> option, there is Loading @@ -455,7 +465,7 @@ filesystem permissions to ensure that only the group Apache runs as may execute suEXEC.</p> <p>If for example, your web-server is configured to run as:</p> <p>If for example, your web server is configured to run as:</p> <example> User www<br /> Loading @@ -473,6 +483,8 @@ <p>This will ensure that only the group Apache runs as can even execute the suEXEC wrapper.</p> </section> </section> <section id="enable"><title>Enabling & Disabling suEXEC</title> Loading Loading
docs/manual/suexec.xml +39 −27 Changes for docs/manual/suexec.xml: 39 added lines, 27 removed lines. Original line number Diff line number Diff line Loading @@ -29,7 +29,7 @@ Apache users the ability to run <strong>CGI</strong> and <strong>SSI</strong> programs under user IDs different from the user ID of the calling web-server. Normally, when a CGI or SSI program executes, it web server. Normally, when a CGI or SSI program executes, it runs as the same user who is running the web server.</p> <p>Used properly, this feature can reduce Loading Loading @@ -250,7 +250,8 @@ <p class="indent"> If the request is for a regular portion of the server, is the requested directory within suEXEC's document root? If the request is for a UserDir, is the requested directory the request is for a <directive module="mod_userdir" >UserDir</directive>, is the requested directory within the directory configured as suEXEC's userdir (see <a href="#install">suEXEC's configuration options</a>)? </p> Loading Loading @@ -378,13 +379,15 @@ directories where suEXEC access should be allowed. All executables under this directory will be executable by suEXEC as the user so they should be "safe" programs. If you are using a "simple" UserDir directive (ie. one without a "*" in it) this should be set to the same value. suEXEC will not work properly in cases where the UserDir directive points to using a "simple" <directive module="mod_userdir">UserDir</directive> directive (ie. one without a "*" in it) this should be set to the same value. suEXEC will not work properly in cases where the <directive module="mod_userdir">UserDir</directive> directive points to a location that is not the same as the user's home directory as referenced in the passwd file. Default value is "public_html".<br /> If you have virtual hosts with a different UserDir for each, as referenced in the <code>passwd</code> file. Default value is "<code>public_html</code>".<br /> If you have virtual hosts with a different <directive module="mod_userdir">UserDir</directive> for each, you will need to define them to all reside in one parent directory; then name that parent directory here. <strong>If this is not defined properly, "~userdir" cgi requests will Loading @@ -393,12 +396,13 @@ <dt><code>--with-suexec-docroot=<em>DIR</em></code></dt> <dd>Define as the DocumentRoot set for Apache. This will be the only hierarchy (aside from UserDirs) that can be used for suEXEC behavior. The default directory is the <code>--datadir</code> value with the suffix "/htdocs", <em>e.g.</em> if you configure with "<code>--datadir=/home/apache</code>" the directory "/home/apache/htdocs" is used as document root for the suEXEC wrapper.</dd> the only hierarchy (aside from <directive module="mod_userdir" >UserDir</directive>s) that can be used for suEXEC behavior. The default directory is the <code>--datadir</code> value with the suffix "<code>/htdocs</code>", <em>e.g.</em> if you configure with "<code>--datadir=/home/apache</code>" the directory "<code>/home/apache/htdocs</code>" is used as document root for the suEXEC wrapper.</dd> <dt><code>--with-suexec-uidmin=<em>UID</em></code></dt> Loading @@ -417,35 +421,41 @@ <dd>This defines the filename to which all suEXEC transactions and errors are logged (useful for auditing and debugging purposes). By default the logfile is named "suexec_log" and located in your standard logfile directory (<code>--logfiledir</code>).</dd> "<code>suexec_log</code>" and located in your standard logfile directory (<code>--logfiledir</code>).</dd> <dt><code>--with-suexec-safepath=<em>PATH</em></code></dt> <dd>Define a safe PATH environment to pass to CGI executables. Default value is "/usr/local/bin:/usr/bin:/bin".</dd> "<code>/usr/local/bin:/usr/bin:/bin</code>".</dd> </dl> <p><strong>Compiling and installing the suEXEC wrapper</strong><br /> If you have enabled the suEXEC feature with the <section> <title>Compiling and installing the suEXEC wrapper</title> <p>If you have enabled the suEXEC feature with the <code>--enable-suexec</code> option the <code>suexec</code> binary (together with Apache itself) is automatically built if you execute the <code>make</code> command.<br /> After all components have been built you can execute the the <code>make</code> command.</p> <p>After all components have been built you can execute the command <code>make install</code> to install them. The binary image <code>suexec</code> is installed in the directory defined by the <code>--sbindir</code> option. The default location is "/usr/local/apache2/bin/suexec".<br /> Please note that you need <strong><em>root "/usr/local/apache2/bin/suexec".</p> <p>Please note that you need <strong><em>root privileges</em></strong> for the installation step. In order for the wrapper to set the user ID, it must be installed as owner <code><em>root</em></code> and must have the setuserid execution bit set for file modes.</p> </section> <p><strong>Setting paranoid permissions</strong><br /> Although the suEXEC wrapper will check to ensure that its <section> <title>Setting paranoid permissions</title> <p>Although the suEXEC wrapper will check to ensure that its caller is the correct user as specified with the <code>--with-suexec-caller</code> <program>configure</program> option, there is Loading @@ -455,7 +465,7 @@ filesystem permissions to ensure that only the group Apache runs as may execute suEXEC.</p> <p>If for example, your web-server is configured to run as:</p> <p>If for example, your web server is configured to run as:</p> <example> User www<br /> Loading @@ -473,6 +483,8 @@ <p>This will ensure that only the group Apache runs as can even execute the suEXEC wrapper.</p> </section> </section> <section id="enable"><title>Enabling & Disabling suEXEC</title> Loading