Index: [Article Count Order] [Thread]

Date:  Thu, 31 Jul 2008 08:22:19 -0400
From:  "Stephanie Sullivan" <bq (at mark) aviaweb.com>
Subject:  [coba-e:13654] Re: apache suexec
To:  <coba-e (at mark) bluequartz.org>
Message-Id:  <00a001c8f308$13d5b640$3b8122c0$@com>
In-Reply-To:  <722224.90970.qm (at mark) web65612.mail.ac4.yahoo.com>
References:  <0b9201c8f2e4$d3d005f0$967da8c0 (at mark) thomasferrari> <722224.90970.qm (at mark) web65612.mail.ac4.yahoo.com>
X-Mail-Count: 13654

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

The issue as I see it (and I have seen this too) is when files are created
via apache (as in php creating a file) they are created with the user and
group of apache. In the RaQ4 files were created with the user of httpd and
the group of the site. 

By default, when creating files in a directory the group should be the group
of the parent folder. You may notice this if you create a file in a virtual
site's path as user root. The file has owner root, but the group is sitexx
where xx is the site number.

Like I said, apache on the RaQ4 did this in a useful way. On the RaQ4 I
believe the files were created with the permission for group write also, but
I'm not positive of that.

The BQ apache.apache ownership causes severe problems for site admins. They
cannot modify files created via apache in their site and there is a host of
other problems. 

I don't care if the owner is apache, but the files should be created with
default group write set in the permissions and the group should not be
forced to apache, but be allowed to default to the group of the directory
where the file is created (like a normal user, or even root).

I hope this helps clarify this issue which causes me some consternation. I
have not found a workaround, but haven't looked all that hard, I must admit.

	Thanks,
		-Stephanie


-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: us-ascii

wj8DBQFIka5/RmFh0h8+YHsRAlSMAKDE3u5BhbBMEuMIOk6polXZDK6CIACeLooU
swTwgULqT61BqEggcWr/pLI=
=H7sJ
-----END PGP SIGNATURE-----