You are not logged in.

#1 2008-08-31 13:11:30

Skippy le Grand Gourou
Member
Registered: 2007-06-12
Posts: 15

Please make consistent server packages ! (or documentation, actually…)

Hi,

Don't want to sound unpleasant, but in arch core packages, apache runs by default as nobody, right ? However SuExec support is compiled for user http, as is mailman ! And I guess they are many other group mismatch potential issues in other packages, there is no reason there wouldn't be.

I agree that's a pity that user and group definition have to be compiled and not simply set in some config file — though it must be more secure. But please, could archlinux just choose ONE user/group for ALL server packages and compiled them so that packages are consistent and usable ?

Thanks.

Edit : BTW, this wiki page won't work, as suexec is set to run as http :

# suexec -V
 -D AP_DOC_ROOT="/srv/http"
 -D AP_GID_MIN=99
 -D AP_HTTPD_USER="http"
 -D AP_LOG_EXEC="/var/log/httpd/suexec.log"
 -D AP_SAFE_PATH="/usr/local/bin:/usr/bin:/bin"
 -D AP_UID_MIN=99
 -D AP_USERDIR_SUFFIX="public_html"

Last edited by Skippy le Grand Gourou (2008-08-31 13:23:50)

Offline

#2 2008-08-31 13:15:24

Pierre
Developer
From: Bonn
Registered: 2004-07-05
Posts: 1,964
Website

Re: Please make consistent server packages ! (or documentation, actually…)

You are wrong. At first apache is in extra and not in core. And it uses http user and group by default. So does lighttpd. If there is still a webserver package using nobody as uer/grouzp, please file a bug report.

Offline

#3 2008-08-31 13:21:26

Skippy le Grand Gourou
Member
Registered: 2007-06-12
Posts: 15

Re: Please make consistent server packages ! (or documentation, actually…)

Pierre wrote:

You are wrong. At first apache is in extra and not in core. And it uses http user and group by default. So does lighttpd. If there is still a webserver package using nobody as uer/grouzp, please file a bug report.

Really ?? Ok, sorry for that. hmm

Anyway, I didn't invent the nobody user,I must have changed the default to follow some wiki page  so there must be some wrong doc somewhere (as the wiki page I mentionned in the first post, which says to set apache to run as nobody).

Offline

#4 2008-08-31 21:48:26

tigrmesh
IRC Op
From: Florida, US
Registered: 2007-12-11
Posts: 794

Re: Please make consistent server packages ! (or documentation, actually…)

Skippy le Grand Gourou wrote:

there must be some wrong doc somewhere (as the wiki page I mentionned in the first post, which says to set apache to run as nobody).

Since the wiki is wrong, please correct it.  All you need to do is create an account and edit the page(s).  And thanks in advance for fixing it.  I don't use apache, but should I ever need/want to, I will be glad for your effort.

Offline

#5 2008-08-31 21:56:09

Skippy le Grand Gourou
Member
Registered: 2007-06-12
Posts: 15

Re: Please make consistent server packages ! (or documentation, actually…)

tigrmesh wrote:
Skippy le Grand Gourou wrote:

there must be some wrong doc somewhere (as the wiki page I mentionned in the first post, which says to set apache to run as nobody).

Since the wiki is wrong, please correct it.  All you need to do is create an account and edit the page(s).  And thanks in advance for fixing it.  I don't use apache, but should I ever need/want to, I will be glad for your effort.

Done.

Offline

Board footer

Powered by FluxBB