PDA

View Full Version : Give apache real login shell



rsteinberger
09-27-2007, 08:22 PM
According to the documentation (1.8 Hayes Official Install and Upgrade Guide/ FC6), I must modify /etc/passwd and give the apache user a real shell (instead of /sbin/nologin). This seems like a bad thing from a security perspective. Is it completely necessary? What functionality will I lose if I don't?

PeteE
09-27-2007, 08:44 PM
According to the documentation (1.8 Hayes Official Install and Upgrade Guide/ FC6), I must modify /etc/passwd and give the apache user a real shell (instead of /sbin/nologin). This seems like a bad thing from a security perspective. Is it completely necessary? What functionality will I lose if I don't?

rsteinberger - the mindtouch.host.exe process needs to run as a user. We've been running it as the apache user ("www-data" on Debian, "apache" on Fedora). If you want to run it as some other user you sure can. You'll just need to make sure it can write to your wiki's /attachment folder as well as to the location of your lucene index.