Adam Chlipala <[EMAIL PROTECTED]> wrote:
> Christopher Clausen wrote:
>> You should also create a PTS group and user for the webserver so that
>> users can ACL web stuff to it to allow websites to continue to work.
>> system:anyuser will likely work for most things, but any database
>> passwords and the like should be restricted to the webserver.
>
> I don't think that's necessary.  We don't let members run programs as
> any users but their own, and this includes PHP and CGI scripts.  I've
> just realized that it could be interesting to get Apache suexec to
> work properly with AFS.  Hopefully we'll figure something out!

Note that just changing uid won't change tokens, so this isn't going to 
be easy.

<<CDC 


_______________________________________________
HCoop-SysAdmin mailing list
[email protected]
http://hcoop.net/cgi-bin/mailman/listinfo/hcoop-sysadmin

Reply via email to