Hello All,

In reference to the file config.inc.php

For security purposes I would like to lock down this file to 640 do it is not 
world readable.
It has the ldap managers password in it as plain text.
Should someone break into the internal network , they would be able to 
manipulate ldap with the manager password any way they see fit.
When I change  the file to 640 I get a blank page from Apache with the flowing 
error:
It does work when the file is 644.

[Sun Sep 06 09:29:25 2015] [error] [client 10.152.83.97] PHP Warning:  
require_once(/opt/ltb-project-self-service-password-0.8/conf/config.inc.php): 
failed to open stream: Permission denied in 
/opt/ltb-project-self-service-password-0.8/index.php on line 23, referer: 
https://10.153.111.239/cas/login?service=https%3a%2f%2f10.153.111.239%2fmain.php
[Sun Sep 06 09:29:25 2015] [error] [client 10.152.83.97] PHP Fatal error:  
require_once(): Failed opening required 'conf/config.inc.php' 
(include_path='.:/usr/share/pear:/usr/share/php') in 
/opt/ltb-project-self-service-password-0.8/index.php on line 23, referer: 
https://10.153.111.239/cas/login?service=https%3a%2f%2f10.153.111.239%2fmain.php


Any suggestions would be helpful.


Thank You;

Chris Cheltenham
[email protected]<mailto:[email protected]>
SwainTechs
10 Walnut Grove Rd
Suite 110
Horsham, PA
19044

888-905-5767 / X407


_______________________________________________
ltb-users mailing list
[email protected]
http://lists.ltb-project.org/listinfo/ltb-users

Reply via email to