LDB wrote:
Boyle Owen wrote:
-----Original Message-----
From: LDB [mailto:[EMAIL PROTECTED]
It works like the following,
DocumentRoot "/srv/www/mediawiki"
<Directory "/srv/www">
Options FollowSymLinks
</Directory>
This is the only directive you need in this directory container.
All the others (especially the "Allow from all") should be in a more
specific container that applies to the doc root, eg:
<Directory "/srv/www/mediawiki">
AllowOverride None
Order allow,deny
Allow from all
</Directory>
But what are the security ramifications of doing it this way that you
recognize?
Never "Allow from" for a directory *above* your docroot or you allow
URLs like http://server/../path to work!
Rgds,
Owen Boyle
Disclaimer: Any disclaimer attached to this message may be ignored.
Thanks,
LDB
---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server
Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: [EMAIL PROTECTED]
" from the digest: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]
This message is for the named person's use only. It may contain
confidential, proprietary or legally privileged information. No
confidentiality or privilege is waived or lost by any mistransmission.
If you receive this message in error, please notify the sender
urgently and then immediately delete the message and any copies of it
from your system. Please also immediately destroy any hardcopies of
the message. You must not, directly or indirectly, use, disclose,
distribute, print, or copy any part of this message if you are not the
intended recipient. The sender's company reserves the right to monitor
all e-mail communications through their networks. Any views expressed
in this message are those of the individual sender, except where the
message states otherwise and the sender is authorised to state them to
be the views of the sender's company.
---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server
Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: [EMAIL PROTECTED]
" from the digest: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]
Thank you much Boyle ... So now I have ...
DocumentRoot "/srv/www/mediawiki"
#
# Configure the DocumentRoot
#
<Directory "/srv/www">
Options FollowSymLinks
</Directory>
#
#<Directory "/srv/www/htdocs">
<Directory "/srv/www/mediawiki">
# Possible values for the Options directive are "None", "All",
# or any combination of:
# Indexes Includes FollowSymLinks SymLinksifOwnerMatch ExecCGI
MultiViews
#
# Note that "MultiViews" must be named *explicitly* --- "Options
All"
# doesn't give it to you.
#
# The Options directive is both complicated and important.
Please see
# http://httpd.apache.org/docs-2.2/mod/core.html#options
# for more information.
Options FollowSymLinks
# AllowOverride controls what directives may be placed in
.htaccess files.
# It can be "All", "None", or any combination of the keywords:
# Options FileInfo AuthConfig Limit
AllowOverride None
# Controls who can get stuff from this server.
Order allow,deny
Allow from all
</Directory>
Is this correct? Thank you again Boyle,
LDB
---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: [EMAIL PROTECTED]
" from the digest: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]
I guess I am more worried about SECURE than correct .. Thanks ..
LDB
---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: [EMAIL PROTECTED]
" from the digest: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]