httpd-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Daniel Lopez <>
Subject Re: suexec - false sense of security
Date Thu, 17 Jan 2002 21:59:37 GMT

> It seems to me that there is a far better method of implementing this type
> of security strategy. Is it not possible to have apache drop to the user
> and group specified in the Virtual Hosts directive when performing ANY and
> ALL operations related to that virtual host? I'm amazed it doesn't work
> this way now though I admit I have little understanding of the
> complexities of this issue.

With 1.3, to be able to change the UID for every request, Apache would need to be
running as root and that would be a huge security risk.

> This would solve a multitude of other issues our users have with
> permissions and security. Is there any possible way of implementing this
> now? Does Apache 2.x support this?

Check the perchild MPM documentation


The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:> for more info.
To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message