Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Apache Security
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
nivek98
n00b
n00b


Joined: 27 Jul 2004
Posts: 37

PostPosted: Sat Jul 08, 2006 5:28 am    Post subject: Apache Security Reply with quote

I'm in the process of researching what can be done to beef up Apache's security. Since I am running a Gentoo server, I wanted to get the Gentoo community's opinion on Apache security.

Currently i'm running a simple LAMP(Linux/Apache/MySQL/PHP) setup with not much of a care for security since, until now, I've been the only one using it. Versions of software listed below:

Apache 2.2.2 (I may use the threaded mpm-worker if I can do PHP using FastCGI)
PHP 5.1.4
MySQL 5.0.22

Here are some of the areas I'd like to improve:

1) First off i'd like PHP running as different users for different vhosts. I've seen mod_suphp and am wondering what else is available. Also, how does PHP+FastCGI work with Apache? I'd like to be able to run Apache threaded if possible because loads will be increasing soon and I've got a SMP server.

2) The classic Apache must be able to read everyone's htdocs problem. I find it a pain to make sure that the apache user/group is always able to read the files. I'm wondering if there is some way i can make apache process requests as a certian user per vhost. I've already tried mpm-peruser and it takes some patching to get it to compile, and when tested, still was unable to read the files.

3) I'm also looking at something like mod_chroot. It seems like mod_chroot has it's fair share of problems, what other implementations are available?

4) Any user suggested ways of improving security would be greatly appreciated as well.

-Nivek98
Back to top
View user's profile Send private message
thesheff17
Apprentice
Apprentice


Joined: 12 Jan 2005
Posts: 283

PostPosted: Tue Jul 11, 2006 4:03 pm    Post subject: Reply with quote

Well I don't have any answers to any of your questions. I was seeing though what issues you had with mod_chroot since I currently use it. I'm pretty new to the whole LAMP.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum