Re: AW: Run external RewriteMap program as non-root

2015-03-06 Thread Jan Kaluža
On 03/05/2015 02:51 PM, Plüm, Rüdiger, Vodafone Group wrote: -Ursprüngliche Nachricht- Von: Jan Kaluža [mailto:jkal...@redhat.com] Gesendet: Donnerstag, 5. März 2015 14:08 An: dev@httpd.apache.org Betreff: Re: Run external RewriteMap program as non-root On 03/05/2015 12:53 PM, Yann

Re: Run external RewriteMap program as non-root

2015-03-05 Thread Ruediger Pluem
On 03/05/2015 07:55 AM, Jan Kaluža wrote: Hi, currently, the External Rewriting Program (RewriteMap prg:) is run as root. I would like to change it but I see three ways how to do it: 1. Execute it right after drop_privileges hook. This looks like best way, but I haven't found any

AW: Run external RewriteMap program as non-root

2015-03-05 Thread Plüm , Rüdiger , Vodafone Group
-Ursprüngliche Nachricht- Von: Jan Kaluža [mailto:jkal...@redhat.com] Gesendet: Donnerstag, 5. März 2015 14:08 An: dev@httpd.apache.org Betreff: Re: Run external RewriteMap program as non-root On 03/05/2015 12:53 PM, Yann Ylavic wrote: On Thu, Mar 5, 2015 at 12:08 PM, Jan

Re: Run external RewriteMap program as non-root

2015-03-05 Thread Yann Ylavic
On Thu, Mar 5, 2015 at 12:08 PM, Jan Kaluža jkal...@redhat.com wrote: On 03/05/2015 07:55 AM, Jan Kaluža wrote: 3. Execute it where it is now (post_config), but set user/group using apr_procattr_t. So far I think this would duplicate the code of mod_unixd and would probably have to also

Re: Run external RewriteMap program as non-root

2015-03-05 Thread André Malo
* Jan Kaluža wrote: Hi, currently, the External Rewriting Program (RewriteMap prg:) is run as root. I would like to change it but I see three ways how to do it: 1. Execute it right after drop_privileges hook. This looks like best way, but I haven't found any hook which could be used for

Re: Run external RewriteMap program as non-root

2015-03-05 Thread Jan Kaluža
On 03/05/2015 07:55 AM, Jan Kaluža wrote: Hi, currently, the External Rewriting Program (RewriteMap prg:) is run as root. I would like to change it but I see three ways how to do it: 1. Execute it right after drop_privileges hook. This looks like best way, but I haven't found any hook which

Re: Run external RewriteMap program as non-root

2015-03-05 Thread Yann Ylavic
On Thu, Mar 5, 2015 at 10:48 AM, André Malo n...@perlig.de wrote: 5) Let it drop the privileges by itself. I actually tend to 5 :-) +1

Re: Run external RewriteMap program as non-root

2015-03-05 Thread Jan Kaluža
On 03/05/2015 09:54 AM, Jan Kaluža wrote: On 03/05/2015 09:03 AM, Ruediger Pluem wrote: On 03/05/2015 07:55 AM, Jan Kaluža wrote: Hi, currently, the External Rewriting Program (RewriteMap prg:) is run as root. I would like to change it but I see three ways how to do it: 1. Execute it right

Re: Run external RewriteMap program as non-root

2015-03-05 Thread Eric Covener
On Thu, Mar 5, 2015 at 4:48 AM, André Malo n...@perlig.de wrote: 5) Let it drop the privileges by itself. I actually tend to 5 :-) +1 (as a new option as described in a followup) -- Eric Covener cove...@gmail.com

Re: Run external RewriteMap program as non-root

2015-03-05 Thread Jan Kaluža
On 03/05/2015 12:53 PM, Yann Ylavic wrote: On Thu, Mar 5, 2015 at 12:08 PM, Jan Kaluža jkal...@redhat.com wrote: On 03/05/2015 07:55 AM, Jan Kaluža wrote: 3. Execute it where it is now (post_config), but set user/group using apr_procattr_t. So far I think this would duplicate the code of

Run external RewriteMap program as non-root

2015-03-04 Thread Jan Kaluža
Hi, currently, the External Rewriting Program (RewriteMap prg:) is run as root. I would like to change it but I see three ways how to do it: 1. Execute it right after drop_privileges hook. This looks like best way, but I haven't found any hook which could be used for that (except