Package: apache2

I am running a server with a 'UMASK 027' setting in /etc/login.defs and pam_umask enabled. This leads to a default umask of 027 for all shell users. However I also expect the apache2 to run with this umask.

Apache always runs with a umask of 022 causing cgi-scripts to create new files with rather generous permissions. This also implies that there are debian packages which expose private uploads to all users in /tmp/ with default settings. The behavior has been produced with fcgid and mod_php under squeeze and wheezy.


--
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]
Archive: http://lists.debian.org/[email protected]

Reply via email to