> The Apache log files are still created as root, then. So any user with
> access to httpd.conf can use Apache to e.g. overwrite /etc/passwd.

Wouldn't it be possible to create the log files with the username and group
of the user that Apache is going to be running as before starting it up?
That way they will be owned by a non-root user and the ownership wouldn't
change??

Just my thoughts

Darryl

Reply via email to