Michael Bell wrote:

openca: user root with group root
httpd:  special openca user (this is the owner of the socket and daemon)

i just gave this a try, there are some file-permission problems to keep checked if going this way:

the conf files in etc/servers are only readable by owner and group
this must be changed

and the var/tmp/openca_socket is only writeable by owner (which of course is not the apache-user anymore then ;) - furthermore the var and tmp ist only group readable/executable, this must be changed too and i set the group of the socket to the apache group and gave this group writepermissions to the socket, so the cgis can write to the socket ;)
(i modified openca_rc for this and put some chown and chmod lines into
this, since you have to do this every time the daemon restarts)


i had no time for cvs changes yet and i may be out of office ;)



greetings
dalini


------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click _______________________________________________ OpenCA-Devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/openca-devel

Reply via email to