[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#703121: apache2: Apache2 ignores/overwrites UMASK setting of pam_umask



Package: apache2

I am running a server with a 'UMASK 027' setting in /etc/login.defs and pam_umask enabled. This leads to a default umask of 027 for all shell users. However I also expect the apache2 to run with this umask.

Apache always runs with a umask of 022 causing cgi-scripts to create new files with rather generous permissions. This also implies that there are debian packages which expose private uploads to all users in /tmp/ with default settings. The behavior has been produced with fcgid and mod_php under squeeze and wheezy.


Reply to: