Bug#703121: apache2: Apache2 ignores/overwrites UMASK setting of pam_umask
Package: apache2
I am running a server with a 'UMASK 027' setting in /etc/login.defs and
pam_umask enabled. This leads to a default umask of 027 for all shell
users. However I also expect the apache2 to run with this umask.
Apache always runs with a umask of 022 causing cgi-scripts to create new
files with rather generous permissions. This also implies that there are
debian packages which expose private uploads to all users in /tmp/ with
default settings. The behavior has been produced with fcgid and mod_php
under squeeze and wheezy.
Reply to: