[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#614813: marked as done (RFP: suexec-conf -- Fully configurable apache suexec binary)



Your message dated Tue, 10 Jul 2018 16:20:31 +0000
with message-id <E1fcvNP-0000XW-Sh@quantz.debian.org>
and subject line closing RFP: suexec-conf -- Fully configurable apache suexec binary
has caused the Debian Bug report #614813,
regarding RFP: suexec-conf -- Fully configurable apache suexec binary
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
614813: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=614813
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: wnpp
Severity: wishlist
Owner: Alexander Gerasiov <gq@debian.org>

* Package name    : suexec-conf
  Version         : 0.0.1
  Upstream Author : Alexander Gerasiov <gq@cs.msu.su>
* URL             : https://github.com/gerasiov/suexec-conf
* License         : Apache
  Programming Lang: C
  Description     : Fully configurable apache suexec binary

Original suexec do some strict checks on start up to provide some security.
This checks are really good, but unfortunately the only way you can configure
it - recompile from sources.

Another problem of original suexec is that is requires that running script
should be owned by the same user suexec setuids to. But there are situation,
when you want different users be able to run shared script (owned by root for
security), or you may want to setup wrapper for some file's types (e.g.
/usr/bin/php-cgi for .php) which is common for all users. In such cases
original suexec will not work, but suexec-conf will do.

suexec-conf is the configurable version of classical suexec from apache.

For now it allows you to configure everything, you could configure for
classic suexec on compile time. And it also support always_allow option where
you could list scripts/command which should be owned by root, but not the user
suexec setuids to.



--- End Message ---
--- Begin Message ---
RFP 614813 has no visible progress for a long time, so closing.

--- End Message ---

Reply to: