Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 10 Mar 2014 13:20:14 +0100
From:      "BONNET, Frank" <frank.bonnet@esiee.fr>
To:        "Steve O'Hara-Smith" <steve@sohara.org>
Cc:        "freebsd-questions@freebsd.org" <freebsd-questions@freebsd.org>
Subject:   Re: ACL questions
Message-ID:  <CA%2B7qukza%2Bo=x7uFkk2zHn0mtFNLcv1y6s8ON-LP7mVOKa5-pmQ@mail.gmail.com>
In-Reply-To: <20140310115929.eb304369181268388c84b851@sohara.org>
References:  <CA%2B7qukxY4XZZr3oWjzpnL%2Bg6taNkbMd7pOHUDegORAmK6RrvgA@mail.gmail.com> <20140310115929.eb304369181268388c84b851@sohara.org>

next in thread | previous in thread | raw e-mail | index | archive | help
Not possible , the user need to have access to all

The other solution is to setup a virtual host for each user , but I have
2500 users
so it will need a really big server to support 2500 vhosts , anyway maybe
has
already done this ?

Thank you



*Frank BONNET*

Systemes UNIX et Reseaux

ESIEE PARIS

01.45.92.66.17 - 06.70.37.37.69


2014-03-10 12:59 GMT+01:00 Steve O'Hara-Smith <steve@sohara.org>:

> On Mon, 10 Mar 2014 12:51:50 +0100
> "BONNET, Frank" <frank.bonnet@esiee.fr> wrote:
>
> > Hello
> >
> > I have ACL question , for internal purpose I need to let some users
> access
> > to their home directory
> > through the WEBDAV protocol with RW access rights.( apache22 )
> >
> > Authentication is done with LDAP and works fine
> >
> > As the webdav processes are owned by the "www" user it cannot access to
> > the user's homedir
> >
> > Is it possible to add an ACL to the users's homedir  to give the www user
> > RW access to the homedir ?
> >
> > I KNOW this is a security risk , this is just a test for now on a small
> > set of users
> >
> > Any other solutions welcome :-)
>
>         Would a www writable subdirectory do instead of giving full access
> to the home directory. It would be simple and safer.
>
> --
> Steve O'Hara-Smith <steve@sohara.org>
>



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CA%2B7qukza%2Bo=x7uFkk2zHn0mtFNLcv1y6s8ON-LP7mVOKa5-pmQ>