Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 18 Oct 2001 15:49:58 +0200
From:      Sheldon Hearn <sheldonh@starjuice.net>
To:        Dag-Erling Smorgrav <des@ofug.org>
Cc:        "Andrey A. Chernov" <ache@nagual.pp.ru>, ports@freebsd.org, arch@freebsd.org
Subject:   Re: HEADS UP: Apache port change from nobody:nogroup to www:www planned 
Message-ID:  <30029.1003412998@axl.seasidesoftware.co.za>
In-Reply-To: Your message of "18 Oct 2001 15:25:55 %2B0200." <xzpofn5dqqk.fsf@flood.ping.uio.no> 

next in thread | previous in thread | raw e-mail | index | archive | help


On 18 Oct 2001 15:25:55 +0200, Dag-Erling Smorgrav wrote:

> It should set up and use its own UID, just like QMail and Postfix set
> up and use their own UIDs.  Ideally, there would be a user in our
> standard master.passwd named "smtp" or "mail", with UID 25 (and of
> course a corresponding group).

You don't think there's merit in the availability of a UID who is
guaranteed to own no files and has world-only access to the filesystem
(or a chrooted subtree)?

I would think the sheer number of applications "abusing" nobody for this
purpose would suggest that it's desirable.

Hell, I'd almost go so far as to say we should rename the NIS/NFS UID
65534, and create a new UID called nobody.

Ciao,
Sheldon.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-ports" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?30029.1003412998>