Bug #16287 Updated: SUID for PHP scripts
| From: | alan_k@php.net | Date: | Tue, 26 Mar 2002 14:52:51 +0000 |
| Subject: | Bug #16287 Updated: SUID for PHP scripts | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-3394@lists.php.net to get a copy of this message | ||
ID: 16287
Updated by: alan_k@php.net
Reported By: luci@conexim.com.au
-Status: Open
+Status: Bogus
Bug Type: Feature/Change Request
Operating System: RH7.2
PHP Version: 4.1.2
New Comment:
This is part of Apache &/or the web server responsiblity, doing it in
PHP, would (apart from duplicate resources), be a bit security
headache..
I believe it is a feature of Apache 2.
If you are looking at cgi's, you could consider the php-cgiwrap that is
available on the net somewhere.
Its not really (AFAIK) ever going to be a php feature.
Previous Comments:
------------------------------------------------------------------------
[2002-03-26 09:16:52] luci@conexim.com.au
ooops should've changed the status before...
------------------------------------------------------------------------
[2002-03-26 09:12:48] luci@conexim.com.au
Those functions are very good, except they cannot be used in a hosting
context where the users are not root...
There should be a mechanism like Apache has for .cgi's (per virtual
host or location) or dynamically establishing the owner via the home
directory lookup.
------------------------------------------------------------------------
[2002-03-26 09:08:19] hholzgra@php.net
http://php.net/posix_setuid
------------------------------------------------------------------------
[2002-03-26 09:01:24] derick@php.net
PHP already has functions to swap uids and guids, posix_* (see
www.php.net/posix).
Derick
------------------------------------------------------------------------
[2002-03-26 08:59:44] luci@conexim.com.au
There is a need for suexec/suid type functionality for PHP scripts -
switch of ownership conext in a secure environment. Is this going to
happen?
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=16287&edit=1