#16111 [Com]: IIS/CGI only gives "Security Alert! PHP CGI cannot be accessed directly."
| From: | bcecile at nemak dot com | Date: | Mon, 12 May 2003 16:48:37 +0000 |
| Subject: | #16111 [Com]: IIS/CGI only gives "Security Alert! PHP CGI cannot be accessed directly." | ||
| References: | 1 | Groups: | php.doc |
| Request: | Send a blank email to phpdoc+get-969353392@lists.php.net to get a copy of this message | ||
ID: 16111
Comment by: bcecile at nemak dot com
Reported By: ramac10 at hotmail dot com
Status: Closed
Bug Type: Documentation problem
Operating System: Windows
PHP Version: 4.2.1
New Comment:
I was having the same problem, and the it was related to improper NT
permissions. Please be sure that your IUSR_MACHINENAME has read
permissions to the php.ini file. When I had this file in the c:\winnt
folder, only Administrators and the System accounts had read access.
This was fine while running PHP as an ISAPI module because IIS was
loading the DLL using the System account, but once I switched to a CGI
module, I started having problems. This was because IIS was now
launching the exe file as IUSR_MACHINENAME which is did not have
correct read access to the php.ini file.
Previous Comments:
------------------------------------------------------------------------
[2003-02-16 19:19:26] XpeditionPilot at hotmail dot com
Some of the problems on this page I have fixed by making sure register
gloabal variables is turned on in php.ini. Also an easy fix to the
Security alert is to make sure php.ini has security set to everyone.
Be sure only to change security for that file, not for the winnt or
windows dir. Also make sure cgi.force_redirect is set to 0, as
everyone has said. Good luck.
------------------------------------------------------------------------
[2003-01-20 01:16:36] philip@php.net
This is now documented:
http://cvs.php.net/cvs.php/phpdoc/en/chapters/install.iis.xml
Thanks for the report :)
------------------------------------------------------------------------
[2003-01-19 23:50:43] sniper@php.net
This is still a documentation problem, document that people should
check their php.ini is actually read by PHP.
------------------------------------------------------------------------
[2003-01-18 15:17:01] philip@php.net
This still looks like a problem to me, am marking as a PWS problem
until resolved.
Also it's important to know the correct php.ini is being edited as this
seems to be the cause of many peoples problems. So before reporting
information to this bug report, please be sure to state where phpinfo()
says it is.
If a PWS expert knows this is still a documentation problem, please
reclassify with an explanation.
------------------------------------------------------------------------
[2003-01-16 20:56:50] dspanogle at aol dot com
win 98SE, PWS, PHP4.3.0 installbinary. ME TOO! read everything I can
find - no solution
1. PWS installed and working
2. run install shield for PHP4.3.0 normal install
(also did manual install forcing PWS etc.)
3. build simple hello.php put in root of PWS directories
4. 'Execute' is checked for that folder
5. useing browser - link/get/select hello.php
6. get same BUG. error "Security Alert... (seems PHP is trying!)
7. Changed cgi.force_redirect = 0 in PHP.ini (in c:/windows)
8. bug changed. Now the hello.php script just shows up as html text
i.e. the <?php ...?> is not executed. (seems PHP is not being accessed
or pulled into the game)
9. because symptoms changed PHP IS reading the php.ini file - it is not
in the wrong directory. so all fixes listed so far will not work.
This is definitly a showstopper for many.
I think that setting cgi.force_redirect = 0 is somehow resulting in the
PWS not knowing where to look for the PHP.exe or something like that
but what do I know. A documentation FIX that works would be nice.
Also there seems to be different fixes for IIS and PWS and the docs are
not clear which fix for which.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/16111
--
Edit this bug report at http://bugs.php.net/?id=16111&edit=1