Re: PHP6, drop open_basedir?
| From: | Sebastian Krebs | Date: | Tue, 17 Jun 2014 09:34:37 +0000 |
| Subject: | Re: PHP6, drop open_basedir? | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-74937@lists.php.net to get a copy of this message | ||
2014-06-17 11:30 GMT+02:00 Lester Caine <lester@lsces.co.uk>:
> On 17/06/14 09:26, Pierre Joye wrote:
> > One of the last reminding so called "security" feature is open_basedir.
> >
> > On Windows f.e. it is very easy to create application pool with the
> > right users/permissions settings (IIS) or only permissions settings
> > (Apache). It is not possible to create one user per host on Apache
> > using mod_php but I think it is acceptable as it is mostly used as
> > development server or dedicated apps.
> >
> > On linux, fcgi/fpm with linux permissions systems allow pretty much
> > the same. And my solutions exist for a per user/application isolation
> > system.
> >
> > I think it is not worth the effort to keep maintaining something that
> > will never be as safe as system level permissions.
> >
> > What do you think about removing it in php 6? Thoughts?
>
> Managing security on servers that one has full access to is not the main
> target of open_basedir?
In my experiene it only leads to a false sense of security. I've seen it
more than once, that people just set a value there and believed, that they
are now safe. On the other hand they wonder, why many things were broken,
so they loosen the restrictions again.
> It has a useful place when working with shared
> hosting?
I'd recommend a using VMs, or container instead.
> While on-line storage costs are going down, sharing code across
> a few sites while maintaining maintaining a level of isolation between
> specific content is not easy to achieve in other ways?
>
Composer?
>
> The usage I'm seeing is that open_basedir provides access to the site
> files and a shared set of resources used across several sites. This is
> probably not the best way of doing things but is one documented on
> several hosting packages. The examples I could link to require a private
> login :( Just a pointer to something that provides an alternative
> resolution would obviously be acceptable. With many of these facilities
> it's not simply removing something but much more important to provide
> education on the alternatives?
>
> --
> Lester Caine - G8HFL
> -----------------------------
> Contact - http://lsces.co.uk/wiki/?page=contact
> L.S.Caine Electronic Services - http://lsces.co.uk
> EnquirySolve - http://enquirysolve.com/
> Model Engineers Digital Workshop - http://medw.co.uk
> Rainbow Digital Media - http://rainbowdigitalmedia.co.uk
>
> --
> PHP Internals - PHP Runtime Development Mailing List
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
--
github.com/KingCrunch