Re: PHP6, drop open_basedir?

From: Date: Tue, 17 Jun 2014 09:34:37 +0000
Subject: Re: PHP6, drop open_basedir?
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-74937@lists.php.net to get a copy of this message
2014-06-17 11:30 GMT+02:00 Lester Caine <lester@lsces.co.uk>: > On 17/06/14 09:26, Pierre Joye wrote: > > One of the last reminding so called "security" feature is open_basedir. > > > > On Windows f.e. it is very easy to create application pool with the > > right users/permissions settings (IIS) or only permissions settings > > (Apache). It is not possible to create one user per host on Apache > > using mod_php but I think it is acceptable as it is mostly used as > > development server or dedicated apps. > > > > On linux, fcgi/fpm with linux permissions systems allow pretty much > > the same. And my solutions exist for a per user/application isolation > > system. > > > > I think it is not worth the effort to keep maintaining something that > > will never be as safe as system level permissions. > > > > What do you think about removing it in php 6? Thoughts? > > Managing security on servers that one has full access to is not the main > target of open_basedir? In my experiene it only leads to a false sense of security. I've seen it more than once, that people just set a value there and believed, that they are now safe. On the other hand they wonder, why many things were broken, so they loosen the restrictions again. > It has a useful place when working with shared > hosting? I'd recommend a using VMs, or container instead. > While on-line storage costs are going down, sharing code across > a few sites while maintaining maintaining a level of isolation between > specific content is not easy to achieve in other ways? > Composer? > > The usage I'm seeing is that open_basedir provides access to the site > files and a shared set of resources used across several sites. This is > probably not the best way of doing things but is one documented on > several hosting packages. The examples I could link to require a private > login :( Just a pointer to something that provides an alternative > resolution would obviously be acceptable. With many of these facilities > it's not simply removing something but much more important to provide > education on the alternatives? > > -- > Lester Caine - G8HFL > ----------------------------- > Contact - http://lsces.co.uk/wiki/?page=contact > L.S.Caine Electronic Services - http://lsces.co.uk > EnquirySolve - http://enquirysolve.com/ > Model Engineers Digital Workshop - http://medw.co.uk > Rainbow Digital Media - http://rainbowdigitalmedia.co.uk > > -- > PHP Internals - PHP Runtime Development Mailing List > To unsubscribe, visit: http://www.php.net/unsub.php > > -- github.com/KingCrunch

« previous php.internals (#74937) next »