Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Cherokee: users

Run cherokee as root or normal user ?

 

 

Cherokee users RSS feed   Index | Next | Previous | View Threaded


rarvind at users

Oct 16, 2009, 2:41 PM

Post #1 of 3 (395 views)
Permalink
Run cherokee as root or normal user ?

what is the recommended way to run cherokee ? as root or as an unprivilidged user ?


Arvind


Yahoo! India has a new look. Take a sneak peek http://in.yahoo.com/trynew
_______________________________________________
Cherokee mailing list
Cherokee [at] lists
http://lists.octality.com/listinfo/cherokee


shailesh.zenwalk at gmail

Oct 16, 2009, 8:30 PM

Post #2 of 3 (379 views)
Permalink
Re: Run cherokee as root or normal user ? [In reply to]

I guess the best thing (security wise) i can think of is, to create a group
or user say cherokee and make cherokee webserver to run and this user should
have read per on all the root file system and only write on certain paths
where it has to write some thing like log, settings, etc.

This isolation will not favor the remote hacker in corrupting the filesystem
via a loop hole of cherokee.

Just my 2 cents. I may be wrong.

On Sat, Oct 17, 2009 at 3:11 AM, Arvind Rangan <
rarvind [at] users> wrote:

> what is the recommended way to run cherokee ? as root or as an
> unprivilidged user ?
>
>
> Arvind
>
>
> Yahoo! India has a new look. Take a sneak peek
> http://in.yahoo.com/trynew
> _______________________________________________
> Cherokee mailing list
> Cherokee [at] lists
> http://lists.octality.com/listinfo/cherokee
>



--
----------------------
“Live your life honestly—if you don’t, you always have
to remember to not be yourself”

"Ever tried Zen Computing?"
visit: www.zenwalk.org


alvaro at octality

Oct 17, 2009, 3:27 AM

Post #3 of 3 (366 views)
Permalink
Re: Run cherokee as root or normal user ? [In reply to]

On 16/10/2009, at 23:41, Arvind Rangan wrote:

> what is the recommended way to run cherokee ? as root or as an
> unprivilidged user ?

Unprivileged, no doubt what so ever.

--
Octality
http://www.octality.com/

_______________________________________________
Cherokee mailing list
Cherokee [at] lists
http://lists.octality.com/listinfo/cherokee

Cherokee users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.