Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Varnish: Dist

r1482 - trunk/varnish-cache/bin/varnishd

 

 

Varnish dist RSS feed   Index | Next | Previous | View Threaded


des at linpro

May 31, 2007, 6:00 AM

Post #1 of 1 (182 views)
Permalink
r1482 - trunk/varnish-cache/bin/varnishd

des at projects.linpro.no writes:
> Log:
> Add two run-time parameters, "user" and "group", which specify an unprivileged
> user and group to which the child process will switch immediately after fork()
> returns, before it starts accepting connections. The default values are
> "nobody" and "nogroup" (they should probably be tweakable at compile time...)
>
> Note that this does not provide full privilege separation, as there are still
> channels between the parent and child processes which need to be monitored,
> but it is an improvement on the previous situation.

These settings should be documented (and tweakable) in varnish.default
etc. Depending on the distribution, there may be more appropriate
default values for user and group (e.g. "www-data" on Debian)

DES
--
Dag-Erling Sm?rgrav
Senior Software Developer
Linpro AS - www.linpro.no

Varnish dist RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.