-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

true - owned by apache or world readable!


Smith, Craig A wrote:
>>  in CentOS/Fedora/RHEL your files need to be owned by group apache.
> 
> I don't think so.  Files only need to be READABLE by the apache process.
> Directories also need to be executable so Apache can "cd" into them, for
> example to generate dynamic directory listings (mod_autoindex).
> 
>     # cd <document_root>;  chmod --recursive 755 *
> 
> 
> For directories that contain scripts or CGIs, Redhat recommends
> assigning ownership to root.
> http://www.redhat.com/docs/manuals/linux/RHL-8.0-Manual/security-guide/s
> 1-server-http.html 
> 
> 
> 
> _______________________________________________
> TCLUG Mailing List - Minneapolis/St. Paul, Minnesota
> tclug-list at mn-linux.org
> http://mailman.mn-linux.org/mailman/listinfo/tclug-list

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkn5+W0ACgkQvE9HrEfeE4dpSQCdHBAvpc5N1JvrmJsKIbkWhIdi
fDUAoMhCObjfDYwGmovSvbcNoT0/JEuJ
=gOx7
-----END PGP SIGNATURE-----