LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > External Applications > Ruby/Rails > Should litespeed be rans as root in a shared rails env?

Reply
 
Thread Tools Display Modes
  #1  
Old 07-20-2007, 12:13 PM
nathanc nathanc is offline
Senior Member
 
Join Date: Jun 2007
Posts: 55
Default Should litespeed be rans as root in a shared rails env?

Should litespeed be rans as root in a shared rails env?
Reply With Quote
  #2  
Old 07-20-2007, 01:00 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,585
No, running as root should be avoid whenever possible, too risky. One security flaw will comprise the whole server.
Reply With Quote
  #3  
Old 07-20-2007, 01:07 PM
nathanc nathanc is offline
Senior Member
 
Join Date: Jun 2007
Posts: 55
I agree, however I keep getting this warning

[config:vhost:mysite.private] Uid of /mnt/on/my/share/www.mysite.private/web/rails/public/ is smaller than minimum requirement 11, use server uid!

I cant use server uid like it recommends cause I need it to run the rails app as the docroot owner.
Any recommendations on resolving this warning?

Quote:
Originally Posted by mistwang View Post
No, running as root should be avoid whenever possible, too risky. One security flaw will comprise the whole server.
Reply With Quote
  #4  
Old 07-20-2007, 01:22 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,585
You could make sure the user id of the docroot owner is higher than 11. Never let root user own the docroot directory.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 08:41 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.