HowtoForge Forums | HowtoForge - Linux Howtos and Tutorials

HowtoForge Forums | HowtoForge - Linux Howtos and Tutorials (http://www.howtoforge.com/forums/index.php)
-   Installation/Configuration (http://www.howtoforge.com/forums/forumdisplay.php?f=27)
-   -   Permissions for Websites and stats (http://www.howtoforge.com/forums/showthread.php?t=61650)

sheshes 29th April 2013 18:10

Permissions for Websites and stats
 
Guys after various updates of Ubuntu (from 10.04 to 12.10 to 13.04) and latest ISPConfig 3.0.5.2 updates there seems to be some kind of missbehaviour when ISPConfig creates new files and folders.

Firstly, stats created after those days have "root" as owner instead of the webXX:clientXX.

Also I experienced the same thing when running sa-updates for spamassasin. The keys created and a new folder containing the new ruleset was owned by root instead of amavis. Lastly the /etc/spamassassin has debian-spamd as owner which I never created or have used before.

So all these pretty much confuse me, so I ' m seeking for a fix on the above and also I would like to know the correct permissions (chmod) for the folders in each website (/var/www/client/****) so I can check if the permissions are uniformly correct in all my website.

Thanks

till 30th April 2013 08:35

The website permissions are correct, the folders have to be owned by root and not the web user. See release notes, the folder permisoons have been changed in 3.0.5.2 for security reasons.

sheshes 30th April 2013 15:49

All folders in /var/www/ should be owned by root and only /var/www/clients/clientX/ folders to be owned by clientXX:webXX ?

What about the mods of each one?

I cannot find the release notes anywhere, only change logs which don't really say anything about this matter.

Also I get this in my apache error log


[Tue Apr 30 16:45:02 2013] [error] [client 127.0.0.1] client denied by server configuration: /var/www/php-cgi-scripts/
[Tue Apr 30 16:45:02 2013] [error] [client 127.0.0.1] (13)Permission denied: access to /webmail/index.html denied
[Tue Apr 30 16:45:02 2013] [error] [client 127.0.0.1] (13)Permission denied: access to /webmail/index.cgi denied
[Tue Apr 30 16:45:02 2013] [error] [client 127.0.0.1] (13)Permission denied: access to /webmail/index.pl denied
[Tue Apr 30 16:45:02 2013] [error] [client 127.0.0.1] (13)Permission denied: access to /webmail/index.php denied
[Tue Apr 30 16:45:02 2013] [error] [client 127.0.0.1] (13)Permission denied: access to /webmail/index.xhtml denied
[Tue Apr 30 16:45:02 2013] [error] [client 127.0.0.1] (13)Permission denied: access to /webmail/index.htm denied

till 30th April 2013 15:56

Quote:

All folders in /var/www/ should be owned by root and only /var/www/clients/clientX/ folders to be owned by clientXX:webXX ?
No, /var/www/clients/clientX is owneb by root and not clientX:webX

The only folders that are owned by the web user in 3.0.5.2 is the web folder which contains the html and php files:

/var/www/clients/clientX/webX/web

and the cgi-bin folder and the private folder of the site.

Quote:

What about the mods of each one?
Ypou can see that in detail on your own servr. Chnage a vlaue of a webist e.g. quota and click on save, then check out the folder permissions after one minute. The permissions that you see then are the correct permissions of ispconfig 3.0.5.2.

Quote:

Also I get this in my apache error log
Most likely a script that tries to find varius index files. This script does not belong to ispconfig.

sheshes 30th April 2013 23:09

Thanks for the clarifications Till.

Much appreciated.

Thread closed


All times are GMT +2. The time now is 20:01.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2014, vBulletin Solutions, Inc.