Beefy Boxes and Bandwidth Generously Provided by pair Networks
Problems? Is your data what you think it is?
 
PerlMonks  

Re: privilege elevation

by BronzeWing (Monk)
on Jan 21, 2003 at 03:01 UTC ( [id://228564]=note: print w/replies, xml ) Need Help??


in reply to Privilege elevation

Hmm. You said "I don't want to shoehorn all users into the same group and then give the configuration files group priveleges", but perhaps it would be acceptable if you made only the configuration files writable by a certain group, whatever group your CGI is running as (nobody probably). Also I believe you could even sgid that particular CGI into its own group, so that other CGIs wouldn't share its rights to the config files.

I still agree with the first comment as the most secure, but I know users usually hate being forced to "waste their time" doing "silly little things" like copying config files when you could make their lives so much easier by just turning down the security a little...

I guess it depends on what balance you want between security and ease of use. :p

-BronzeWing

Log In?
Username:
Password:

What's my password?
Create A New User
Domain Nodelet?
Node Status?
node history
Node Type: note [id://228564]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this?Last hourOther CB clients
Other Users?
Others lurking in the Monastery: (6)
As of 2024-04-25 14:02 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    No recent polls found