httpd-cvs mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From n..@apache.org
Subject svn commit: r487904 - in /httpd/httpd/trunk/docs/manual/programs: htdigest.xml htpasswd.xml
Date Sat, 16 Dec 2006 21:59:14 GMT
Author: niq
Date: Sat Dec 16 13:59:13 2006
New Revision: 487904

URL: http://svn.apache.org/viewvc?view=rev&rev=487904
Log:
PR#40950: add security note to docs (submitted Thijs Kinkhorst)

Modified:
    httpd/httpd/trunk/docs/manual/programs/htdigest.xml
    httpd/httpd/trunk/docs/manual/programs/htpasswd.xml

Modified: httpd/httpd/trunk/docs/manual/programs/htdigest.xml
URL: http://svn.apache.org/viewvc/httpd/httpd/trunk/docs/manual/programs/htdigest.xml?view=diff&rev=487904&r1=487903&r2=487904
==============================================================================
--- httpd/httpd/trunk/docs/manual/programs/htdigest.xml (original)
+++ httpd/httpd/trunk/docs/manual/programs/htdigest.xml Sat Dec 16 13:59:13 2006
@@ -66,4 +66,9 @@
     </dl>
 </section>
 
+<section id="security"><title>Security Considerations</title>
+    <p>This program is not safe as a setuid executable. Do <em>not</em>
make it
+    setuid.</p>
+</section>
+
 </manualpage>

Modified: httpd/httpd/trunk/docs/manual/programs/htpasswd.xml
URL: http://svn.apache.org/viewvc/httpd/httpd/trunk/docs/manual/programs/htpasswd.xml?view=diff&rev=487904&r1=487903&r2=487904
==============================================================================
--- httpd/httpd/trunk/docs/manual/programs/htpasswd.xml (original)
+++ httpd/httpd/trunk/docs/manual/programs/htpasswd.xml Sat Dec 16 13:59:13 2006
@@ -188,6 +188,9 @@
     <em>not</em> be within the Web server's URI space -- that is, they should
     not be fetchable with a browser.</p>
 
+    <p>This program is not safe as a setuid executable. Do <em>not</em>
make it
+    setuid.</p>
+
     <p>The use of the <code>-b</code> option is discouraged, since when
it is
     used the unencrypted password appears on the command line.</p>
 



Mime
View raw message