httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Peter Thomassen <>
Subject Secondary group membership respected?
Date Sat, 19 May 2007 21:27:58 GMT

I'm using mod_vhost and have "VirtualDocumentRoot /var/www/vhost/%0"
configured. The /var/www/vhost/ directory belongs to root:daemon. The
Apache user www-data belongs primarily to www-data, and also to daemon and

I thought that Apache could access the vhost/ directory when its mode is
750, but I found out that it only works with 755, disclosing things to
other users. I therefore think that the secondary groups aren't respected
in a proper way.

What makes me wonder is that this only can be half of the truth: The files
Apache serves belong to the ftpuser group (which is a secondary group of
the Apache user). These files can be accessed by Apache without an error.
Why then doesn't that work for my vhost/ directory?

Thank you,

View raw message