From owner-freebsd-questions@FreeBSD.ORG Tue Dec 20 12:40:34 2005 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id CC13516A41F for ; Tue, 20 Dec 2005 12:40:34 +0000 (GMT) (envelope-from msoulier@gmail.com) Received: from nproxy.gmail.com (nproxy.gmail.com [64.233.182.199]) by mx1.FreeBSD.org (Postfix) with ESMTP id C3A0943D5E for ; Tue, 20 Dec 2005 12:40:33 +0000 (GMT) (envelope-from msoulier@gmail.com) Received: by nproxy.gmail.com with SMTP id p48so479633nfa for ; Tue, 20 Dec 2005 04:40:31 -0800 (PST) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:sender:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=c3Wt/+qNr9LCYe0oCm2mtsu2vkr0wHYLn9Cs82nFQ9HMo2gBxvlPFLlPfO3757PoFX9NsuvuzCDK9cpEim+shiDr2pIJZ/HQUoU37M8Wo2sGR5o4iSzvDjmmjqulhwIBVjVNxFkL4R/f/qcU2Ywk71EVV5RjHgjo0tUw4+mNEA0= Received: by 10.49.32.19 with SMTP id k19mr300318nfj; Tue, 20 Dec 2005 04:40:31 -0800 (PST) Received: by 10.48.225.4 with HTTP; Tue, 20 Dec 2005 04:40:30 -0800 (PST) Message-ID: Date: Tue, 20 Dec 2005 07:40:30 -0500 From: "Michael P. Soulier" Sender: msoulier@gmail.com To: "Daniel A." In-Reply-To: <5ceb5d550512191737u23abdac4ya84a6d0c90e4638d@mail.gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline References: <5ceb5d550512191737u23abdac4ya84a6d0c90e4638d@mail.gmail.com> Cc: freebsd-questions@freebsd.org Subject: Re: Fine-tuning access X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Dec 2005 12:40:34 -0000 On 12/19/05, Daniel A. wrote: > I've thought a possible solution for this: > Adding the www user to all my users groups, thus enabling the www user > to read all files chmodded with read permissions for group. > Are there any drawbacks of this solution? > Is there a better solution that I'm not familiar with? That's a common solution. So is forcing them to go through a sysadmin to install their files, and make them owned by www. Considered PHP's security record, you might want to do the latter. Mike -- Michael P. Soulier