Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 22nd November 2006, 05:17 PM
lvona Offline
Registered User
 
Join Date: Jul 2006
Posts: 10
Question How to set context allowing user to modify /var/www

I tried posting this to the selinux mailing-list, but it never showed up, so here we go.

I have been struggling with the following problem for ages. I simply want to allow ftp/sftp remote access to the /var/www/html folder on my FC5 linux box. I have a user -- webmaster -- with /var/www as his home dir. I have made webmaster a member of the apache group, and apache:apache is the ownership on /var/www and subdirs.



What commands (semanage, newrole, etc.) do I need to run to allow webmaster (context: user_u:system_r:unconfined_t) to make changes to /var/www and it's subdirs? (context: system_u:object_r:httpd_sys_content_t)
Reply With Quote
  #2  
Old 22nd November 2006, 09:10 PM
SlowJet Offline
Registered User
 
Join Date: Jan 2005
Posts: 5,002
I goofed up my replies to that list to becuase I haven't been on a list for while.

I think it is about reply-all vs. reply?

Anyway, try again because
1. No one here is going to know that much detail about your SELinux questions and
2. I think there may be a beter way of doing what you what to do.

SJ
__________________
Do the Math
Reply With Quote
  #3  
Old 23rd November 2006, 12:09 AM
lvona Offline
Registered User
 
Join Date: Jul 2006
Posts: 10
Talking Thanks

Thanks, SJ.

I tried posting twice, though already. Postfix tells me I'm getting greylisted, to which I take no offense , but after the reported 30 min ban, my post still doesn't show up.

If you can imagine another way of doing things, could you give me a lead? Just off the top of the head. I'm pretty self-sufficient with this kind of stuff, but this one has me stumped.

But, I refuse to turn off SELINUX. It's so powerful, and I am devoted to adoption.

I really want to get the PRODUCTION WEB SERVER I'm running off the XP WORKSTATION it's running on, (a workstation still in use, BTW ) and onto something a little more secure and easy to monitor. But, if I can't provide sftp to the live dirs, developers can't post content without me copying it from their home dirs manually.

I don't like waking up at 5AM to post content. All 'sudo cp' and no sleep makes Jack kill EVERYONE.
Reply With Quote
  #4  
Old 23rd November 2006, 06:40 AM
stanjam Offline
Registered User
 
Join Date: Oct 2006
Posts: 133
I would have your webmaster scp files into your linux box in a seperate folder. This folder becomes essentially a test box for your web site (always a good idea before going live). You can then test the files locally with your web browser and transfer them to the var/www folder as root and set up the permissions you need for the public to have access.
Reply With Quote
  #5  
Old 24th November 2006, 07:44 AM
SlowJet Offline
Registered User
 
Join Date: Jan 2005
Posts: 5,002
I nominate stanjam to write a How-TO for web and ftp content providers to a FC SElinux enabled Linux box.

Do I here a second? Ivona?

SJ
__________________
Do the Math
Reply With Quote
Reply

Tags
allowing, context, modify, or var or www, set, user

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
allowing ssh,and rsh anass.emmacs Servers & Networking 0 4th May 2007 12:19 PM
Allowing user access of shutdown command Hououtate Using Fedora 3 4th April 2006 12:08 AM
Allowing SFTP without allowing SSH grim76 Security and Privacy 3 26th October 2005 02:18 PM
Allowing users to write/modify files in mounted filesystems? veraction Using Fedora 11 14th November 2004 11:23 PM


Current GMT-time: 14:51 (Friday, 24-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat