[imp] IMP 2.2.x RPMs for Red Hat 7 available

Brent J. Nordquist bjn@horde.org
Thu, 8 Feb 2001 11:45:11 -0600 (CST)


On Thu, 8 Feb 2001, Christopher Kalos <ckalos@gothambroadband.com> wrote:

> Mike:  You didn't give me a chance to look at test.php3.  It was set
> to 000 (by default???)

Yes, that's intentional (for security reasons); secure.sh does that for
all Horde/IMP sites (that isn't an RPM thing).  You can a+r it to test,
and a-r it when you're done.

> Directory permissions on ./config and ./imp/config were 640.  Change that to
> 644, and Setup functions.

You're sure you meant 640, and not 750 (drwxr-xr-x)?  The directories are
supposed to be user root, group apache, and permission 750.  Again, that's
intentional for all Horde/IMP sites (see docs/SECURITY) -- that keeps
local users on the server from snooping your passwords.  Group apache
allows the httpd to read the config. files, and owner root
(non-group-writable) makes sure that a httpd security hole doesn't allow
someone to overwrite the config. files with other values.

> Aside from those three permission issues, everything looks clean now.

If you really mean 640 then something is trés weird... starting with a
clean tree (the directories /var/www/horde-phplib and /var/www/html/horde
do not exist), I've verified that the permissions for everything are as
they should be.

Glad it's working for you, though.  :-)

-- 
Brent J. Nordquist <bjn@horde.org>
Yahoo!: Brent_Nordquist / AIM: BrentJNordquist / ICQ: 76158942