Sponsored Content
Full Discussion: apache user dir
Top Forums UNIX for Dummies Questions & Answers apache user dir Post 6109 by macdonto on Thursday 30th of August 2001 12:47:53 AM
Old 08-30-2001
http://65.12.163.3:5000/
here is the main page.

if i try to go to
http://65.12.163.3:5000/~macdonto/
it gives me an error. I have changed the permissions on my public_html file and the index.html file inside to chmod 755.

todd
 

10 More Discussions You Might Find Interesting

1. UNIX for Dummies Questions & Answers

Modify user home dir

I created a new user and assigned a certain home dir to tis user. I've noticed that this home dir (/export/home/test) is already assigned to other users. I really want to create a dedicated home dir for the new user. Can anyone tell me how I can modify this user with a new homedir? Thx for... (4 Replies)
Discussion started by: kris_devis
4 Replies

2. Shell Programming and Scripting

User dir access using ~ in sh

I am writing code to copy file if user dir exists. Code snippet : #!/bin/sh if then cp ~user1/file file else cp ~user2/file file fi This code works if shell is ksh but not if shell is sh. Can anyone suggest how this can work in sh script? Thanks, Ashish (1 Reply)
Discussion started by: Ashishp
1 Replies

3. Solaris

need to restrict user to his home dir

Hello, i need to create a user who's access is restricted only to his home directory and below, i restricted his pty access by adding 'no-pty' to the options of the ssh key in authorized_keys file. However, sftp access still allows this user access to all my file system thanks (5 Replies)
Discussion started by: lidram
5 Replies

4. UNIX for Advanced & Expert Users

user has access only to one dir

Hello i want to ask how can i let a newly created user to access only one directory and not any other directory at all.: (1 Reply)
Discussion started by: learn82
1 Replies

5. UNIX for Dummies Questions & Answers

Specifying read on dir user?

If I have a number of users all in the same group. How do I give read only access to some of them on everyone elses home directory. Is it possible if they are all in the same group?? So user1,2,3,4 can have read/execute on user1-5 home directory, but user5 can only read only have read... (1 Reply)
Discussion started by: sniff
1 Replies

6. UNIX for Advanced & Expert Users

How to know the user who moved the files to other dir

Hi, I want to know the user ID who moved a file from one directory to another Directory. Example: File1 created by user A is present in dirA then some one has moved it to dirB using "mv" command I want to know the user ID who moved the file to dirB. As far as i know "ls -lrt" command... (1 Reply)
Discussion started by: srilaxmi
1 Replies

7. AIX

Not able to mount user home dir from with automount

Hello there Have anyone configured an AIX 5L machine as NIS client? with homedirectories automounted form an NFS share? The NIS server is running Solaris. I am able to configure the AIX machine as client and user is able to login but I have configured the client to use the automountd... (0 Replies)
Discussion started by: balaji_prk
0 Replies

8. Solaris

how to change /export/home/user dir to /home /user in solaris

Hi all i am using solaris 10, i am creating user with useradd -d/home/user -m -s /bin/sh user user is created with in the following path /export/home/user (auto mount) i need the user to be created like this (/home as default home directory ) useradd -d /home/user -m -s /bin/sh... (2 Replies)
Discussion started by: kalyankalyan
2 Replies

9. UNIX for Dummies Questions & Answers

Switching from root to normal user takes me to user's home dir

Whenever i switch from root to another user, by doing su - user, it takes me to home directory of user. This is very annoying as i want to be in same dir to run different commands as root sometimes and sometimes as normal user. How to fix this? (1 Reply)
Discussion started by: syncmaster
1 Replies

10. AIX

Assign read write permission to the user for specific dir and it's sub dir and files in AIX

I have searched this quite a long time but couldn't find the right method for me to use. I need to assign read write permission to the user for specific directories and it's sub directories and files. I do not want to use ACL. I do not want to assign user the same group of that directories too.... (0 Replies)
Discussion started by: blinkingdan
0 Replies
webadm_selinux(8)					webadm SELinux Policy documentation					 webadm_selinux(8)

NAME
webadm_r - Web administrator role. - Security Enhanced Linux Policy DESCRIPTION
SELinux supports Roles Based Access Control (RBAC), some Linux roles are login roles, while other roles need to be transition into. Note: Examples in this man page will use the staff_u SELinux user. Non login roles are usually used for administrative tasks. For example, tasks that require root privileges. Roles control which types a user can run processes with. Roles often have default types assigned to them. The default type for the webadm_r role is webadm_t. The newrole program to transition directly to this role. newrole -r webadm_r -t webadm_t sudo is the preferred method to do transition from one role to another. You setup sudo to transition to webadm_r by adding a similar line to the /etc/sudoers file. USERNAME ALL=(ALL) ROLE=webadm_r TYPE=webadm_t COMMAND sudo will run COMMAND as staff_u:webadm_r:webadm_t:LEVEL When using a a non login role, you need to setup SELinux so that your SELinux user can reach webadm_r role. Execute the following to see all of the assigned SELinux roles: semanage user -l You need to add webadm_r to the staff_u user. You could setup the staff_u user to be able to use the webadm_r role with a command like: $ semanage user -m -R 'staff_r system_r webadm_r' staff_u BOOLEANS
SELinux policy is customizable based on least access required. webadm policy is extremely flexible and has several booleans that allow you to manipulate the policy and run webadm with the tightest access possible. If you want to determine whether webadm can manage generic user files, you must turn on the webadm_manage_user_files boolean. Disabled by default. setsebool -P webadm_manage_user_files 1 If you want to determine whether webadm can read generic user files, you must turn on the webadm_read_user_files boolean. Disabled by default. setsebool -P webadm_read_user_files 1 If you want to allow users to resolve user passwd entries directly from ldap rather then using a sssd server, you must turn on the authlo- gin_nsswitch_use_ldap boolean. Disabled by default. setsebool -P authlogin_nsswitch_use_ldap 1 If you want to deny user domains applications to map a memory region as both executable and writable, this is dangerous and the executable should be reported in bugzilla, you must turn on the deny_execmem boolean. Enabled by default. setsebool -P deny_execmem 1 If you want to deny any process from ptracing or debugging any other processes, you must turn on the deny_ptrace boolean. Enabled by default. setsebool -P deny_ptrace 1 If you want to allow all domains to use other domains file descriptors, you must turn on the domain_fd_use boolean. Enabled by default. setsebool -P domain_fd_use 1 If you want to allow all domains to have the kernel load modules, you must turn on the domain_kernel_load_modules boolean. Disabled by default. setsebool -P domain_kernel_load_modules 1 If you want to allow all domains to execute in fips_mode, you must turn on the fips_mode boolean. Enabled by default. setsebool -P fips_mode 1 If you want to enable reading of urandom for all domains, you must turn on the global_ssp boolean. Disabled by default. setsebool -P global_ssp 1 If you want to allow confined applications to run with kerberos, you must turn on the kerberos_enabled boolean. Enabled by default. setsebool -P kerberos_enabled 1 If you want to allow logging in and using the system from /dev/console, you must turn on the login_console_enabled boolean. Enabled by default. setsebool -P login_console_enabled 1 If you want to allow system to run with NIS, you must turn on the nis_enabled boolean. Disabled by default. setsebool -P nis_enabled 1 If you want to allow confined applications to use nscd shared memory, you must turn on the nscd_use_shm boolean. Disabled by default. setsebool -P nscd_use_shm 1 If you want to disallow programs, such as newrole, from transitioning to administrative user domains, you must turn on the secure_mode boolean. Enabled by default. setsebool -P secure_mode 1 If you want to allow unconfined executables to make their stack executable. This should never, ever be necessary. Probably indicates a badly coded executable, but could indicate an attack. This executable should be reported in bugzilla, you must turn on the selin- uxuser_execstack boolean. Enabled by default. setsebool -P selinuxuser_execstack 1 If you want to allow ssh logins as sysadm_r:sysadm_t, you must turn on the ssh_sysadm_login boolean. Disabled by default. setsebool -P ssh_sysadm_login 1 If you want to allow the graphical login program to login directly as sysadm_r:sysadm_t, you must turn on the xdm_sysadm_login boolean. Disabled by default. setsebool -P xdm_sysadm_login 1 MANAGED FILES
The SELinux process type webadm_t can manage files labeled with the following file types. The paths listed are the default paths for these file types. Note the processes UID still need to have DAC permissions. httpd_config_t /etc/httpd(/.*)? /etc/nginx(/.*)? /etc/apache(2)?(/.*)? /etc/cherokee(/.*)? /etc/lighttpd(/.*)? /etc/apache-ssl(2)?(/.*)? /var/lib/openshift/.httpd.d(/.*)? /var/lib/stickshift/.httpd.d(/.*)? /etc/vhosts /etc/thttpd.conf httpd_lock_t httpd_log_t /srv/([^/]*/)?www/logs(/.*)? /var/www(/.*)?/logs(/.*)? /var/log/glpi(/.*)? /var/log/cacti(/.*)? /var/log/httpd(/.*)? /var/log/nginx(/.*)? /var/log/apache(2)?(/.*)? /var/log/php-fpm(/.*)? /var/log/cherokee(/.*)? /var/log/lighttpd(/.*)? /var/log/suphp.log.* /var/log/thttpd.log.* /var/log/apache-ssl(2)?(/.*)? /var/log/cgiwrap.log.* /var/www/stickshift/[^/]*/log(/.*)? /var/www/miq/vmdb/log(/.*)? /var/log/roundcubemail(/.*)? /var/log/php_errors.log.* /var/log/dirsrv/admin-serv(/.*)? /var/lib/openshift/.log/httpd(/.*)? /var/www/openshift/console/log(/.*)? /var/www/openshift/broker/httpd/logs(/.*)? /var/www/openshift/console/httpd/logs(/.*)? /etc/httpd/logs httpd_modules_t /usr/lib/httpd(/.*)? /usr/lib/apache(/.*)? /usr/lib/cherokee(/.*)? /usr/lib/lighttpd(/.*)? /usr/lib/apache2/modules(/.*)? /etc/httpd/modules httpd_php_tmp_t httpd_script_exec_type httpd_suexec_tmp_t httpd_tmp_t /var/run/user/apache(/.*)? /var/www/openshift/console/tmp(/.*)? httpd_unit_file_t /usr/lib/systemd/system/httpd.* /usr/lib/systemd/system/jetty.* /usr/lib/systemd/system/nginx.* /usr/lib/systemd/system/php-fpm.* httpd_var_run_t /var/run/mod_.* /var/run/wsgi.* /var/run/httpd.* /var/run/nginx.* /var/run/apache.* /var/run/php-fpm(/.*)? /var/run/lighttpd(/.*)? /var/lib/php/session(/.*)? /var/lib/php/wsdlcache(/.*)? /var/run/dirsrv/admin-serv.* /var/www/openshift/broker/httpd/run(/.*)? /var/www/openshift/console/httpd/run(/.*)? /opt/dirsrv/var/run/dirsrv/dsgw/cookies(/.*)? /var/run/thttpd.pid /var/run/gcache_port /var/run/cherokee.pid httpdcontent public_content_rw_t /var/spool/abrt-upload(/.*)? systemd_passwd_var_run_t /var/run/systemd/ask-password(/.*)? /var/run/systemd/ask-password-block(/.*)? user_home_t /home/[^/]*/.+ user_tmp_t /var/run/user(/.*)? /tmp/hsperfdata_root /var/tmp/hsperfdata_root /tmp/gconfd-.* webadm_tmp_t COMMANDS
semanage fcontext can also be used to manipulate default file context mappings. semanage permissive can also be used to manipulate whether or not a process type is permissive. semanage module can also be used to enable/disable/install/remove policy modules. semanage boolean can also be used to manipulate the booleans system-config-selinux is a GUI tool available to customize SELinux policy settings. AUTHOR
This manual page was auto-generated using sepolicy manpage . SEE ALSO
selinux(8), webadm(8), semanage(8), restorecon(8), chcon(1), sepolicy(8) , setsebool(8) mgrepl@redhat.com webadm webadm_selinux(8)
All times are GMT -4. The time now is 04:03 PM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy