PHP Security Tweaks

Mike McGrath mmcgrath at redhat.com
Mon May 26 03:40:50 UTC 2008


On Sun, 25 May 2008, Jeffrey Tadlock wrote:

> On Sat, May 24, 2008 at 10:18 PM, Jeffrey Tadlock <linux at elfshadow.net> wrote:
> > 'open_basedir' is causing issues with the user's page (i.e. clicking
> > the jeffreyt link at the top of the page), when it is enabled it just
> > goes to a blank page.  The same happens with the Infrastructure page
> > as well.  Everything else seemed to work well with it enabled.  I will
> > play with that on a vanilla install at home and see what is up with
> > that.
>
> I think I have this working now.  I needed to add /usr/share/pear to
> the open_basedir list.  The things I saw broken because of that last
> night now appear to be working.  It is now enabled on publictest2.
>

Side note about this, it seems to have broken OpenID support.  I've
reverted to a default configuration so ricky can continue testing.  If
you've got a moment could you hook up with him at some point and find out
exactly what configuration is causing the problem?

	-Mike




More information about the infrastructure mailing list