May I recommend you create some unprivileged user (I use the name
"avatar"), then set up sudo to permit user "apache" to run the "at"
command as user "avatar" without a password?  Something like:

	avatar	ALL = NOPASSWD:/usr/bin/at

Then your PHP script could:

	exec("sudo -u innocuoususer at blah-blah");

and the at command would run as "avatar".  You could set "apache" back
to /bin/nologin and be quite a bit safer.
