Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Dec 2002
    Location
    Australia
    Posts
    65

    Default suPHP & php.ini configuration

    I recently made the move to suPHP. I must say, despite my research saying how much security if offers, I am looking back just a little.

    For example, I do not like how a local php.ini file can be used to overwrite settings I'd prefer not overwritable in the main php.ini file. It would also be good to lock certain settings in, like memory_limit. I already have one user using more memory than I'd like them to, although I've added restrictions in my resource monitor to try counter this. *sigh* .

    I also do not like the fact if a local php.ini file is created, all settings within the main php.ini configuration are ignored, even though the local php.ini may not overwrite such settings. I do love that users are bound to their own names, but surely there is a way to configure suPHP or something to include the main php.ini settings in the local php.ini file by default without the user having to copy and paste all the settings in?
    Last edited by Kurieuo; 02-12-2009 at 06:04 AM. Reason: make more clear

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Apr 2008
    Location
    PK
    Posts
    443

    Default

    Quote Originally Posted by Kurieuo View Post
    I recently made the move to suPHP. I must say, despite my research saying how much security if offers, I am looking back just a little.

    For example, I do not like how a local php.ini file can be used to overwrite settings I'd prefer not overwritable in the main php.ini file. It would also be good to lock certain settings in, like memory_limit. I already have one user using more memory than I'd like them to, although I've added restrictions in my resource monitor to try counter this. *sigh* .

    I also do not like the fact if a local php.ini file is created, all settings within the main php.ini configuration are ignored, even though the local php.ini may not overwrite such settings. I do love that users are bound to their own names, but surely there is a way to configure suPHP or something to include the main php.ini settings in the local php.ini file by default without the user having to copy and paste all the settings in?
    Yes, sometimes you do not want users to overwrite the parameters like memory_limit max_execution_time etc. A workaround would be to define a specific php.ini file with your preferred settings and add the following directive to the .htaccess file of the account where you want these settings.

    suPHP_ConfigPath /path/to/folder

    The php.ini file placed in 'folder' will be used. If you do not want users to change these settings, simply chattr the .htaccess file and make it immutable. Not the best solution as it may prevent users from applying redirects.
    Last edited by JawadArshad; 02-12-2009 at 07:39 AM.
    1 solution works for all problems. Trying harder!
    HostMasterTips - Understanding Tech Support

  3. #3
    Member
    Join Date
    Dec 2008
    Posts
    81

    Default

    "For example, I do not like how a local php.ini file can be used to overwrite settings"

    You can lock this when you build apache. Do a Find for ".ini" under Exhaustive options and you'll find the tickbox, can't the exact name.

Similar Threads & Tags
Similar threads

  1. How can I protect php.ini with suPHP?
    By dansgalaxy in forum Security
    Replies: 38
    Last Post: 04-19-2012, 05:45 AM
  2. suphp & php.ini & open_basedir
    By rlshosting in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 03-10-2012, 01:52 PM
  3. suPHP php.ini question
    By lowhigh in forum New User Questions
    Replies: 3
    Last Post: 06-29-2011, 02:31 AM
  4. php.ini / suphp / suhosin
    By gsus in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 06-02-2010, 09:00 AM
  5. How can I protect php.ini with suPHP?
    By dansgalaxy in forum cPanel and WHM Discussions
    Replies: 11
    Last Post: 09-11-2009, 02:00 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube