The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Installing FCGI Securely

Discussion in 'Workarounds and Optimization' started by markb14391, Feb 4, 2011.

  1. markb14391

    markb14391 Well-Known Member

    Joined:
    Jun 9, 2008
    Messages:
    305
    Likes Received:
    2
    Trophy Points:
    18
    We want to move from suphp to FCGI (with SuExec) for various reasons. However, we are concerned by this warning:

    So, how can we modify the configuration to be secure? This seems to be very elusive information. We basically want the same type of security as suphp without the performance hit and the inability to use opcode caches like APC.

    Any help will be appreciated.

    Thanks,

    Mark
     
  2. cPanelTristan

    cPanelTristan Quality Assurance Analyst
    Staff Member

    Joined:
    Oct 2, 2010
    Messages:
    7,623
    Likes Received:
    21
    Trophy Points:
    38
    Location:
    somewhere over the rainbow
    cPanel Access Level:
    Root Administrator
  3. markb14391

    markb14391 Well-Known Member

    Joined:
    Jun 9, 2008
    Messages:
    305
    Likes Received:
    2
    Trophy Points:
    18
    Thank you.

    Does this tutorial accomplish the same thing from a security standpoint?

    Also, I heard that fine-tuning is needed to prevent unused/leftover PHP processes from building up. What do you recommend there?

    And, are those the only two main concerns regarding configuration of FCGI (security and process tuning)?

    Thanks!
     
  4. cPanelTristan

    cPanelTristan Quality Assurance Analyst
    Staff Member

    Joined:
    Oct 2, 2010
    Messages:
    7,623
    Likes Received:
    21
    Trophy Points:
    38
    Location:
    somewhere over the rainbow
    cPanel Access Level:
    Root Administrator
    That tutorial only allows custom php.ini files per account. It isn't setting a wrapper in place of using the binary there for each account.
     
Loading...

Share This Page