upcp is changing httpd.conf to 600 this break many fantastico installation

BianchiDude

Well-Known Member
PartnerNOC
Jul 2, 2005
617
0
166
upcp is changing httpd.conf to 600 this break many fantastico installation

Why is upcp changing httpd.conf to 600?

I have custom scripts that need to access it, i need it to stay 644, also fantastico needs it to be 644.

Is anyone else having this problem? How can I prevent upcp form chaning it?
 

kosmo

Well-Known Member
Verifed Vendor
Aug 12, 2001
400
0
316
All over Europe
The latest Fantastico version 2.8.8 r10 doesn't need any more access to httpd.conf.

kosmo
 

kosmo

Well-Known Member
Verifed Vendor
Aug 12, 2001
400
0
316
All over Europe
BianchiDude said:
My custom scripts still need access to it.
I suggest to open a bugzilla ticket requesting to make it a WHM Tweak Settings option. This would make sense, in particular for individuals with a few trusted accounts on a server.

kosmo
 

cPanelNick

Administrator
Staff member
Mar 9, 2015
3,481
35
208
cPanel Access Level
DataCenter Provider
BianchiDude said:
upcp is changing httpd.conf to 600 this break many fantastico installation

Why is upcp changing httpd.conf to 600?

I have custom scripts that need to access it, i need it to stay 644, also fantastico needs it to be 644.

Is anyone else having this problem? How can I prevent upcp form chaning it?

Why do you need to read httpd.conf?

Sadly, in general

Security = 1/Convience

another way of saying that

security is inversely proportional to convenience
 

BianchiDude

Well-Known Member
PartnerNOC
Jul 2, 2005
617
0
166
What security issues? What is in httpd.conf that will give me access to the server?
 

silversurfer

Well-Known Member
Dec 29, 2002
274
0
168
We have clients complaining today of this error in Cpanel :

[an error occurred while processing this directive] Dedicated Ip Address
[an error occurred while processing this directive]
[an error occurred while processing this directive]

etc. Changing it to 644 fix it.

This is on c131.
 

silversurfer

Well-Known Member
Dec 29, 2002
274
0
168
Well the number of issues needing an update to edge to fix this 2 days is just too much... oh well.
 

BianchiDude

Well-Known Member
PartnerNOC
Jul 2, 2005
617
0
166
PWSowner said:
Account usernames for starters. Lots of general data.
WHAT? like at hacker is going to check httpd.conf for usernames when /etc/passwd is world readable. Does anyone know of an actual security issue?
 

chirpy

Well-Known Member
Verifed Vendor
Jun 15, 2002
13,437
33
473
Go on, have a guess
It is a serious security issue having access to httpd.conf because of the information that it contains. Security is about layers and preventing access to one file helps build up that security. Users should not have general access to httpd.conf and it's excellent that cPanel have developed a way to block that. It's unfortunate that it's broken something for you, but you'll simply have to work around the issue as it's not going to go away.
 

BianchiDude

Well-Known Member
PartnerNOC
Jul 2, 2005
617
0
166
chirpy said:
It is a serious security issue having access to httpd.conf because of the information that it contains. Security is about layers and preventing access to one file helps build up that security. Users should not have general access to httpd.conf and it's excellent that cPanel have developed a way to block that. It's unfortunate that it's broken something for you, but you'll simply have to work around the issue as it's not going to go away.
Ok, thanks for the info, ill just create a sudo command to cat it.
 

techark

Well-Known Member
May 22, 2002
277
0
316
Does more than breaks Fantastico it also means users cannot manage addon or parked domains from cpanel any longer. They just get the cannot read httpd.conf premission errors when they try.

This is silly.
 

techark

Well-Known Member
May 22, 2002
277
0
316
cpanelnick said:
Why do you need to read httpd.conf?

Sadly, in general

Security = 1/Convience

another way of saying that

security is inversely proportional to convenience
Well I do not but your own software does. Cannot manage addon or parked doamins via cpanel anylonger. At least test your changes before you go off changing things and making a statement like that.
 

haze

Well-Known Member
Dec 21, 2001
1,540
3
318
techark said:
Well I do not but your own software does. Cannot manage addon or parked doamins via cpanel anylonger. At least test your changes before you go off changing things and making a statement like that.
You have made a decision to use the Edge release, thus you have taken the choice to use a NON STABLE TESTING RELEASE! You report bugs, cPanel fixes them and eventually releases a Current > Release then Stable build. You need to expect that such issues will arise when you make a decision to use Edge on production systems.

You can not fault cPanel for your own ignorance, and you can not fault them for improving security. They have workarounds, and they have a proper means of reporting such issues ( bugzilla.cpanel.net ). Also, contact the vendor of any 3rd party software that doesn't work as that is far from cPanels responsibility.