Bug 714490

Summary: wrong permissions for logdir
Product: [Fedora] Fedora Reporter: Harald Reindl <h.reindl>
Component: httpdAssignee: Joe Orton <jorton>
Status: CLOSED NOTABUG QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 15CC: jorton, pahan
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-07-20 10:56:55 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Harald Reindl 2011-06-19 15:52:53 UTC
please can anybody fix this permissions in the Fedora-SPEC so httpd can create logfiles not only by the root-owned master-process?

current:
%attr(0700,root,root) %dir %{_localstatedir}/log/httpd

fixed:
%attr(0700,apache,root) %dir %{_localstatedir}/log/httpd

Comment 1 Joe Orton 2011-07-20 10:56:55 UTC
No, that is a security feature, the "apache" user should have the minimum possible privileges.

Comment 2 Harald Reindl 2011-07-20 11:27:19 UTC
it is a valid usecase that web-applications are using logfiles for several things and this time they do not run as root, for me /var/log/httpd/ is the correct folder for anything logging httpd-related things