24
edits
(Added notes on UID requirements) |
(Added some potential pitfalls.) |
||
| Line 32: | Line 32: | ||
This worked for me. YMMV. | This worked for me. YMMV. | ||
==== Potential Pitfalls ==== | |||
* Webserver may not support set-uid functionality - no way around this except rebuilding the server or using apache as the tbox2 user. | |||
* Potential to steal all mail: Using apache as the owner of the aliases.tbox file means that if apache is ever compromised, then mail can be diverted from all users. | |||
* Potential to steal all mail: Using tbox2 as the owner of the aliases.tbox file means that if Tinderbox2 is ever compromised, then mail can be diverted from all users. | |||
edits