Paul de Weerd wrote:
On Tue, Jan 05, 2010 at 06:25:59AM -0600, Chris Bennett wrote:
| I don't use a lot of conf files in conf/modules, but yesterday I
| edited my php.conf and httpd.conf.
| The two changes were tied to each other for a specific change.
| | I just got my insecurity output. It only listed changes to httpd.conf.
| There was nothing about change to php.conf.
| | For a while now, since 4.3 httpd.conf has:
| Include /var/www/conf/modules/*.conf
| | Since all conf files in conf/modules essentially ARE httpd.conf as
| of a restart, why aren't these files tracked also?

You may want to read up on security(8), especially the part that talks
about using mtree...

Cheers,

Paul 'WEiRD' de Weerd

Thanks, I had already added to changelist, but this is better to know (and done now)

--
A human being should be able to change a diaper, plan an invasion,
butcher a hog, conn a ship, design a building, write a sonnet, balance
accounts, build a wall, set a bone, comfort the dying, take orders,
give orders, cooperate, act alone, solve equations, analyze a new
problem, pitch manure, program a computer, cook a tasty meal, fight
efficiently, die gallantly. Specialization is for insects.
  -- Robert Heinlein

Reply via email to