8.13. Running CGI Scripts as a Different User with suexec
Problem
You want to have CGI programs executed by some user other than
nobody (or whatever user the Apache
server runs as). For example, you may have a database that is not
accessible to anyone except a particular user, so the server needs to
temporarily assume that user’s identity to access it.
Solution
When building Apache, enable suexec by passing the --enable-suexec argument to configure.
Then, in a virtual host section, specify which user and group you’d like to use to run CGI programs:
User rbowen Group users
Also, suexec will be invoked for any CGI programs run out of username-type URLs for the affected virtual host.
Discussion
The suexec wrapper is a
suid (runs as the user ID of the user that owns the file) program that
allows you to run CGI programs as any user you specify, rather than as
the nobody user that Apache runs
as. suexec is a standard part of
Apache but is not enabled by default.
Tip
The suexec concept does not fit well into the Windows environment, and so suexec is not available under Windows.
When suexec is installed, there are two different ways that it can be invoked, as shown in the Solution.
A User and Group directive may be specified in a VirtualHost container, and all CGI programs executed within the context of that virtual host are executed as that user and group. Note that this only applies to CGI programs. Normal documents and other types of dynamic content are still accessed as the user and group specified ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access