Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
bugzilla
Project
Project
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Registry
Registry
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
Ivan Ivlev
bugzilla
Commits
5d71f7bc
Commit
5d71f7bc
authored
Apr 25, 2001
by
barnboy%trilobyte.net
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Fix for confusing language regarding protection of data/ & shadow/ directories
and localconfig file.
parent
2d4d7c92
Hide whitespace changes
Inline
Side-by-side
Showing
5 changed files
with
34 additions
and
17 deletions
+34
-17
Bugzilla-Guide.html
docs/html/Bugzilla-Guide.html
+6
-3
security.html
docs/html/security.html
+6
-3
administration.sgml
docs/sgml/administration.sgml
+6
-3
Bugzilla-Guide.txt
docs/txt/Bugzilla-Guide.txt
+10
-5
administration.xml
docs/xml/administration.xml
+6
-3
No files found.
docs/html/Bugzilla-Guide.html
View file @
5d71f7bc
...
...
@@ -5336,11 +5336,14 @@ TARGET="_top"
></LI
><LI
><P
>
Ensure you have adequate access controls for
$BUGZILLA_HOME/data/, $BUGZILLA_HOME/localconfig,
and $BUGZILLA_HOME/shadow directories
.
>
Ensure you have adequate access controls for
the $BUGZILLA_HOME/data/ and
$BUGZILLA_HOME/shadow/ directories, as well as the $BUGZILLA_HOME/localconfig file
.
The localconfig file stores your "bugs" user password,
which would be terrible to have in the hands
of a criminal. Also some files under $BUGZILLA_HOME/data store sensitive information.
of a criminal. Also some files under $BUGZILLA_HOME/data/ store sensitive information, and
$BUGZILLA_HOME/shadow/ stores bug information for faster retrieval. If you fail to secure
these directories and this file, you will expose bug information to those who may not
be allowed to see it.
</P
><P
>
On Apache, you can use .htaccess files to protect access to these directories, as outlined
...
...
docs/html/security.html
View file @
5d71f7bc
...
...
@@ -172,11 +172,14 @@ TARGET="_top"
></LI
><LI
><P
>
Ensure you have adequate access controls for
$BUGZILLA_HOME/data/, $BUGZILLA_HOME/localconfig,
and $BUGZILLA_HOME/shadow directories
.
>
Ensure you have adequate access controls for
the $BUGZILLA_HOME/data/ and
$BUGZILLA_HOME/shadow/ directories, as well as the $BUGZILLA_HOME/localconfig file
.
The localconfig file stores your "bugs" user password,
which would be terrible to have in the hands
of a criminal. Also some files under $BUGZILLA_HOME/data store sensitive information.
of a criminal. Also some files under $BUGZILLA_HOME/data/ store sensitive information, and
$BUGZILLA_HOME/shadow/ stores bug information for faster retrieval. If you fail to secure
these directories and this file, you will expose bug information to those who may not
be allowed to see it.
</P
><P
>
On Apache, you can use .htaccess files to protect access to these directories, as outlined
...
...
docs/sgml/administration.sgml
View file @
5d71f7bc
...
...
@@ -1048,11 +1048,14 @@ operating parameters for bugzilla.</PARA>
</LISTITEM>
<LISTITEM>
<PARA>
Ensure you have adequate access controls for
$BUGZILLA_HOME/data/, $BUGZILLA_HOME/localconfig,
and $BUGZILLA_HOME/shadow directories
.
Ensure you have adequate access controls for
the $BUGZILLA_HOME/data/ and
$BUGZILLA_HOME/shadow/ directories, as well as the $BUGZILLA_HOME/localconfig file
.
The localconfig file stores your "bugs" user password,
which would be terrible to have in the hands
of a criminal. Also some files under $BUGZILLA_HOME/data store sensitive information.
of a criminal. Also some files under $BUGZILLA_HOME/data/ store sensitive information, and
$BUGZILLA_HOME/shadow/ stores bug information for faster retrieval. If you fail to secure
these directories and this file, you will expose bug information to those who may not
be allowed to see it.
</PARA>
<PARA>
On Apache, you can use .htaccess files to protect access to these directories, as outlined
...
...
docs/txt/Bugzilla-Guide.txt
View file @
5d71f7bc
...
...
@@ -1787,11 +1787,16 @@ Chapter 3. Administering Bugzilla
4. Do not run Apache as "nobody". This will require very lax
permissions in your Bugzilla directories. Run it, instead, as a
user with a name, set via your httpd.conf file.
5. Ensure you have adequate access controls for $BUGZILLA_HOME/data/,
$BUGZILLA_HOME/localconfig, and $BUGZILLA_HOME/shadow directories.
The localconfig file stores your "bugs" user password, which would
be terrible to have in the hands of a criminal. Also some files
under $BUGZILLA_HOME/data store sensitive information.
5. Ensure you have adequate access controls for the
$BUGZILLA_HOME/data/ and $BUGZILLA_HOME/shadow/ directories, as
well as the $BUGZILLA_HOME/localconfig file. The localconfig file
stores your "bugs" user password, which would be terrible to have
in the hands of a criminal. Also some files under
$BUGZILLA_HOME/data/ store sensitive information, and
$BUGZILLA_HOME/shadow/ stores bug information for faster
retrieval. If you fail to secure these directories and this file,
you will expose bug information to those who may not be allowed to
see it.
On Apache, you can use .htaccess files to protect access to these
directories, as outlined in Bug 57161 for the localconfig file,
and Bug 65572 for adequate protection in your data/ and shadow/
...
...
docs/xml/administration.xml
View file @
5d71f7bc
...
...
@@ -1048,11 +1048,14 @@ operating parameters for bugzilla.</PARA>
</LISTITEM>
<LISTITEM>
<PARA>
Ensure you have adequate access controls for
$BUGZILLA_HOME/data/, $BUGZILLA_HOME/localconfig,
and $BUGZILLA_HOME/shadow directories
.
Ensure you have adequate access controls for
the $BUGZILLA_HOME/data/ and
$BUGZILLA_HOME/shadow/ directories, as well as the $BUGZILLA_HOME/localconfig file
.
The localconfig file stores your "bugs" user password,
which would be terrible to have in the hands
of a criminal. Also some files under $BUGZILLA_HOME/data store sensitive information.
of a criminal. Also some files under $BUGZILLA_HOME/data/ store sensitive information, and
$BUGZILLA_HOME/shadow/ stores bug information for faster retrieval. If you fail to secure
these directories and this file, you will expose bug information to those who may not
be allowed to see it.
</PARA>
<PARA>
On Apache, you can use .htaccess files to protect access to these directories, as outlined
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment