You are viewing a plain text version of this content. The canonical link for it is here.
Posted to apache-bugdb@apache.org by adam sah <as...@bamboo.com> on 1999/07/16 08:00:52 UTC

documentation/4732: /htdocs/manual/misc/security_tips.html could use structural improvement

>Number:         4732
>Category:       documentation
>Synopsis:       /htdocs/manual/misc/security_tips.html could use structural improvement
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    apache
>State:          open
>Class:          doc-bug
>Submitter-Id:   apache
>Arrival-Date:   Thu Jul 15 23:10:01 PDT 1999
>Last-Modified:
>Originator:     asah@bamboo.com
>Organization:
apache
>Release:        1.3
>Environment:
NT, but that doesn't matter
>Description:
it's unclear which part(s) of the security tips doc apply to a given
   installation-- a bunch of it seems to apply only to ISPs, where
   untrusted users can publish content.

>How-To-Repeat:
n/a
>Fix:
feature request: it would be awesome if the security tips doc were split
   into N categories, one for each common use of Apache, eg:
1. intranet, ie. behind a firewall and where you trust your users.
2. corporate websites, but where users are not allowed to login to the 
   machine, nor publish content.
3. ISP, where users can publish content.

If I was more of an Apache expert, I'd submit them! (sorry)
>Audit-Trail:
>Unformatted:
[In order for any reply to be added to the PR database, you need]
[to include <ap...@Apache.Org> in the Cc line and make sure the]
[subject line starts with the report component and number, with ]
[or without any 'Re:' prefixes (such as "general/1098:" or      ]
["Re: general/1098:").  If the subject doesn't match this       ]
[pattern, your message will be misfiled and ignored.  The       ]
["apbugs" address is not added to the Cc line of messages from  ]
[the database automatically because of the potential for mail   ]
[loops.  If you do not include this Cc, your reply may be ig-   ]
[nored unless you are responding to an explicit request from a  ]
[developer.  Reply only with text; DO NOT SEND ATTACHMENTS!     ]