Browse files

Fixed #7616 -- Added advice on unix socket permissions and umasks to …

…fastcgi deployment documentation. Thanks to Malcolm Tredinnick for the report and advice, and PaulM and cramm for reviewing the patch.

git-svn-id: bcc190cf-cafb-0310-a4f2-bffc1f526a37
  • Loading branch information...
1 parent 7f9da79 commit 3739f89b44ab075597f6a43627b4ab8c50563d10 Gabriel Hurley committed Oct 19, 2010
Showing with 8 additions and 0 deletions.
  1. +8 −0 docs/howto/deployment/fastcgi.txt
@@ -110,6 +110,14 @@ Running a threaded server on a TCP port::
Running a preforked server on a Unix domain socket::
./ runfcgi method=prefork socket=/home/user/mysite.sock
+.. admonition:: Socket security
+ Django's default umask requires that the webserver and the Django fastcgi
+ process be run with the same group **and** user. For increased security,
+ you can run them under the same group but as different users. If you do
+ this, you will need to set the umask to 0002 using the ``umask`` argument
+ to ``runfcgi``.
Run without daemonizing (backgrounding) the process (good for debugging)::

0 comments on commit 3739f89

Please sign in to comment.