Browse files

[1.2.X] Fixed #7616 -- Added advice on unix socket permissions and um…

…asks to fastcgi deployment documentation. Thanks to Malcolm Tredinnick for the report and advice, and PaulM and cramm for reviewing the patch.

Backport of [14276] from trunk.

git-svn-id: bcc190cf-cafb-0310-a4f2-bffc1f526a37
  • Loading branch information...
1 parent 4ec58f7 commit da17c2b84fda02aa1f1615f04e6d681cea9adcb4 Gabriel Hurley committed Oct 19, 2010
Showing with 8 additions and 0 deletions.
  1. +8 −0 docs/howto/deployment/fastcgi.txt
@@ -111,6 +111,14 @@ Running a threaded server on a TCP port::
Running a preforked server on a Unix domain socket::
./ runfcgi method=prefork socket=/home/user/mysite.sock
+.. admonition:: Socket security
+ Django's default umask requires that the webserver and the Django fastcgi
+ process be run with the same group **and** user. For increased security,
+ you can run them under the same group but as different users. If you do
+ this, you will need to set the umask to 0002 using the ``umask`` argument
+ to ``runfcgi``.
Run without daemonizing (backgrounding) the process (good for debugging)::

0 comments on commit da17c2b

Please sign in to comment.