<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: start apache without being root in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995768#M423316</link>
    <description>Sorry guys, apparently sudo is not in the policy of my company (!?)&lt;BR /&gt; :-(( &lt;BR /&gt;Any other idea?</description>
    <pubDate>Mon, 07 Aug 2006 12:28:50 GMT</pubDate>
    <dc:creator>Mauro Cossu</dc:creator>
    <dc:date>2006-08-07T12:28:50Z</dc:date>
    <item>
      <title>start apache without being root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995764#M423312</link>
      <description>Hello Gurus&lt;BR /&gt;&lt;BR /&gt;Not sure this is the right place for my query… anyway here it goes:&lt;BR /&gt;&lt;BR /&gt;I have a web application which runs on HP 11.11. Every now and then I need to restart the web server apache. The problem is that I do not have the root password and apache needs to be restarted as root, so I have to log a call to the administrator. He would grant me root access for a while… just the time to restart apache… &lt;BR /&gt;All this has become pretty boring… also because I always have to wait and depend on somebody else … sometime it could take up to a 2 days before restarting apache.&lt;BR /&gt;So my question is: is there a way to start apache without being root? &lt;BR /&gt;&lt;BR /&gt;Thanx for your help&lt;BR /&gt;Mauro&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Aug 2006 09:12:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995764#M423312</guid>
      <dc:creator>Mauro Cossu</dc:creator>
      <dc:date>2006-08-07T09:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: start apache without being root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995765#M423313</link>
      <description>In order to bind to a port number below 1024, the effective user id must be 0 (root) and since you almost certainly want to use the standard port 80 then the rule applies. What your sysadmin could do is setup a sudo command so that you are able to start httpd with an effective uid of 0.&lt;BR /&gt;This is a safe and secure approach and makes much more sense than allowing you root access --- after all, you could do much more than start apache while you are root and do tremendous damage -- intentionally or otherwise. If your admin is not familiar with sudo then refer him to:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://hpux.cs.utah.edu/hppd/hpux/Sysadmin/sudo-1.6.8p9/" target="_blank"&gt;http://hpux.cs.utah.edu/hppd/hpux/Sysadmin/sudo-1.6.8p9/&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Aug 2006 09:18:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995765#M423313</guid>
      <dc:creator>A. Clay Stephenson</dc:creator>
      <dc:date>2006-08-07T09:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: start apache without being root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995766#M423314</link>
      <description>Mauro,&lt;BR /&gt;&lt;BR /&gt;Not that sure about restarting apache without being root, but maybe you can work something out with the sys adms, you can tell them to configure sudo and to give you permissions just to restart apache when you su to the root account.&lt;BR /&gt;&lt;BR /&gt;I am sure you will get plenty of more advice overhere.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Jaime.</description>
      <pubDate>Mon, 07 Aug 2006 09:19:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995766#M423314</guid>
      <dc:creator>Jaime Bolanos Rojas.</dc:creator>
      <dc:date>2006-08-07T09:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: start apache without being root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995767#M423315</link>
      <description>Shalom Mauro,&lt;BR /&gt;&lt;BR /&gt;The process of running apache in a chroot jail is a secure way of accomplishing what you wish.&lt;BR /&gt;&lt;BR /&gt;Any exploits that gain access gain access to no critical mountpoints.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Mon, 07 Aug 2006 09:27:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995767#M423315</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-08-07T09:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: start apache without being root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995768#M423316</link>
      <description>Sorry guys, apparently sudo is not in the policy of my company (!?)&lt;BR /&gt; :-(( &lt;BR /&gt;Any other idea?</description>
      <pubDate>Mon, 07 Aug 2006 12:28:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995768#M423316</guid>
      <dc:creator>Mauro Cossu</dc:creator>
      <dc:date>2006-08-07T12:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: start apache without being root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995769#M423317</link>
      <description>Mauro,&lt;BR /&gt;&lt;BR /&gt;If the sys adm did not want to configure sudo, any other way around might be a violation to their security policies, which they would'nt think it was funny.&lt;BR /&gt;&lt;BR /&gt;Again I am sure somebody can come out with an idea, but that is breaking into the system.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Jaime.</description>
      <pubDate>Mon, 07 Aug 2006 12:35:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995769#M423317</guid>
      <dc:creator>Jaime Bolanos Rojas.</dc:creator>
      <dc:date>2006-08-07T12:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: start apache without being root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995770#M423318</link>
      <description>In that case, create a setuid C program that will start and stop httpd. This is much safer than a setuid shell script BUT it is state-of-the-art stupid to not allow the installation of sudo but at the same time allow you (an otherwise regular user to be logged in as root temporarily). Sudo is a much safer and more secure alternative than your present approach. Sudo could be setup to allow you to only start and stop httpd and nothing else.&lt;BR /&gt;&lt;BR /&gt;I can understand the concern if hpptd is handling many applications and the concern is that you may not be aware of a safe time to bounce the httpd daemon BUT when they log you in as root that problem still exists.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Aug 2006 12:38:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995770#M423318</guid>
      <dc:creator>A. Clay Stephenson</dc:creator>
      <dc:date>2006-08-07T12:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: start apache without being root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995771#M423319</link>
      <description>Plan B. Setup an httpd daemon that binds to a high port (e.g. 9999); this can be started as stopped by a regular user but it will require a port specification for every client connect:&lt;BR /&gt;&lt;BR /&gt;e.g.&lt;BR /&gt;&lt;A href="http://mickey.disney.com:9999" target="_blank"&gt;http://mickey.disney.com:9999&lt;/A&gt;&lt;BR /&gt;rather than simply:&lt;BR /&gt;&lt;A href="http://mickey.disney.com" target="_blank"&gt;http://mickey.disney.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Of course, this will require notification and documentation changes for all users and possibly firewall changes so sudo remain the much better choice.&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Aug 2006 12:46:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995771#M423319</guid>
      <dc:creator>A. Clay Stephenson</dc:creator>
      <dc:date>2006-08-07T12:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: start apache without being root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995772#M423320</link>
      <description>What about providing a login that only gets a restricted shell and putting the needed commands in the rsh.  Doesn't anybody use that anymore?&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Aug 2006 18:12:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995772#M423320</guid>
      <dc:creator>Dan Maschmeier_1</dc:creator>
      <dc:date>2006-08-07T18:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: start apache without being root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995773#M423321</link>
      <description>thanks- very helpful</description>
      <pubDate>Mon, 14 Aug 2006 09:01:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/start-apache-without-being-root/m-p/4995773#M423321</guid>
      <dc:creator>Mauro Cossu</dc:creator>
      <dc:date>2006-08-14T09:01:27Z</dc:date>
    </item>
  </channel>
</rss>

