Re: getting rid of apache passphrase




hello people,

just want to ask if getting rid of the apache passphrase poses a security
threat, i don't want the company i worked for calling me up everytime they
cant access the webserver because the server is asking for the passphrase
everytime the box restarts du to power failure.

Depends on how good your control of access to the server is.
In my case for example, I control physical access to the machine.
That could be, and has been a problem when I was away and power
went out, to get things back up, so I got rid of the passphrase.
Now, as long as the fsck-s clear at boot time, the server makes
it all the way back up without intervention.

But, if you have a lot of people running around, even if ignorant,
then you might want to think again about eliminating it.

It is less likely to be a concern for remote access, but could come
up, especially if someone gets root to your server. Of course, then
all bets are off anyway.

////jerry


TIA
_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"
_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: getting rid of apache passphrase
    ... > just want to ask if getting rid of the apache passphrase poses a ... Depends on how good your control of access to the server is. ... went out, to get things back up, so I got rid of the passphrase. ... But, if you have a lot of people running around, even if ignorant, ...
    (freebsd-questions)
  • E-mail message just wont die
    ... I have an e-mail message that I can't get rid of. ... Everytime I check ... I don't have "Leave messages on server" checked ...
    (microsoft.public.internet.mail)
  • Re: apache
    ... > i have a webserver that needs to run apache with SSL (httpd -SSL, ... > somebody doesn't enter the passphrase by hand... ... > server every time by entering the passphrase by hand is not what i am ... The solution that i opted for was to create a server on a secure network ...
    (FreeBSD-Security)
  • Re: Loop-AES on SuSE 9.1 or Gentoo
    ... > it says, but somehow, everytime I try to recompile ... > even when I get past the boot and into the console, ... > - where invalid and other SuSE said invalid arguments). ... Sounds to me like the -'s are part of your passphrase? ...
    (sci.crypt)
  • Re: PubkeyAuthentication
    ... > I'd like to login from my client to a server without using a password. ... > when I use 'ssh server' it asks me for my passphrase; ... If you've used a passphrase on your key, ...
    (comp.security.ssh)