We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 32829
    • 108 Posts
    Can some kind person point me to where I might find correct chmod settings for Revo.

    I’m using a Linux-based VPS running CentOS 5.

    It also seems I need to set the /modx/core/cache directory to chmod = 777

    I thought 777 was bad security?

    Can someone more knowledgable comment?

    There are other directories/files that I needed to chmod to 777 (755 resulted in a handful of errors).

    Thanks.

    As a side note, files/directories saved via *.tar.gz are able to preserve chmod settings .. no?

    So it would be nice to see a *.tar.gz alongside the zip on the downloads page.
      Radified, VPS guide, Revo 206 Traditional, PHP 534, suPHP, MySQL 5151, Apache 2217, CentOS 5.5 on Virtuozzo VPS.
      • 22303 MODX Staff
      • 10,725 Posts
      Quote from: xeeter at Dec 30, 2009, 05:42 PM

      Can some kind person point me to where I might find correct chmod settings for Revo.

      I’m using a Linux-based VPS running CentOS 5.

      It also seems I need to set the /modx/core/cache directory to chmod = 777

      I thought 777 was bad security?

      Can someone more knowledgable comment?

      There are other directories/files that I needed to chmod to 777 (755 resulted in a handful of errors).

      Thanks.

      As a side note, files/directories saved via *.tar.gz are able to preserve chmod settings .. no?

      So it would be nice to see a *.tar.gz alongside the zip on the downloads page.
      This completely depends on your environment and how the web server is configured to execute PHP. If PHP executes as your shell account, then 755 for directories should be fine. If PHP executes as your web server user account, you can chgrp the directories that need to be writable to the web server user account and use 775. The only reason you would ever need to use 777 is if you could not chgrp the directories that need to be writable; in that case you have to make them world writable (777) in order to allow the PHP process to write to them.
        • 32829
        • 108 Posts
        you can chgrp the directories that need to be writable
        I am trying to find a list of the directories & files that need to be writable. Where might that info be located?
          Radified, VPS guide, Revo 206 Traditional, PHP 534, suPHP, MySQL 5151, Apache 2217, CentOS 5.5 on Virtuozzo VPS.
          • 3749
          • 24,544 Posts
          Quote from: xeeter at Dec 30, 2009, 09:47 PM

          you can chgrp the directories that need to be writable
          I am trying to find a list of the directories & files that need to be writable. Where might that info be located?

          http://svn.modxcms.com/docs/display/revolution/Fresh+Installation smiley
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 32829
            • 108 Posts
            Thanks.

            Now we’re cooking with plutonium.
              Radified, VPS guide, Revo 206 Traditional, PHP 534, suPHP, MySQL 5151, Apache 2217, CentOS 5.5 on Virtuozzo VPS.
              • 32829
              • 108 Posts
              This completely depends on your environment and how the web server is configured to execute PHP. If PHP executes as your shell account, then 755 for directories should be fine. If PHP executes as your web server user account, you can chgrp the directories that need to be writable to the web server user account and use 775. The only reason you would ever need to use 777 is if you could not chgrp the directories that need to be writable; in that case you have to make them world writable (777) in order to allow the PHP process to write to them.

              From my web hosting provider:

              A more accurate way to describe this would be to refer to the PHP handler used on your server. If your handler is suPHP, then all PHP scripts will be executed as the owner of that PHP script, so for example, radified.com’s PHP would be run as user.

              If you use DSO/CGI PHP handler (current setting on host.radified.com), then all PHP scripts are executed as the web server’s user (nobody), so if a script needs to write to a file on your server, this file would need to have less restrictive permissions or its ownership would need to be changed to nobody.

              I advise against changing the ownership though, as this will interfere with cPanel’s ability to back up your files.

              Comment? I am not groking exactly what he’s saying.
                Radified, VPS guide, Revo 206 Traditional, PHP 534, suPHP, MySQL 5151, Apache 2217, CentOS 5.5 on Virtuozzo VPS.
                • 32829
                • 108 Posts
                Okay, thanks. This helped a lot. I’m starting to get somewhere.
                  Radified, VPS guide, Revo 206 Traditional, PHP 534, suPHP, MySQL 5151, Apache 2217, CentOS 5.5 on Virtuozzo VPS.
                  • 32699 ☆ A M B ☆
                  • 427 Posts
                  You may find it easier in the long run to simply use the suPHP, if it is available.
                    Get your copy of MODX Revolution Building the Web Your Way http://www.sanitypress.com/books/modx-revolution-building-the-web-your-way.html

                    Check out my MODX || xPDO resources here: http://www.shawnwilkerson.com
                    • 10702
                    • 107 Posts
                    On our server MODx is only running when CHMOD of the Core/Cache-folder and the corresponding subfolders are set to 777 (while all the files included in these folders are set to 644). 774 and 775 doesn´t work for Core/Cache-folder.

                    Is this 777-configuration for the Cache-folder really safe? In my understanding everybody from public can write in these folders and execute the files.

                    Does anybody know this?

                    Thanks a lot in advance!
                    Gerdi smiley

                      • 22303 MODX Staff
                      • 10,725 Posts
                      Just make the group owner your web server user and give the group write permissions (i.e. 775, or 664 for files); you do not have to give world-writable permissions if you can control group ownership of the files on your server. Please note you should never set files to 777 or 775, only folders; files should generally be 666 or 664. Even better you can control permissions symbolically on most systems, e.g. to give the group write permissions you would use chmod g+w and so on...