We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 3749
    • 24,544 Posts
    Interesting story. I was aware of that link, but it doesn't really give me the information I need to make a decision about which distribution to use for upgrading.

    I did use the Advanced distribution once to upgrade a hardened Traditional install. It appeared to work, but the site version displayed in the Manager didn't change, and I don't know what else didn't happen. I need more information about what those two distributions (especially the Advanced one) actually *do* during setup.

    Considering that we strongly recommend moving the core out of the site root and renaming the manager folder, there really should be more detailed information about how to upgrade once you do that. Upgrading a hardened site should also be much easier than it is now.
      Did I help you? Buy me a beer
      Get my Book: MODX:The Official Guide
      MODX info for everyone: http://bobsguides.com/modx.html
      My MODX Extras
      Bob's Guides is now hosted at A2 MODX Hosting
      • 38237
      • 83 Posts
      You are putting your finger in the wound with regards to MODX documentation laugh when i started with modx there was no documentation, nothing like your blog, it was only the official ones which are vague. From my experience the only difference is the options which it gives you during the setup process, in addition to the smaller size due to the fact of having some contents zipped.

      I personally do not prefer things to be made easier for me smiley, so i go with traditional then manual hardening. I guess you are either seeking a response from the dev who wrote the code OR you should read the installation script which is simple enough specially for you wink

      I recommend you to upgrade using the same kind of package you used for installation. I'll be working on an AutoUpgrade extra soon which should respect hardening, just hope i will not have a hard week (Or you can start it and i join later tongue ).
        • 36816
        • 109 Posts
        Greetings Bob,

        Quote from: BobRay at Aug 29, 2014, 03:26 PM
        Considering that we strongly recommend moving the core out of the site root and renaming the manager folder, there really should be more detailed information about how to upgrade once you do that. Upgrading a hardened site should also be much easier than it is now.

        It may or may not add help, but in case it does... Each and every Revo install I've done, I've used Advanced, and moved core outside of document root, although I've not yet changed the name of manager or connectors directories.

        In my use case, upgrades have been without problem as follows:

        Update add-ons. Flush Sessions. Logout of manager. Manually clear cache.
        Upload advanced distribution to server
        Extract to a temporary directory
        Using host's cpanel file manager, move setup directory to document root
        Using host's cpanel file manager, move core directory to the location where it's previously been installed outside document root (merging new/old)
        Run setup -- tell setup where to find the core; it asks when it can't find it inside document root
        


        Of course, having different names for manager and connectors may well change the game in its entirety, but I thought I'd at least share my experience with moving the core -- it's been flawless on upgrade.

          • 3749
          • 24,544 Posts
          Good info, thanks. The question is whether that would also work to upgrade a hardened *Traditional* install (which is the distribution we're recommending for most people). It seems like it would, but I'm sure many people (including me) would be hesitant to try it on an important production site.

          Imo, renaming the manager is as important as moving the core (if not more so), since the manager has to be available via URL. Its existence is a surefire indication of a MODX site, and any security flaw in the manager would be instantly exploitable if it's not renamed. So whether your method would work on a site with a renamed manager folder is also critical.
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 36816
            • 109 Posts
            Quote from: clareoconsulting at Aug 29, 2014, 03:45 PM
            Of course, having different names for manager and connectors may well change the game in its entirety, but I thought I'd at least share my experience with moving the core -- it's been flawless on upgrade.

            Well... I had a little time free, so did a fresh install of 2.2.14-Advanced, moving core outside document root, and renaming both manager and connectors directories using those options within setup. No extras or content, just a "hello world" home page.

            Ran an upgrade to 2.2.15-Advanced as described in my previous post. It ran without error. Timestamps in the renamed manager and connectors matched the time of the upgrade, so it seems that setup successfully found those directories.

            Upgraded that -- same technique -- to 2.3.1. Had the same duplicate key warning Susan mentioned, but I think that's a red herring. No other issues, and the time stamps in the renamed manager & connectors directories changed again to the time of running setup.

            Mileage may vary on a site with content, extras, etc., but on upgrade of fresh Advanced installs, all went pretty well.

              • 36816
              • 109 Posts
              Quote from: BobRay at Aug 29, 2014, 04:06 PM
              The question is whether that would also work to upgrade a hardened *Traditional* install

              I was trying the upgrade using Advanced and renamed connectors / manager as you wrote. Time permitting later, I'll try the same thing with Traditional.

              Quote from: BobRay at Aug 29, 2014, 04:06 PM
              It seems like it would, but I'm sure many people (including me) would be hesitant to try it on an important production site.

              I share your sentiment. I've had more than a few installs (Modx and other things), where I re-install the un-upgraded production site to a staging subdomain, and do a test upgrade there before subjecting the production site to the upgrade process.

              Quote from: BobRay at Aug 29, 2014, 04:06 PM
              Its existence is a surefire indication of a MODX site

              That generates curiosity if other Modx fingerprints are successfully being found by miscreants, reducing the success of fingerprint reduction by manager rename. You know what they say about "security by obscurity" *smile*

              Quote from: BobRay at Aug 29, 2014, 04:06 PM
              any security flaw in the manager would be instantly exploitable if it's not renamed

              Really can't argue that. Same can be said for core too. I'd previously hesitated to rename manager / connectors because of the upgrade concerns noted here. It's starting to look reliable enough to proceed - at least in a minimal config.

              It'd be interesting to hear from others that have hardened production sites about how the upgrade goes.