You are viewing the PKP Support Forum | PKP Home Wiki

Security Enhanced Linux and Open Journal Systems

Are you an Editor, Author, or Journal Manager in need of help? Want to talk to us about workflow issues? This is your forum.

Moderators: jmacgreg, michael, vgabler, John

Forum rules
The Public Knowledge Project Support Forum is moving to http://forum.pkp.sfu.ca

This forum will be maintained permanently as an archived historical resource, but all new questions should be added to the new forum. Questions will no longer be monitored on this old forum after March 30, 2015.

Security Enhanced Linux and Open Journal Systems

Postby F. Lengyel » Mon Apr 18, 2005 9:22 pm

I've installed OJS 1.1.9 on a Red Hat Enterprise Linux 4 system, which has Security Enhanced Linux enabled. The site is configured as a virtual site (there are others), with virtual sites following the security context specified by the following regular expression, located in /etc/selinux/targeted/context/files/file_contexts (in the apache section):

Code: Select all
/home/[^/]+/((www)|(web)|(public_html))(/.+)? system_u:object_r:httpd_user_content_t

This works, (folliowng the scheme /home/siteusername/www); however, since the OJS working directory should not be WWW accessible, but only accessible to the Apache web server, it is necessary to specify, during the installation, a directory outside of /home/siteusername/www and give it a security context of httpd_sys_content_t (with chcon -t httpd_sys_content_t working_docs_directory). So this means adding a rule to the local securty context of the site, so that a restorecon -v -R /home/siteusername doesn't wipe out this setting.

It's likely that OJS sites will want to adopt the intelligence agency level of security provided by selinux, if this is available. This raises the question of configuring OJS installation security contexts. Setting chmod 777 for directories such as images/custom and images/article images is less than optimal.

Is anyone else concerned with OJS under selinux?

F. Lengyel
Posts: 1
Joined: Mon Apr 18, 2005 8:54 pm
Location: CUNY Graduate Center, New York

File and Folder permissions

Postby ramon » Tue Apr 19, 2005 10:49 am

F. Lengyel,

The submission files, images/custom, and images/articleimages/ need a 775 permission, not 777. The important thing is that the owner of the system folder should be in the apache group.

I'm not Linux savvy enough to discuss the security implementations, but I don't believe they will be a problem...
Posts: 945
Joined: Wed Oct 15, 2003 6:15 am
Location: Brasí­lia/DF - Brasil

Return to OJS Editorial Support and Discussion

Who is online

Users browsing this forum: Google [Bot] and 1 guest