diff options
author | barnboy%trilobyte.net <> | 2001-04-25 16:38:17 +0200 |
---|---|---|
committer | barnboy%trilobyte.net <> | 2001-04-25 16:38:17 +0200 |
commit | 5d71f7bcd2f55a2b0de4f360a9d22df6b636b598 (patch) | |
tree | b4a893bf848f362b55e34bbb6cee9e00942aa165 /docs/html | |
parent | 2d4d7c92bfb4ce18e4413b1e66f30bd62a44e6ff (diff) | |
download | bugzilla-5d71f7bcd2f55a2b0de4f360a9d22df6b636b598.tar.gz bugzilla-5d71f7bcd2f55a2b0de4f360a9d22df6b636b598.tar.xz |
Fix for confusing language regarding protection of data/ & shadow/ directories
and localconfig file.
Diffstat (limited to 'docs/html')
-rw-r--r-- | docs/html/Bugzilla-Guide.html | 9 | ||||
-rw-r--r-- | docs/html/security.html | 9 |
2 files changed, 12 insertions, 6 deletions
diff --git a/docs/html/Bugzilla-Guide.html b/docs/html/Bugzilla-Guide.html index 76c9b8dc3..0712a5146 100644 --- a/docs/html/Bugzilla-Guide.html +++ b/docs/html/Bugzilla-Guide.html @@ -5336,11 +5336,14 @@ TARGET="_top" ></LI ><LI ><P -> Ensure you have adequate access controls for $BUGZILLA_HOME/data/, $BUGZILLA_HOME/localconfig, - and $BUGZILLA_HOME/shadow directories. +> Ensure you have adequate access controls for the $BUGZILLA_HOME/data/ and + $BUGZILLA_HOME/shadow/ directories, as well as the $BUGZILLA_HOME/localconfig file. The localconfig file stores your "bugs" user password, which would be terrible to have in the hands - of a criminal. Also some files under $BUGZILLA_HOME/data store sensitive information. + of a criminal. Also some files under $BUGZILLA_HOME/data/ store sensitive information, and + $BUGZILLA_HOME/shadow/ stores bug information for faster retrieval. If you fail to secure + these directories and this file, you will expose bug information to those who may not + be allowed to see it. </P ><P > On Apache, you can use .htaccess files to protect access to these directories, as outlined diff --git a/docs/html/security.html b/docs/html/security.html index 7c45ea1f9..220559a72 100644 --- a/docs/html/security.html +++ b/docs/html/security.html @@ -172,11 +172,14 @@ TARGET="_top" ></LI ><LI ><P -> Ensure you have adequate access controls for $BUGZILLA_HOME/data/, $BUGZILLA_HOME/localconfig, - and $BUGZILLA_HOME/shadow directories. +> Ensure you have adequate access controls for the $BUGZILLA_HOME/data/ and + $BUGZILLA_HOME/shadow/ directories, as well as the $BUGZILLA_HOME/localconfig file. The localconfig file stores your "bugs" user password, which would be terrible to have in the hands - of a criminal. Also some files under $BUGZILLA_HOME/data store sensitive information. + of a criminal. Also some files under $BUGZILLA_HOME/data/ store sensitive information, and + $BUGZILLA_HOME/shadow/ stores bug information for faster retrieval. If you fail to secure + these directories and this file, you will expose bug information to those who may not + be allowed to see it. </P ><P > On Apache, you can use .htaccess files to protect access to these directories, as outlined |