Platforms

This module should work on all platforms supporting setresuid() and setresgid()
system calls.

This includes Linux, FreeBSD, OpenBSD, HPUX, but probably not all versions.

suid-test.c is a testprogram that checks if a platform has the necessary
functios, and if they function as expected.

Simply compile with cc -o suid-test suid_test.c
I would like to hear about compile errors :)

Please send me the output of the suid-test program, so I can make a list of
supported / unsupported platforms. If you get unresolved errors in the
setresuid() / getresuid() functions simply state your platform (uname -a) and
that it didn't compile.
------------------------------------------------------------------------------

Compilation

Simply type 'make' to compile. The makefile uses Apache's apxs, so that HAS to
match your currently running Apache. You also need an Apache with DSO support,
don't even thing about making this a static module.

After a make you should end up with a mod_suid.so file. Copy this file to
the dir you specified with --libexecdir, or use a dir and use full paths.
------------------------------------------------------------------------------

Usage

Make apache load the module :

LoadModule suid_module      /usr/libexec/apache/mod_suid.so
Make SURE that this is the last LoadModule line in your Apache config !!!

Change user / group in Apache to root. For this to work, you need a Apache
compiled with -DBIG_SECURITY_HOLE, else it will refuse to start.

In your vhost config :

SuidEnable      yes
SuidPolicy      user-group
Suid            user someuser
Suid            group somegroup

The Apache childs run as your standard Apache user. Actually, it runs as the
user it finds first when it looks at def_users. Make sure one of those exist !!

SuidPolicy can be user-group | file | document-root | parent-directory, I
use user-group myself.

WARNING :

This code CAN open up your server to hackers. If you need a secure system,
DON'T use this module.

Don't bug me with warnings about how unsafe this is, I know.
