Correct Permissions For Web files

Whatever means you choose to develop and manage your Web site, you need to make sure that your Web files are given the correct permissions so that Apache can read the pages and serve them to your visitors.

Apache runs as a special user called nobody. This means that for Apache to serve up your Web pages to visitors, the files either need to be readable to the world, or they need to be owned by the nobody user. Which of these approaches you take depends on your needs.  

Every virtual host, including the initial one that was created when your server was created, has its own user group created with it. This group is intended to allow multiple people to work on and contribute Web content to your site. Even if you are the only who will be working on your site, it is your membership in the group that allows you to upload files to the document root of the virtual host. One approach then would be to make all of your Web files owned by the user who created them and by the correct virtual host group. The files would be writable to both the user and to the group, so that anyone in the group could modify them. They would also be readable by the world, so that Apache can serve the files, but not writable to the world so as to protect against unauthorized page editing.  

For example, if my domain name were “acme.com,” and both the users “msmith” and “jdoe” were to create and manage my Web content, my files in /www/vhosts/acme.com/htdocs might look something like the following:

-rw-rw-r-- 1 msmith  acme.com 430 Sep 13 07:45 index.html

-rw-rw-r-- 1 jdoe    acme.com  17 Nov 14 05:28 info.html

-rw-rw-r-- 1 jdoe    acme.com 496 Sep 14 05:50 sales.html

Remember that to change ownership and permissions on files or directories, the following commands are available to you and your users:

chmod: If you own a file and need to change its file permissions, the chmod command should be used. If you are the superuser, this command can also be used to change the permissions of any files, regardless of its owner.

vchown: Users in the sysadmin group can use this command to change the ownership of files and directories that don’t belong to them as long as they do not belong to the superuser. For example, vchown can be used to change a file so that it is owned by the “nobody” user, or to take ownership of a file that someone else has created. Also, vchown can be used to change the group that a file belongs to.  This command cannot be used to change the ownership of a file that belongs to root, or to make a file be owned by root if it belongs to someone else.

vchmod: Users in the sysadmin group can use this command to change the permissions of files that are owned by someone else as long as they do not belong to the superuser. For example, if one of your normal users uploads a file but doesn’t know how to use the chmod command to change the file permissions, a member of the sysadmin group can use vchmod to do it for them. This command cannot be used to change the file permissions of files that are owned by root.

chown: This command, when run by the superuser, can change the ownership and group that a file belongs to regardless of who owns the file.

For example, let’s assume that my administrative user account were “msmith,” and the index.html file that I placed in the document root of my Web site had the following ownership and permissions:

-rw-r-----  1 msmith msmith  430 Sep 13 07:45 index.html

If someone were to try to view this file through their Web browser, they would receive a "Permission Denied" (500) error, because the nobody user, which Apache runs as, is not allowed to view the file. In order to correct this, I would need to use the chmod command to give read permissions to the world:

> chmod 644 index.html

This would change the file permissions to look like this:

-rw-r--r--  1 msmith msmith  430 Sep 13 07:45 index.html

Because all users now have permission to read the file, Apache would be able to properly serve the page.  However, let's assume that I want to allow other members of the "acme.com" group to edit the file.  First, I would need to make the acme.com group the group owner of the file using the chown command:

> chown msmith.acme.com index.html

The file would now be owned by the acme.com user group:

-rw-r--r--  1 msmith acme.com  430 Sep 13 07:45 index.html

Now, to give the members of the group the ability to modify the file, I need to make the file writeable to the group with the chmod command:

> chmod 664 index.html

The resulting permissions would then look like:

-rw-rw-r--  1 msmith acme.com  430 Sep 13 07:45 index.html