Re: Privilege reduction with start_server / plackup

by Anonymous Monk
on Apr 17, 2020 at 14:27 UTC

in reply to Privilege reduction with start_server / plackup

Every web server has the ability to specify the user -- say, nobody or www_user -- that the server will run as. It uses high privilege to open the low-numbered ports, then immediately (and, irrevocably) becomes a non-privileged user. It's a one-way street, they can't go back. Furthermore: if you are using FastCGI, the worker processes never need to have high privilege, nor necessarily the same user-ids.
Node Type: note
