Jump to content

Debian /var/www/ file permissions


Recommended Posts

Hello,

 

I am experimenting with setting up my own Linux based server using Debian.  Right now it seems to be running great, however I have a few php scripts that move files around and create directories that are giving me some problems.  For some crazy reason, my permissions seem to be really screwed up.  When my script tries to create a folder, it will only give the max permissions of 755 (even if I tell it to set the folder to 0777).  If I try to move my files, I get permission errors as well.  It looks like the folders are being created under a user and usergroup called www-data.  Is there another step that I have missed to get this working?

 

Thanks in advance!

owner

Link to comment
https://forums.phpfreaks.com/topic/186274-debian-varwww-file-permissions/
Share on other sites

The way I normally setup Debian systems is as follows:

 

1) As root, create a new group called 'www' then place yourself within that group, logout and back in for it to take effect.

 

sudo groupadd www
sudo gpasswd -a <yourusername> www
logout

 

2) Make the entire /var/www directory structure be owned by 'www-data' and the 'www' group. Give users belonging to the 'www' group write permissions, then set the sticky bit on the group for this directory structure so that any new directories created will take on these same permissions.

 

sudo chown -R www-data:www /var/www
sudo find /var/www -type f -exec chmod 664 {} \;
sudo find /var/www -type d -exec chmod 775 {} \;
sudo find /var/www -type d -exec chmod g+s {} \;

 

That should now give you sufficient permissions to create directories and files within /var/www manually (ie: Via a terminal). If you want these directories to be writtable by the server process you will however need to chown them to www-data:www. Any new directories created by the Apache process will automatically be owned by www-data:www.

 

3) Allow users within the 'www' group to change directories they own within /var/www to be owned by 'www-data:www'.

 

sudo sudoedit /etc/sudoers

 

Then add the following line.....

 

%www ALL = NOPASSWD: /bin/chown www-data /var/www/*, /bin/chown -R www-data /var/www/*

 

This means users within the 'www' group can now execute....

 

sudo chown www-data /var/www/<directoryname>

 

on directories they own, making them writtable via the Apache process.

 

That's basically it. Allot of people like to simply join the www-data group and set the sticky bit on /var/www but you generally don't want all directories to be writtable by the Apache process.

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.