[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kde-www
Subject:    Re: private wiki access
From:       Navindra Umanee <navindra () cs ! mcgill ! ca>
Date:       2005-03-03 17:00:26
Message-ID: 20050303120026.B13253 () cs ! mcgill ! ca
[Download RAW message or body]

Dirk Mueller <mueller@kde.org> wrote:
> I pointed you to our howto which tells about sensible defaults for
> PHP to have a reasonably secure setup. There's really not much more
> to do other than that and to establish DoS filters (ulimit's,
> connection concurrency limits etc).

Yes, thanks.  I wasn't responsible for the PHP/OS setup, all that was
primarily setup and maintained previously by someone else.  I spent a
few hours myself fixing it all and securing it as mentioned.  Thanks
for your pointers, I had used them and informed myself about PHP as
well.

It's all good and well, but then when you have two demanding services
both vulnerable to different kinds of attacks, both which behave less
than ideally whether being attacked or not, and you have to monitor
them both at the same and suffer downtimes of both services when
things go wrong on either...  Well it's not good for Dot and it's not
good for Wiki.

I am not actually sitting at the computer all day so I can't always
keep up with all the different attack vectors on two different complex
systems and so I can't guarantee uptime without any more help
available.  Separating the concerns, effectively removing one from the
equation, makes my life vastly easier and makes these services work
better.

I had been looking for a new host/admin for the Wiki for a while
already and I'm pleased that things have come to a point and Jason has
made this generous offer.

Only one person has asked for private access to the Wiki so far, so
not too much of an urgency as I had been made to believe.  Send
requests directly to Luci now for clearance, since he knows what the
status of the data transfer is and whether he wants people using the
old wiki now or not.

Cheers,
Navin.
_______________________________________________
kde-www mailing list
kde-www@kde.org
https://mail.kde.org/mailman/listinfo/kde-www
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic