WebFaction
Community site: login faq

I'm not a professional SA, but what's the best practice in securing the django settings.py file via permissions/locations to be as secure as possible in webfaction;s shared hosting environment?

asked 06 Aug '11, 18:42

romangods
312
accept rate: 0%


Your shell user is the only user who needs access to your settings file, so you can secure it with:

chmod 600 settings.py

Note that by default, other users won't be able to access your files since they cannot traverse the top level of your home directory. So, if you haven't mucked about with permissions there, then you don't need to make any other changes to keep your settings secure.

permanent link

answered 06 Aug '11, 18:52

seanf
12.2k42136
accept rate: 37%

Thanks! For auditing, do you know if webfaction keeps audit trails of their own SA's access to client accounts since they obviously can get access to my home directory and view the settings file?

(06 Aug '11, 20:21) romangods

We don't keep file-specific audit histories, but we do keep a ~3 week history of login activity (including su logins from root to user accounts) and shell command history for root, so we're usually able to reconstruct a sequence of events if we need to.

As a matter of policy, we won't view or modify any of your files unless you open a support ticket that requires us to do so, or if there is a problem on the server (like a runaway process) that would require us to do so. In any case, you will always be informed when that happens.

(07 Aug '11, 10:32) seanf
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×909
×69

question asked: 06 Aug '11, 18:42

question was seen: 4,115 times

last updated: 07 Aug '11, 10:32

WEBFACTION
REACH US
SUPPORT
AFFILIATE PROGRAM
LEGAL
© COPYRIGHT 2003-2020 SWARMA LIMITED - WEBFACTION IS A SERVICE OF SWARMA LIMITED
REGISTERED IN ENGLAND AND WALES 5729350 - VAT REGISTRATION NUMBER 877397162
5TH FLOOR, THE OLD VINYL FACTORY, HAYES, UB3 1HA, UNITED KINGDOM