diff options
author | Florian Klink <flokli@flokli.de> | 2019-12-20 23:34:55 +0100 |
---|---|---|
committer | GitHub <noreply@github.com> | 2019-12-20 23:34:55 +0100 |
commit | 0a41dae98b96bf97da9887d7219ee80db3768296 (patch) | |
tree | 07531c459ab7ba06be3de4198ac2636070a57eee /nixos/doc/manual/release-notes/rl-2003.xml | |
parent | 749857f7aa593f3c1b79781f808eee1106c2e584 (diff) | |
parent | 2a413da57efc4c2009c984c63def8e9060771269 (diff) |
Merge pull request #56255 from Izorkin/nginx-temp1
nginx: do not run anything as root
Diffstat (limited to 'nixos/doc/manual/release-notes/rl-2003.xml')
-rw-r--r-- | nixos/doc/manual/release-notes/rl-2003.xml | 12 |
1 files changed, 12 insertions, 0 deletions
diff --git a/nixos/doc/manual/release-notes/rl-2003.xml b/nixos/doc/manual/release-notes/rl-2003.xml index 1c9d6b957155f..5744de96b74b3 100644 --- a/nixos/doc/manual/release-notes/rl-2003.xml +++ b/nixos/doc/manual/release-notes/rl-2003.xml @@ -331,6 +331,18 @@ services.xserver.displayManager.defaultSession = "xfce+icewm"; </listitem> <listitem> <para> + The nginx web server previously started its master process as root + privileged, then ran worker processes as a less privileged identity user. + This was changed to start all of nginx as a less privileged user (defined by + <literal>services.nginx.user</literal> and + <literal>services.nginx.group</literal>). As a consequence, all files that + are needed for nginx to run (included configuration fragments, SSL + certificates and keys, etc.) must now be readable by this less privileged + user/group. + </para> + </listitem> + <listitem> + <para> OpenSSH has been upgraded from 7.9 to 8.1, improving security and adding features but with potential incompatibilities. Consult the <link xlink:href="https://www.openssh.com/txt/release-8.1"> |