summary refs log tree commit diff
path: root/nixos/doc/manual/release-notes/rl-2003.xml
diff options
context:
space:
mode:
authorFlorian Klink <flokli@flokli.de>2019-12-20 23:34:55 +0100
committerGitHub <noreply@github.com>2019-12-20 23:34:55 +0100
commit0a41dae98b96bf97da9887d7219ee80db3768296 (patch)
tree07531c459ab7ba06be3de4198ac2636070a57eee /nixos/doc/manual/release-notes/rl-2003.xml
parent749857f7aa593f3c1b79781f808eee1106c2e584 (diff)
parent2a413da57efc4c2009c984c63def8e9060771269 (diff)
Merge pull request #56255 from Izorkin/nginx-temp1
nginx: do not run anything as root
Diffstat (limited to 'nixos/doc/manual/release-notes/rl-2003.xml')
-rw-r--r--nixos/doc/manual/release-notes/rl-2003.xml12
1 files changed, 12 insertions, 0 deletions
diff --git a/nixos/doc/manual/release-notes/rl-2003.xml b/nixos/doc/manual/release-notes/rl-2003.xml
index 1c9d6b957155f..5744de96b74b3 100644
--- a/nixos/doc/manual/release-notes/rl-2003.xml
+++ b/nixos/doc/manual/release-notes/rl-2003.xml
@@ -331,6 +331,18 @@ services.xserver.displayManager.defaultSession = "xfce+icewm";
    </listitem>
    <listitem>
     <para>
+     The nginx web server previously started its master process as root
+     privileged, then ran worker processes as a less privileged identity user.
+     This was changed to start all of nginx as a less privileged user (defined by
+     <literal>services.nginx.user</literal> and
+     <literal>services.nginx.group</literal>). As a consequence, all files that
+     are needed for nginx to run (included configuration fragments, SSL
+     certificates and keys, etc.) must now be readable by this less privileged
+     user/group.
+    </para>
+   </listitem>
+   <listitem>
+    <para>
      OpenSSH has been upgraded from 7.9 to 8.1, improving security and adding features
      but with potential incompatibilities.  Consult the
      <link xlink:href="https://www.openssh.com/txt/release-8.1">