lighttpd/lighttpd-1.4.56-defaultconf.patch
starlet-dx 716554f715 Update to 1.4.56 and fix CVE-2022-37797
(cherry picked from commit 30db137f7ebc504a7d2ebad08bcb37a059d1d6a4)
2022-09-21 17:52:59 +08:00

69 lines
2.3 KiB
Diff

--- doc/config/lighttpd.conf.orig 2016-07-19 09:09:39.000000000 -0500
+++ doc/config/lighttpd.conf 2016-07-19 09:25:40.282577966 -0500
@@ -204,7 +204,9 @@
## By default lighttpd would not change the operation system default.
## But setting it to 2048 is a better default for busy servers.
##
-server.max-fds = 2048
+## With SELinux enabled, this is denied by default and needs to be allowed
+## by running the following once : setsebool -P httpd_setrlimit on
+#server.max-fds = 2048
##
## listen-backlog is the size of the listen() backlog queue requested when
--- doc/config/lighttpd.conf~ 2016-08-05 08:24:07.000000000 -0500
+++ doc/config/lighttpd.conf 2016-08-05 08:26:43.914683962 -0500
@@ -112,7 +112,7 @@
##
## Document root
##
-server.document-root = server_root + "/htdocs"
+server.document-root = server_root + "/lighttpd"
##
## The value for the "Server:" response field.
--- doc/config/lighttpd.conf~ 2016-06-28 12:32:10.000000000 -0500
+++ doc/config/lighttpd.conf 2016-06-28 12:41:50.478761160 -0500
@@ -67,7 +67,7 @@
## conf.d/fastcgi.conf
## conf.d/scgi.conf
##
-var.socket_dir = home_dir + "/sockets"
+var.socket_dir = state_dir + "/sockets"
##
#######################################################################
--- doc/config/lighttpd.conf~ 2020-04-27 10:48:12.000000000 -0500
+++ doc/config/lighttpd.conf 2020-04-27 10:55:12.145316446 -0500
@@ -90,7 +90,7 @@
##
## Use IPv6?
##
-server.use-ipv6 = "enable"
+#server.use-ipv6 = "enable"
##
## bind to a specific IP
--- doc/config/lighttpd.conf~ 2020-10-26 14:23:23.000000000 -0500
+++ doc/config/lighttpd.conf 2020-10-26 14:27:55.577840608 -0500
@@ -14,8 +14,8 @@
## chroot example aswell.
##
var.log_root = "/var/log/lighttpd"
-var.server_root = "/srv/www"
-var.state_dir = "/run"
+var.server_root = "/var/www"
+var.state_dir = "/run/lighttpd"
var.home_dir = "/var/lib/lighttpd"
var.conf_dir = "/etc/lighttpd"
@@ -438,7 +438,7 @@
##
## # Check your cipher list with: openssl ciphers -v '...'
## # (use single quotes as your shell won't like ! in double quotes)
-## #ssl.cipher-list = "HIGH" # default
+## #ssl.cipher-list = "PROFILE=SYSTEM"
##
## # (recommended to accept only TLSv1.2 and TLSv1.3)
## #ssl.openssl.ssl-conf-cmd = ("MinProtocol" => "TLSv1.2")