This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

Suhosin is a dead project. How will Sentora move on to PHP 7.x?
#11
[Not Solved] RE: Suhosin is a dead project. How will Sentora move on to PHP 7.x?
(08-23-2018, 09:35 PM)Eulogy Wrote: Plesk Use Mod_sec + fail2ban jail as WAF. We can even setup jail for sentora if you think that can be a problem. I'm using sentora on PHP 7.x with fail2ban, Mod_sec, firewall and SElinux, no problem til now.

Otherwise you can hope to someone can get back  suhosin

https://github.com/sektioneins/suhosin7/...ae1e30d3f5

This project might be worth looking at:

https://snuffleupagus.readthedocs.io

I'm currently testing it with Sentora on CentOS 7 with PHP 7.2.

Takes a bit of configuring and from my testing one configuration is affecting all PHP-based sites and I can't seem to completely get each site running separately from each other (I am finding that the "rules" file for the vhosts is affecting the Sentora code even when there's no "rules" file defined for Sentora). Not sure if this is a bug issue with Snuffleupagus or by design, but it's currently being developed which is more than seems to be happening with Suhosin Smile

I am also running Fail2Ban on the same test server and so far it seems happy keeping things at bay...

Keith
Reply
Thanks given by:
#12
[Not Solved] RE: Suhosin is a dead project. How will Sentora move on to PHP 7.x?
(08-24-2018, 05:32 AM)fearworks Wrote: This project might be worth looking at:

https://snuffleupagus.readthedocs.io

I'm currently testing it with Sentora on CentOS 7 with PHP 7.2.

Takes a bit of configuring and from my testing one configuration is affecting all PHP-based sites and I can't seem to completely get each site running separately from each other (I am finding that the "rules" file for the vhosts is affecting the Sentora code even when there's no "rules" file defined for Sentora). Not sure if this is a bug issue with Snuffleupagus or by design, but it's currently being developed which is more than seems to be happening with Suhosin Smile

I am also running Fail2Ban on the same test server and so far it seems happy keeping things at bay...

Keith

Hello, fearworks, how did you manage to use php 7.2 with sentora ? is it secure? how so? 

Would you please share some tips.. comandes.. or installers if you can.

Thank you..

And thank you everyone who contributed in SENTORA, you are a life savers.. Thank you
Reply
Thanks given by:
#13
[Not Solved] RE: Suhosin is a dead project. How will Sentora move on to PHP 7.x?
(12-12-2018, 09:56 AM)ilyass Wrote: Hello, fearworks, how did you manage to use php 7.2 with sentora ? is it secure? how so? 

Would you please share some tips.. comandes.. or installers if you can.

Thank you..

And thank you everyone who contributed in SENTORA, you are a life savers.. Thank you

I have to admit I haven't tested it thoroughly and compared the security performance against PHP 5.6 running with Suhosin, but I can say that it does appear to function. I've been waiting for PHP 7.3 to be released, and this happened a few days ago, so I will be looking to share some more info very soon.

Obviously it goes without saying that anything involving PHP 7+ is purely experimental and isn't officially supported by the Sentora team. Anyone should only play about with it in a testing or development environment as I am doing, but hopefully it may pave the way for Sentora's first real steps into PHP 7 territory one day (soon?!?)...

Keith
Reply
Thanks given by:


Possibly Related Threads...
Thread Author Replies Views Last Post
to clone 'sentora' installation to another machine gabriel15959 3 75 06-13-2019, 12:15 AM
Last Post: gabriel15959
Time to give up on Suhosin? aaronlroberts 2 527 05-11-2019, 08:31 AM
Last Post: aaronlroberts
Sentora open_basedir - how to set for specific directory sathish2009 6 2,408 05-02-2019, 07:35 AM
Last Post: TGates

Forum Jump:


Users browsing this thread: 1 Guest(s)