suEXEC / non suEXEC performance

Post by Kelv » Thu, 29 Jun 2000 04:00:00

Hi there,

I have about 3500 virtually hosted websites on 2 linux webservers. I'm about
to introduce a third one, but unlike the other two, I've set it so that
every single virtualhost has user and group directives so that their cgi
scripts run as the user rather than the webservers user/group id.

As suEXEC is going to get called every time a script is run, I'm wondering
how much more overhead this is going to add to the system.

If it's too high, I'm going to have it selective for users that want it, and
normal webserver id's for those that don't care.

Anyone already been down this avenue? If so, feedback appreciated.




1. Apache and suexec: any downside/disadvantages to running SUEXEC ??


Found lots of config info etc on web but have heard that it is not
really a good idea in most circumstances. I realize it theoretically
adds some protections.

1. Is it really always a good idea? ..i.e., if one is not running an
ISP / virtual host service...  (I dont need to serve others; have own
machine/server exclusivley)

2. Does it have any downsides ?  ... Even as a beginner, I can see
that it imposes some script config constraints - do those make things
difficult or impossible at times?

I ask about the downsides cause some while back I read something along
those lines, just cant remember or locate where or specifically what
the implications were (wasn't ready for the info then). I'm new to
apache/suexec so I dont fully understand - seems to a beginner like me
that it may make some things a little more difficult than need be ??

I have apache already setup with it now (preconfigured by provider)
but am considering likely renaming suexec to disable it. I've got
Redhat 6.2 Apache 1.3.19 configured for suexec (which seems
troublesome with some scripts).

Thanks for any advice.


