aboutsummaryrefslogtreecommitdiff
path: root/manifests/series7/hardened.pp
diff options
context:
space:
mode:
Diffstat (limited to 'manifests/series7/hardened.pp')
-rw-r--r--manifests/series7/hardened.pp8
1 files changed, 8 insertions, 0 deletions
diff --git a/manifests/series7/hardened.pp b/manifests/series7/hardened.pp
new file mode 100644
index 0000000..73cf21a
--- /dev/null
+++ b/manifests/series7/hardened.pp
@@ -0,0 +1,8 @@
+class php::series7::hardened {
+ php::config {
+ 'allow_url_fopen' : series => '7', value => 'Off';
+ 'allow_url_include' : series => '7', value => 'Off';
+ 'disable_functions' : series => '7', value => 'pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,phpinfo, system, exec, shell_exec, passthru, proc_get_status, proc_open, popen, proc_close, proc_nice, proc_terminate, pcntl_exec, proc_open, show_source, dl, symlink, system_exec';
+ #series => '7', value => 'disable_functions = pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,phpinfo, system, exec, shell_exec, passthru, proc_get_status, proc_open, popen, proc_close, proc_nice, proc_terminate, pcntl_exec, proc_open, curl_init, parse_ini_file, show_source, dl, symlink, syslog, mail, system_exec',
+ }
+}