Commit 45a408b8 authored by Poul-Henning Kamp's avatar Poul-Henning Kamp

update -r description

parent b7175b38
...@@ -111,13 +111,12 @@ OPTIONS ...@@ -111,13 +111,12 @@ OPTIONS
default_ttl run-time parameter. default_ttl run-time parameter.
-r param[,param...] -r param[,param...]
Specifies a list of parameters that are read only. This Make the listed parameters read only. This gives the
gives the system administrator a way to limit what someone system administrator a way to limit what the Varnish CLI can do.
with access to the Varnish CLI can do. In a very secure Consider making parameters such as *user*, *group*, *cc_command*,
environment you want to consider setting parameters such *vcc_allow_inline_c* read only as these can potentially be used
as *user*, *group*, *cc_command*, *vcc_allow_inline_c* to to escalate privileges from the CLI.
read only as these can potentially be used to escalate Protecting *listen_address* may also be a good idea.
privileges.
-u user Specifies the name of an unprivileged user to which the child -u user Specifies the name of an unprivileged user to which the child
process should switch before it starts accepting process should switch before it starts accepting
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment