026e67e6ba
Version 1.4.19 includes fixes to the following minor security issues: http://www.lighttpd.net/security/lighttpd_sa_2008_01.txt http://www.lighttpd.net/security/lighttpd_sa_2008_02.txt http://www.lighttpd.net/security/lighttpd_sa_2008_03.txt Also note that it is now explicitely built without libpcre (mostly used by mod_cache)
REQUIREMENTS PRE-INSTALL POST-INSTALL lighttpd runs as a different user ('lighttpd') by default for security reasons. Do the following after installing the port: useradd -s /bin/false lighttpd groupadd lighttpd touch /var/www/logs/access_log touch /var/www/logs/error_log chown lighttpd:lighttpd /var/www/logs/* If you wish to enable SSL support, uncomment the relevant lines in /etc/lighttpd.conf and generate a self-signed certificate: openssl req -new -x509 \ -keyout /etc/ssl/certs/lighttpd.pem -out /etc/ssl/certs/lighttpd.pem \ -days 365 -nodes PRECAUTION