I’ve done a little tuning to my WordPress setup. To keep up to date, I’ve switched from the Ubuntu installation to a downloaded installation under /opt/wordpress. This is owned by my user and served by Apache running as www-data. Updates are done using the SFTP method.
Securing /opt/wordpress
I added myself to the www-data group. This allows Apache to read any files with group access but prevents writing if the web-server is compromised.
I set the group sticky bit on all the directories. If required, setting it on the wp-content/upgrade directory should be sufficient.
SSH Key
I generated my key outside the home directory for www-data which is /var/www. The directory I chose is not one I would publish. However, ssh requires a .ssh/known_hosts file in its home directory. This was created and the appropriate security was added. The key is password protected.
Outstanding Issues
There are some outstanding issues. I’ll look into these as time permits.
Native ssh
The PHP ssh2 extention does not work on my server. I’ve found a couple of issues. (Most issues can be resolved by installing the ssh-sftp-updater-support plugin.)
- Passwords on the key don’t work. This is a known issue with a work-around. The initial connection appears to fail, but a second call should resolve the issue. (Neither implementation works reliably.)
- The is_dir function does not work. Returning true for paths that end in a slash (
/
) is a workaround. This got me as far as trying to install. This may be a result of how the path is constructed and there is a published workaround. - The is_file function appears to fail as WordPress reports the download contains no files. This is likely the same issue as for the is_dir function.
Theme upgrades
My modifications to the theme are getting a little old. The theme works reasonably well on mobile devices, but I would like to update it to a more streamlined theme. The site statistics I have indicate a surprisingly high percentage of viewers use a mobile device.