AsiaBSDCon 2017 Secure CGI

FastCGI security model

FastCGI security model

FastCGI security model
FastCGI's manager-based security model.

FastCGI security policies are per-installation. Given the many different kinds of FastCGI managers, there is no clear consensus on file-system jails, privilege dropping, etc.