• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Resolved Is it SAFE to disable open_basedir in dedicated server?

Mkting

New Pleskian
Server operating system version
Debian 10
Plesk version and microupdate number
18.0.44
Hello,
I have noticed that the php openbase_dir directive is severely slowing down php execution on my server with various wordpress sites.
By disabling it I noticed a considerable increase to the loading speed of all pages using realpath_cache_size.

Since the server is my own dedicated one with no access from external users, I was wondering how much risk I would be taking by disabling openbase_dir on all sites or at least those with high traffic that need better speeds.

Also I would add that each website has been configured as a "Dedicated FPM application served by nginx", so each website use a separate fpm.

I know it is a directive used to increase security but I understand it is needed more for hosted websites rather than on dedicated servers with limited access.

I have a server with debian 10.5 and plesk 18.0.44
 
Many people and hosting providers still consider this setting a necessary security measure, but that's not exactly true. Even PHP itself officially denies it being useful in a security context: PHP: A Note on Security in PHP
In my opinion, using proper UNIX permissions is the only way to really secure the system, then you can ignore open_basedir completely and thus benefit from the realpath cache.
 
Back
Top