Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Change the Default Umask for Apache and PHP

The umask decides the permissions of new files that Apache and PHP create. This guide shows how to change it. You need root access, so it fits VPS and dedicated servers.

Dedicated Servers2 min read14 steps

What is umask?

Permissions are rules that say who can read, write or run a file. A umask is a number that takes permissions away from new files. It is like a stencil that blocks some rights.

The common default is 022. With it, a new file gets 644 and a new folder gets 755. Only the owner can write to them. A umask of 002 lets the group write too. You may want that if a team shares a site folder.

Warning: a looser umask makes files easier for others to change. Only do this when you need it. Back up the file you edit first.

Steps on CentOS, AlmaLinux or RHEL

  1. Log in to your server over SSH as root.
  2. Back up the Apache settings file.
cp /etc/sysconfig/httpd /etc/sysconfig/httpd.bak

This makes a safe copy.

  1. Open the file with nano /etc/sysconfig/httpd.
  2. Add this line at the bottom.
umask 002

This sets the new default for Apache and the PHP code it runs.

  1. Save the file and exit.
  2. Restart Apache.
systemctl restart httpd

This makes Apache read the new setting.

Steps on Ubuntu or Debian

  1. Back up the file /etc/apache2/envvars.
  2. Open it with nano /etc/apache2/envvars.
  3. Add the line umask 002 at the bottom.
  4. Save the file.
  5. Restart Apache with systemctl restart apache2.

Test the change

  1. Create a small PHP file that makes a new file, or upload through an app that uses PHP.
  2. Run ls -l in that folder.
  3. Check that the new file shows rw-rw-r--, which means 664.
Tip: If you use PHP-FPM, the pool may run under its own service file. Check its systemd unit for a UMask= line. Control panel servers can differ, so ask Hostvento support first.

Quick recap

  • Umask removes permissions from new files.
  • 022 gives 644 files and 755 folders. 002 allows group writing.
  • Add the umask line to the Apache environment file, then restart Apache.
  • Back up first and test with a new file.