diff --git a/INSTALL b/INSTALL index 3bdf95a9a..e7ff603d3 100644 --- a/INSTALL +++ b/INSTALL @@ -179,8 +179,12 @@ virtual host config by with: AllowOverride all +For non-apache web servers add equivalent configuration parameters to deny +direct access to these private resources. + It is also recommended to change the document root to /public_html -after installation. +after installation if Roundcube runs at root of a dedicated virtual host. This +will automatically keep sensitive files out of reach for http requests. UPGRADING