Why is PHP insecure by default on FC1? Is it because it's not for production use? It uses a php.ini that is only suited for development, not production use. I ended up grabbing the "php.ini-recommended" file from the official release of PHP-4.3.6 and made a couple Fedora-related changes to it (diff helped out here). J.A.K.E. [ jake1138 AT yahoo DOT com ]