General Horde Settings
* $conf[vhosts]
Enable virtual host configuration? If you want to use a single Horde installation for different virtual hosts, you can create separate configuration files for each virtual host, e.g. conf-www.example.com.php or prefs-mail.example.com.php. The global configuration files are always loaded first, and virtual host specific files are not required. If running command line scripts, you can specify the host name with the environment variable SERVER_NAME.
PHP Settings
* $conf[debug_level]
The value to set error_reporting() to. See http://www.php.net/manual/function.error-reporting.php for more information and possible values.
Enter a valid PHP expression.
* $conf[max_exec_time]
If we need to perform a long operation, what should we set max_execution_time to (in seconds)? 0 means no limit; however, a value of 0 will cause a warning if you are running in safe mode. See http://www.php.net/manual/function.set-time-limit.php for more information.
* $conf[compress_pages]
If this option is set to true, and you have the php zlib extension installed, pages over a certain size will be compressed and sent to the browser as gzip-encoded data in order to save bandwidth. There is little reason not to enable this.
* $conf[secret_key]
Secret key for generating signed messages from this server. This is a random string unique to this Horde installation.
* $conf[umask]
What umask should we run with? This will affect the permissions on any temporary files that are created. This value is an integer.
* $conf[testdisable]
Disable the test script (horde/test.php)? For security reasons, this is disabled by default
$conf[tmpdir]
If you want to use a temporary directory other than the system default or the one specified in php's upload_tmp_dir value, enter it here.
URL Settings
* $conf[use_ssl]
Assume that we are not using SSL and never generate https URLs.
Assume that we are using SSL and always generate https URLs.
Attempt to auto-detect, and generate URLs appropriately
Assume that we are not using SSL and generate https URLs only for login.
Determines how we generate full URLs (for location headers and such).
* $conf[server][name]
What server name should we use? You'll probably know if you need to change this default; only in situations where you need to override what Apache thinks the server name is.
Enter a valid PHP expression.
$conf[server][port]
What port number is the webserver running on? Again, you shouldn't need to change the default, and you probably know it if you do. The exception is if you have chosen to always generate https URLs, as described above.
Enter a valid PHP expression.
* $conf[urls][token_lifetime]
This is the length of time in minutes that links protected with request tokens (to prevent cross-site request forgery) will be valid. Higher values may make your users more vulnerable to these attacks.
* $conf[urls][hmac_lifetime]
This is the length of time in minutes that links signed with HMACs (to prevent forged URL parametes) will be valid. Higher values may make your users more vulnerable to forgery or phishing.
$conf[urls][pretty]
No (GET-based URLs)
URL rewriting (mod_rewrite, lighttpd rules, etc.)
Use pretty URLs?
$conf[safe_ips]
A list of IP subnets that are considered safe, e.g. to transfer encryption passphrases without requiring an HTTPS connection. (Example: 192.168.0.0, 10.0.0.0) To consider all connections to be safe (e.g. when SSL is handled by an SSL crypto card and not by the webserver) this value should be '*'.
Session Settings
* $conf[session][name]
What name should we use for the session that Horde applications share? If you want to share sessions with other applications on your webserver, you will need to make sure that they are using the same session name. This value can also be used to invalidate previous sessions when upgrading your local version of Horde (Note: Session names must consist of only alphanumeric characters.)
* $conf[session][use_only_cookies]
Should we only allow session information to be stored in a session cookie and not be passed by URL (GET) parameters? This is on by default because passing session information in the URL is a security risk. Consider carefully before turning it off . Cookies must be working and enabled in the browser though, or you won't be able to login to Horde. If false, session information will be passed via both the URL and cookies.
* $conf[session][timeout]
The cookie lifetime (in seconds). If 0, (DEFAULT; RECOMMENDED) cookies will expire when the browser closes. Otherwise, this is the length after which a cookie will expire (this lifetime is updated after every browser request). Setting a non-zero value is NOT RECOMMENDED as there is no guarantee a session will ever expire; additionally, the session expiration value is based on the SERVER, not the CLIENT, so this will most certainly not work the way you want/think it should (see http://www.php.net/manual/en/function.session-set-cookie-params.php ) for further information.
* $conf[session][cache_limiter]
What caching level should we use for the session? DO NOT CHANGE THIS UNLESS YOU REALLY KNOW WHAT YOU ARE DOING. Setting this to anything other than 'nocache' will almost certainly result in severely broken script behavior.
* $conf[session][max_time]
The maximum length of time (in seconds) a session can be active after user authentication before it will be destroyed. (Sessions may otherwise never timeout if a user never closes their browser.) 0 means there is no maximum session time (NOT RECOMMENDED).
* $conf[cookie][domain]
What domain should we set cookies from? If you have a cluster that needs to share cookies, this might be '.example.com' - the leading '.' is important. If you only use session cookies (see above), but you are running Horde on an intranet server without a domain part, i.e. http//horde/, you need to set this value to ''. Most likely, though, you won't have to change the default.
Enter a valid PHP expression.
* $conf[cookie][path]
What path should we set cookies to? For maximum security this should match the URL where Horde is on your webserver. If Horde is at /horde, then this should be '/horde'. If Horde is installed as the document root, then this needs to be '/' - NOT ''. If IE will be used to access Horde modules, you should read this first (discussing issues with IE's Content Advisor): http://lists.horde.org/archives/imp/Week-of-Mon-20030113/029149.html