Troubleshooting & Common Errors

Resolving ModSecurity SecDataDir Permission Issues: Debugging and Replacing mod_ruid2 with mod_suexec in WHM

By the Domain India teamPublished 8 min read
Knowledge base article
Contents (7 sections)

The error collections_remove_stale: Failed to access DBM file ... Permission denied comes from ModSecurity, the web application firewall inside Apache. It means ModSecurity can't read or clean up the files where it keeps data between requests. On a cPanel server this is almost always caused by the old Apache module mod_ruid2. This guide explains what the message means for a website on shared hosting, and, in a clearly marked section, how to fix it on a cPanel server you manage yourself.

Key takeaways

On Domain India shared hosting you don't need to do anything: ModSecurity and Apache's modules are managed by us for the whole server, and you can't change them. If a legitimate action on your site returns a 403, open a ticket with the URL, the time and your IP address. On your own cPanel server, the lasting fix is to remove mod_ruid2 in WHM's EasyApache 4 and run PHP through PHP-FPM with mod_suexec. Changing folder permissions only hides the problem until the next restart.

1. What SecDataDir is

ModSecurity can remember things across requests: how many requests an IP address has made, a score for a session, or a count for the whole server. These persistent collections are stored as small database (DBM) files in the folder named by the SecDataDir directive. On cPanel servers that folder is usually /var/cpanel/secdatadir.

Apache processes read and write those files, and ModSecurity regularly removes stale entries. That works when every Apache process runs as the same system user. It breaks when different processes run as different users.

2. Why mod_ruid2 causes the error

mod_ruid2 made each Apache process switch to the owner of the website it was serving. A file created while serving one account belonged to that account's user, so the next process, running as a different user, got Permission denied when it tried to read or clean it.

Typical symptoms on the server:

  • ModSecurity: collections_remove_stale: Failed to access DBM file "/var/cpanel/secdatadir/...": Permission denied repeating in the Apache error log;
  • rules that rely on collections, such as rate limits, silently not working;
  • the error disappearing after a chown of the folder, then returning within hours.

mod_ruid2 is no longer maintained, cPanel has deprecated it, and current EasyApache 4 builds on AlmaLinux, Rocky Linux and CloudLinux 8 and later don't offer it. If you still run it, you are on an old setup that needs moving anyway.

3. On Domain India shared hosting

If you host with us on cPanel, DirectAdmin or Webuzo shared hosting, this error is not yours to fix and not something you can see. It would appear only in the server's main Apache log, and Apache's modules, ModSecurity and its data folder are configured by us for the whole server. Customers can't change them, and ModSecurity can't be switched off per domain.

What you might notice as a website owner is different: one action on your site, such as saving a post, submitting a form or uploading a file, fails with 403 Forbidden while the rest of the site works. That is usually a ModSecurity rule blocking a request it mistook for an attack.

  1. Repeat the action once
    and note the exact date and time.
  2. Copy the full URL
    from the address bar and write down what you did.
  3. Find your public IP address
    by searching "what is my IP" on the same connection.
  4. Open a ticket
    at /client/support/new when logged in, or at /support/ticket, with those details. We find the rule in the server logs and decide whether a precise exception is safe.
ModSecurity lines in .htaccess give a 500 error

Don't add SecRuleEngine Off, SecRuleRemoveById or similar lines to .htaccess. They are not allowed on our servers and make your site return a 500 Internal Server Error.

For the full picture on shared hosting, read configuring ModSecurity in cPanel.

4. On your own cPanel server: confirm the cause

Everything from here on applies only to a cPanel and WHM server where you have root access, for example a server with your own cPanel licence. A Domain India VPS is self-managed and comes without cPanel.

Check the Apache error log for the message and see whether mod_ruid2 is loaded:

bash
grep -c "collections_remove_stale" /etc/apache2/logs/error_log
httpd -M 2>/dev/null | grep -Ei "ruid2|suexec|mpm"
ls -ld /var/cpanel/secdatadir
ls -l /var/cpanel/secdatadir | head

If ruid2_module appears and the files in the folder belong to many different account users, you have found the cause. Don't rely on rpm -qa alone to check modules; httpd -M shows what Apache actually loaded.

chown and chmod are not a fix

Resetting the folder's owner and permissions makes the error stop for a while, then the next request served for another account creates files it can't share again. Recursive permission changes on system folders also risk opening them to every user on the server. Remove the cause instead.

5. On your own cPanel server: replace mod_ruid2

The current cPanel model is PHP-FPM for PHP, with each domain's pool running as the account user, and mod_suexec for CGI scripts. Apache itself then runs as one user, so ModSecurity's data folder works again.

  1. Take a backup and plan a quiet window.
    Download or save a copy of the current profile in WHM › EasyApache 4 so you can go back.
  2. Move PHP to PHP-FPM first.
    In WHM › MultiPHP Manager, turn PHP-FPM on for the domains, or use whmapi1 convert_all_domains_to_fpm. Make sure no site depends on the DSO handler.
  3. Customize the profile.
    In WHM › EasyApache 4, click Customize on the current profile. Under Apache Modules, remove mod_ruid2 and make sure mod_suexec is selected.
  4. Choose the MPM.
    mod_ruid2 needed the prefork MPM. With PHP-FPM you can switch to mpm_event, which uses less memory under load.
  5. Review and provision.
    Check the list of changes, then provision. EasyApache rebuilds and restarts Apache.
  6. Clear the old data.
    Stop Apache briefly, move the old files out of /var/cpanel/secdatadir, and start it again so ModSecurity creates fresh files with the right owner.
  7. Watch the log.
    Run tail -f /etc/apache2/logs/error_log while you load a few sites, and confirm the collections_remove_stale lines no longer appear.

After the change, test sites that used to rely on per-user Apache processes, such as scripts that write files. Under PHP-FPM, PHP still runs as the account user, so file ownership inside home folders is unchanged.

6. Prevent it happening again

  • Check module compatibility before installing anything in EasyApache 4, especially modules that change which user Apache runs as.
  • Keep cPanel and EasyApache 4 updated, and read cPanel's deprecation notices; deprecated modules disappear in later versions.
  • Know what your ruleset needs. If your ModSecurity rules don't use persistent collections, you may not need SecDataDir activity at all. Check your ruleset's documentation before changing directives.
  • Test on a staging server where you can, and keep the saved EasyApache profile until you are sure.

For ModSecurity logs, directives and tuning on a server you manage, see the comprehensive guide to ModSecurity.

7. Where Domain India fits

Our shared hosting runs ModSecurity server-wide, managed by us, so you get the protection without maintaining modules or data folders. If you need to configure Apache and ModSecurity yourself, a VPS gives you root access; it is self-managed, and you install the software stack you want.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details
VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details
What does "collections_remove_stale: Failed to access DBM file" mean?

ModSecurity could not read or clean up one of the files where it stores data between requests, in the folder set by SecDataDir. On cPanel servers it is usually caused by mod_ruid2, which makes Apache processes run as different users.

I host on Domain India shared hosting. Do I need to fix this?

No. ModSecurity and Apache's modules are managed by us for the whole server, and customers can't change them. If a legitimate action on your site returns a 403, open a ticket with the URL, the exact time and your public IP address.

Can I turn off ModSecurity for my site on shared hosting?

No. ModSecurity runs for the whole server and can't be switched off per domain, and ModSecurity lines in .htaccess give a 500 error. Support can review a rule that blocks a legitimate request.

Why does changing the folder permissions only fix it for a while?

With mod_ruid2, each Apache process runs as the account it is serving, so new files keep getting different owners. The error returns as soon as a process for another account touches them. Removing mod_ruid2 fixes the cause.

What replaces mod_ruid2 on a cPanel server?

PHP-FPM, with each domain's pool running as the account user, plus mod_suexec for CGI scripts. Apache then runs as one user, and you can use the mpm_event MPM.

Is mod_ruid2 still available in EasyApache 4?

cPanel has deprecated mod_ruid2, and current EasyApache 4 builds on AlmaLinux, Rocky Linux and CloudLinux 8 and later don't offer it. Servers still using it should move to PHP-FPM.

Ready to get a blocked action working? Collect the URL, the time and your IP address and open a support ticket. Running your own server instead? Compare VPS plans.

Blocked by the firewall on your site?

Send us the URL, the exact time and your public IP address, and we will find the rule and help you get it working.

Open a ticket

Ready when you are

Get cPanel hosting from ₹125/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
ModSecurity SecDataDir Permission Denied Fix | Domain India