computers:apache_server_configuration
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| computers:apache_server_configuration [2018/12/14 02:52] – [HTTPS/SSL] chkuo | computers:apache_server_configuration [2022/11/02 16:04] (current) – chkuo | ||
|---|---|---|---|
| Line 19: | Line 19: | ||
| ===== Configuration ===== | ===== Configuration ===== | ||
| - | |||
| * the configuration file is: ''/ | * the configuration file is: ''/ | ||
| + | * Directory listing | ||
| + | * To disable directory listing | ||
| + | * add '' | ||
| + | * To enable directory listing in a specific directory | ||
| + | * add a '' | ||
| + | * Within the '' | ||
| + | * Sample configuration: | ||
| + | |||
| <file 000-default.conf> | <file 000-default.conf> | ||
| Line 86: | Line 93: | ||
| </ | </ | ||
| - | ===== HTTPS/ | + | ===== Update |
| - | * Use [[https:// | + | |
| - | * install: | + | |
| <code bash> | <code bash> | ||
| - | $ sudo apt-get | + | # for Ubuntu 20.04.5 LTS; 2022/ |
| - | $ sudo apt-get install software-properties-common | + | # to update |
| - | $ sudo add-apt-repository universe | + | $ apache2 |
| - | $ sudo add-apt-repository ppa:certbot/certbot | + | Server version: Apache/ |
| - | $ sudo apt-get update | + | Server built: |
| - | $ sudo apt-get install | + | $ sudo add-apt-repository ppa:ondrej/apache2 |
| + | $ sudo apt update | ||
| + | $ sudo apt install | ||
| + | $ apache2 | ||
| + | Server version: Apache/ | ||
| + | Server built: | ||
| + | $ systemctl status apache2 | ||
| + | $ sudo systemctl start apache2 | ||
| + | $ sudo systemctl enable apache2 | ||
| </ | </ | ||
| - | * modify ''/ | ||
| - | < | ||
| - | ServerName example.com | ||
| - | ServerAdmin admin@example.com | ||
| - | </ | ||
| - | * execute | ||
| - | <code bash> | ||
| - | $ sudo certbot --apache | ||
| - | </ | ||
| - | |||
| - | |||
| - | |||
| - | |||
| - | ==== Directory listing ==== | ||
| - | * disable directory listing by specifying '' | ||
| - | * to enable directory listing in a specific directory, add a '' | ||
| - | ==== Password protection ==== | + | ===== Password protection |
| Inside the directory to be protected, add a '' | Inside the directory to be protected, add a '' | ||
| <code bash> | <code bash> | ||
| Line 132: | Line 130: | ||
| + | ===== HTTPS/SSL ===== | ||
| + | * Use [[https:// | ||
| + | * install: | ||
| + | <code bash> | ||
| + | # require snapd; pre-installed on Ubuntu 20.04 | ||
| + | # remove the pre-installed cerbot (if present) | ||
| + | $ sudo apt remove certbot | ||
| + | # install certbot using snap | ||
| + | $ sudo snap install --classic certbot | ||
| + | # get a certificate; | ||
| + | # (1) get a certificate without changing the Apache configuration | ||
| + | $ sudo certbot certonly --apache | ||
| + | # (2) get a certificate and have certbot edit the Apache configuration | ||
| + | $ sudo certbot --apache | ||
| + | # | ||
| + | # check status | ||
| + | $ sudo systemctl status certbot.timer | ||
| + | # test renewal | ||
| + | $ sudo certbot renew --dry-run | ||
| + | # manual renewal; not recommended | ||
| + | # better to put '/ | ||
| + | $ sudo certbot renew | ||
| + | # enable ssl | ||
| + | $ sudo a2enmod ssl | ||
| + | </ | ||
| + | * modify ''/ | ||
| + | < | ||
| + | ServerName example.com | ||
| + | ServerAdmin admin@example.com | ||
| + | </ | ||
| + | * SSL test: [[https:// | ||
| ===== PHP ===== | ===== PHP ===== | ||
| ==== Info ==== | ==== Info ==== | ||
| Line 174: | Line 202: | ||
| ==== Permissions ==== | ==== Permissions ==== | ||
| - | Make the permissions more restrictive for security reasons. Assuming the wiki is installed in ''/ | + | Make the permissions more restrictive for security reasons. Assuming |
| <code bash> | <code bash> | ||
| # change the ownership | # change the ownership | ||
| - | sudo chown -R www-data:admin / | + | sudo chown -R www-data:adm / |
| # restrict access by other | # restrict access by other | ||
| sudo chmod -R o-rwx / | sudo chmod -R o-rwx / | ||
| Line 200: | Line 228: | ||
| sudo mkdir -p / | sudo mkdir -p / | ||
| # change ownership | # change ownership | ||
| - | sudo chown -R www-data:admin / | + | sudo chown -R www-data:adm / |
| # configure the virtual host For WebDAV | # configure the virtual host For WebDAV | ||
| # create the WebDAV password file with the user test | # create the WebDAV password file with the user test | ||
| Line 206: | Line 234: | ||
| sudo htpasswd -c / | sudo htpasswd -c / | ||
| # change the ownership and permissions | # change the ownership and permissions | ||
| - | sudo chown www-data:admin / | + | sudo chown www-data:adm / |
| sudo chmod 640 / | sudo chmod 640 / | ||
| # backup the vhost configuration | # backup the vhost configuration | ||
| Line 241: | Line 269: | ||
| ==== References ==== | ==== References ==== | ||
| + | * [[https:// | ||
| * [[https:// | * [[https:// | ||
computers/apache_server_configuration.1544727171.txt.gz · Last modified: by chkuo