Exercise

Add New Web Page Exercise

Task

A developer wants about.html added to the web site on workstation. Move their file into place, find out why Apache refuses to serve it, and confirm that SELinux is the cause.

Host
workstation
Prerequisite
Set Up a Basic Web Server Exercise
Simulated hand-off
/tmp/about.html
  1. Simulate the developer handing over the file

    Create /tmp/about.html with this line, then check its label.

    vim /tmp/about.html
    <h1>About Us</h1>
    ls -lZ /tmp/about.html
  2. Move the page into the DocumentRoot

    sudo mv /tmp/about.html /var/www/html/
    ls -lZ /var/www/html/
  3. Attempt to access the page

    curl http://localhost/about.html

    Apache answers 403 Forbidden.

  4. Switch SELinux to permissive temporarily

    sudo setenforce 0
    getenforce
    curl http://localhost/about.html
    sudo setenforce 1
    getenforce

    In permissive mode the page loads, so SELinux is what blocked it.

  5. View the audit log

    sudo less /var/log/audit/audit.log

    Type /about.html and press Enter to search, then press q to quit.

  6. Use sealert

    sudo dnf install setroubleshoot-server -y
    sudo sealert -a /var/log/audit/audit.log | less

    Read the report, then press q to quit.