Exercise
Allow Users to Have Personal Web Pages Exercise
Task
Turn on Apache's UserDir feature on
workstation so student can
publish a page from ~/public_html, then
clear the two obstacles in the way: file permissions and
SELinux.
- Host
workstation- Prerequisite
- Set Up a Basic Web Server Exercise
- Personal page
http://localhost/~student/
-
Create a personal web page for the student user
mkdir ~/public_html vim ~/public_html/index.htmlAdd this line and save the file:
<h1>Hello from student's home directory</h1>cat ~/public_html/index.html -
Enable Apache's UserDir feature
Keep a copy of the original for the cleanup step. Apache loads only files that end in
.conf, so the copy is ignored.sudo cp /etc/httpd/conf.d/userdir.conf /etc/httpd/conf.d/userdir.conf.orig sudo vim /etc/httpd/conf.d/userdir.confComment out the
UserDir disabledline and uncomment theUserDir public_htmlline, so they read:#UserDir disabled UserDir public_htmlsudo systemctl restart httpd.service systemctl status httpd.service --no-pager -
Test the configuration
curl http://localhost/~student/ sudo ls /var/log/httpd sudo less /var/log/httpd/error_logPress
Gto jump to the end of the log, thenqto quit.ls -ld ~ -
Fix permissions (DAC)
chmod 711 ~ ls -ld ~ ls -ld ~/public_html -
Test again to observe a different failure
curl http://localhost/~student/Still
403 Forbidden, but this time SELinux is the reason. -
Troubleshoot with sealert and getsebool
sudo sealert -a /var/log/audit/audit.log | lessType
/home/studentand press Enter to find the alert, then pressqto quit.getsebool httpd_enable_homedirs -
Turn on the SELinux boolean (MAC)
sudo setsebool -P httpd_enable_homedirs on getsebool httpd_enable_homedirs-Pwrites the value to the policy so it survives a reboot. -
Verify the results
curl http://localhost/~student/You should see
<h1>Hello from student's home directory</h1>. -
Clean up
sudo setsebool -P httpd_enable_homedirs off chmod 700 ~ rm -rf ~/public_html sudo mv /etc/httpd/conf.d/userdir.conf.orig /etc/httpd/conf.d/userdir.conf sudo systemctl disable --now httpd.service sudo rm -f /var/www/html/index.html sudo dnf remove -y httpd