Exercise

Allow Users to Have Personal Web Pages Exercise

Task

Turn on Apache's UserDir feature on workstation so student can publish a page from ~/public_html, then clear the two obstacles in the way: file permissions and SELinux.

Host
workstation
Prerequisite
Set Up a Basic Web Server Exercise
Personal page
http://localhost/~student/
  1. Create a personal web page for the student user

    mkdir ~/public_html
    vim ~/public_html/index.html

    Add this line and save the file:

    <h1>Hello from student's home directory</h1>
    cat ~/public_html/index.html
  2. Enable Apache's UserDir feature

    Keep a copy of the original for the cleanup step. Apache loads only files that end in .conf, so the copy is ignored.

    sudo cp /etc/httpd/conf.d/userdir.conf /etc/httpd/conf.d/userdir.conf.orig
    sudo vim /etc/httpd/conf.d/userdir.conf

    Comment out the UserDir disabled line and uncomment the UserDir public_html line, so they read:

        #UserDir disabled
        UserDir public_html
    sudo systemctl restart httpd.service
    systemctl status httpd.service --no-pager
  3. Test the configuration

    curl http://localhost/~student/
    sudo ls /var/log/httpd
    sudo less /var/log/httpd/error_log

    Press G to jump to the end of the log, then q to quit.

    ls -ld ~
  4. Fix permissions (DAC)

    chmod 711 ~
    ls -ld ~
    ls -ld ~/public_html
  5. Test again to observe a different failure

    curl http://localhost/~student/

    Still 403 Forbidden, but this time SELinux is the reason.

  6. Troubleshoot with sealert and getsebool

    sudo sealert -a /var/log/audit/audit.log | less

    Type /home/student and press Enter to find the alert, then press q to quit.

    getsebool httpd_enable_homedirs
  7. Turn on the SELinux boolean (MAC)

    sudo setsebool -P httpd_enable_homedirs on
    getsebool httpd_enable_homedirs

    -P writes the value to the policy so it survives a reboot.

  8. Verify the results

    curl http://localhost/~student/

    You should see <h1>Hello from student's home directory</h1>.

  9. Clean up

    sudo setsebool -P httpd_enable_homedirs off
    chmod 700 ~
    rm -rf ~/public_html
    sudo mv /etc/httpd/conf.d/userdir.conf.orig /etc/httpd/conf.d/userdir.conf
    sudo systemctl disable --now httpd.service
    sudo rm -f /var/www/html/index.html
    sudo dnf remove -y httpd