Exercise
Configure a New DocumentRoot for Apache on servera Exercise
Task
Repeat the DocumentRoot workflow on
servera, which starts without a web server:
install Apache, serve /website, and make
SELinux allow it.
- Host
servera- New DocumentRoot
/website
-
Install httpd and start its service
serverahas no web server yet.sudo dnf install -y httpd sudo systemctl enable --now httpd.service systemctl is-active httpd.service -
Make a /website directory with an HTML file
sudo mkdir /website sudo vim /website/index.htmlAdd this line and save the file:
<h1>Welcome to /website</h1>ls -lZ /website/ -
Configure Apache to serve /website
Keep a copy of the original configuration for the cleanup step, then edit it.
sudo cp /etc/httpd/conf/httpd.conf /etc/httpd/conf/httpd.conf.orig sudo vim /etc/httpd/conf/httpd.confChange both occurrences of
/var/www/htmlto/website: theDocumentRootline and the<Directory>line that follows it. They should read:DocumentRoot "/website" <Directory "/website">sudo systemctl restart httpd.service systemctl status httpd.service --no-pager -
Test and troubleshoot with SELinux in permissive mode
curl http://localhost/ sudo setenforce 0 curl http://localhost/ sudo setenforce 1With SELinux enforcing, Apache cannot read the new page and answers with its test page instead. In permissive mode,
<h1>Welcome to /website</h1>loads. -
Troubleshoot with sealert
sudo dnf install -y setroubleshoot-server sudo sealert -a /var/log/audit/audit.log | lessType
/website/index.htmland press Enter to find the alert, then pressqto quit. -
Configure a policy for /website
sudo semanage fcontext -a -t httpd_sys_content_t '/website(/.*)?' sudo semanage fcontext -l -C-l -Clists only your local customizations. The rule changes the policy, not the files. -
Apply the policy to the files
sudo restorecon -Rv /website ls -lZ /website/ -
Verify the results
getenforce curl http://localhost/With SELinux enforcing, you should see
<h1>Welcome to /website</h1>. -
Clean up
sudo mv /etc/httpd/conf/httpd.conf.orig /etc/httpd/conf/httpd.conf sudo semanage fcontext -d '/website(/.*)?' sudo rm -rf /website sudo systemctl disable --now httpd.service sudo dnf remove -y httpd setroubleshoot-server