Exercise

Configure a New DocumentRoot for Apache on servera Exercise

Task

Repeat the DocumentRoot workflow on servera, which starts without a web server: install Apache, serve /website, and make SELinux allow it.

Host
servera
New DocumentRoot
/website
  1. Install httpd and start its service

    servera has no web server yet.

    sudo dnf install -y httpd
    sudo systemctl enable --now httpd.service
    systemctl is-active httpd.service
  2. Make a /website directory with an HTML file

    sudo mkdir /website
    sudo vim /website/index.html

    Add this line and save the file:

    <h1>Welcome to /website</h1>
    ls -lZ /website/
  3. Configure Apache to serve /website

    Keep a copy of the original configuration for the cleanup step, then edit it.

    sudo cp /etc/httpd/conf/httpd.conf /etc/httpd/conf/httpd.conf.orig
    sudo vim /etc/httpd/conf/httpd.conf

    Change both occurrences of /var/www/html to /website: the DocumentRoot line and the <Directory> line that follows it. They should read:

    DocumentRoot "/website"
    <Directory "/website">
    sudo systemctl restart httpd.service
    systemctl status httpd.service --no-pager
  4. Test and troubleshoot with SELinux in permissive mode

    curl http://localhost/
    sudo setenforce 0
    curl http://localhost/
    sudo setenforce 1

    With SELinux enforcing, Apache cannot read the new page and answers with its test page instead. In permissive mode, <h1>Welcome to /website</h1> loads.

  5. Troubleshoot with sealert

    sudo dnf install -y setroubleshoot-server
    sudo sealert -a /var/log/audit/audit.log | less

    Type /website/index.html and press Enter to find the alert, then press q to quit.

  6. Configure a policy for /website

    sudo semanage fcontext -a -t httpd_sys_content_t '/website(/.*)?'
    sudo semanage fcontext -l -C

    -l -C lists only your local customizations. The rule changes the policy, not the files.

  7. Apply the policy to the files

    sudo restorecon -Rv /website
    ls -lZ /website/
  8. Verify the results

    getenforce
    curl http://localhost/

    With SELinux enforcing, you should see <h1>Welcome to /website</h1>.

  9. Clean up

    sudo mv /etc/httpd/conf/httpd.conf.orig /etc/httpd/conf/httpd.conf
    sudo semanage fcontext -d '/website(/.*)?'
    sudo rm -rf /website
    sudo systemctl disable --now httpd.service
    sudo dnf remove -y httpd setroubleshoot-server