Exercise

Configure a New DocumentRoot for Apache Exercise

Task

Serve the web site on workstation from /web, find out why SELinux blocks it, and add a file context policy so it works with SELinux enforcing.

Host
workstation
Prerequisite
Set Up a Basic Web Server Exercise
New DocumentRoot
/web
  1. Make a /web directory with an HTML file

    sudo mkdir /web
    sudo vim /web/index.html

    Add this line and save the file:

    <h1>Welcome to /web</h1>
    ls -lZ /web/
  2. Configure Apache to serve /web

    Keep a copy of the original configuration for the cleanup step, then edit it.

    sudo cp /etc/httpd/conf/httpd.conf /etc/httpd/conf/httpd.conf.orig
    sudo vim /etc/httpd/conf/httpd.conf

    Change both occurrences of /var/www/html to /web: the DocumentRoot line and the <Directory> line that follows it. They should read:

    DocumentRoot "/web"
    <Directory "/web">
    sudo systemctl restart httpd.service
    systemctl status httpd.service --no-pager
  3. Test and troubleshoot with SELinux in permissive mode

    curl http://localhost/
    sudo setenforce 0
    curl http://localhost/
    sudo setenforce 1

    With SELinux enforcing, Apache cannot read the new page and answers with its test page instead. In permissive mode, <h1>Welcome to /web</h1> loads.

  4. Troubleshoot with sealert

    sudo sealert -a /var/log/audit/audit.log | less

    Type /web/index.html and press Enter to find the alert, then press q to quit.

  5. Configure a policy for /web

    sudo semanage fcontext -a -t httpd_sys_content_t '/web(/.*)?'
    sudo semanage fcontext -l -C

    -l -C lists only your local customizations. The rule changes the policy, not the files.

  6. Apply the policy to the files

    sudo restorecon -Rv /web
    ls -lZ /web/
  7. Verify the results

    getenforce
    curl http://localhost/

    With SELinux enforcing, you should see <h1>Welcome to /web</h1>.

  8. Clean up

    sudo mv /etc/httpd/conf/httpd.conf.orig /etc/httpd/conf/httpd.conf
    sudo systemctl restart httpd.service
    sudo semanage fcontext -d '/web(/.*)?'
    sudo rm -rf /web
    curl http://localhost/

    Apache serves <h1>Welcome to Workstation</h1> from its default DocumentRoot again.