Exercise
Configure a New DocumentRoot for Apache Exercise
Task
Serve the web site on workstation from
/web, find out why SELinux blocks it, and
add a file context policy so it works with SELinux
enforcing.
- Host
workstation- Prerequisite
- Set Up a Basic Web Server Exercise
- New DocumentRoot
/web
-
Make a /web directory with an HTML file
sudo mkdir /web sudo vim /web/index.htmlAdd this line and save the file:
<h1>Welcome to /web</h1>ls -lZ /web/ -
Configure Apache to serve /web
Keep a copy of the original configuration for the cleanup step, then edit it.
sudo cp /etc/httpd/conf/httpd.conf /etc/httpd/conf/httpd.conf.orig sudo vim /etc/httpd/conf/httpd.confChange both occurrences of
/var/www/htmlto/web: theDocumentRootline and the<Directory>line that follows it. They should read:DocumentRoot "/web" <Directory "/web">sudo systemctl restart httpd.service systemctl status httpd.service --no-pager -
Test and troubleshoot with SELinux in permissive mode
curl http://localhost/ sudo setenforce 0 curl http://localhost/ sudo setenforce 1With SELinux enforcing, Apache cannot read the new page and answers with its test page instead. In permissive mode,
<h1>Welcome to /web</h1>loads. -
Troubleshoot with sealert
sudo sealert -a /var/log/audit/audit.log | lessType
/web/index.htmland press Enter to find the alert, then pressqto quit. -
Configure a policy for /web
sudo semanage fcontext -a -t httpd_sys_content_t '/web(/.*)?' sudo semanage fcontext -l -C-l -Clists only your local customizations. The rule changes the policy, not the files. -
Apply the policy to the files
sudo restorecon -Rv /web ls -lZ /web/ -
Verify the results
getenforce curl http://localhost/With SELinux enforcing, you should see
<h1>Welcome to /web</h1>. -
Clean up
sudo mv /etc/httpd/conf/httpd.conf.orig /etc/httpd/conf/httpd.conf sudo systemctl restart httpd.service sudo semanage fcontext -d '/web(/.*)?' sudo rm -rf /web curl http://localhost/Apache serves
<h1>Welcome to Workstation</h1>from its default DocumentRoot again.