Exercise
Configure Apache to Listen on 8888 Exercise
Task
Move the web server on servera off port 80
and onto port 8888, open that port in the firewall, then
find out why httpd refuses to start.
- Host
-
servera, fromworkstation - Prerequisite
- Allow HTTP Traffic
-
Allow 8888/tcp in the firewall
ssh student@servera sudo firewall-cmd --add-port=8888/tcp --permanent sudo firewall-cmd --reload sudo firewall-cmd --list-allThe zone now reports
ports: 8888/tcpalongside its services. This is the other order from the last exercise: write the permanent configuration, then--reloadto put it into effect. -
Point Apache's Listen line at 8888
sudo vim /etc/httpd/conf/httpd.confSearch for the line with
/^Listen 80and press Enter. Press C to change the rest of the line, typeListen 8888, press Esc, then write the file with:wq.grep ^Listen /etc/httpd/conf/httpd.confThe file should now show
Listen 8888and nothing else on that line. -
Restart httpd and watch it fail
sudo systemctl restart httpd.service systemctl status httpd.service --no-pagerThe restart reports
Job for httpd.service failed because the control process exited with error code, and the status output names the reason:(13)Permission denied: AH00072: make_sock: could not bind to address 0.0.0.0:8888 no listening sockets available, shutting downThe firewall is open and no other process holds 8888, so neither of those is the problem. Something denied Apache permission to use the port.
-
Confirm SELinux is the cause
sudo setenforce 0 sudo systemctl restart httpd.service systemctl is-active httpd.serviceThe service reports
activethe moment SELinux stops enforcing, which names the culprit. Put the host back before going on:sudo systemctl stop httpd.service sudo setenforce 1 -
Read what sealert recommends
sudo dnf install -y setroubleshoot-server sudo systemctl restart httpd.serviceWith
setroubleshoot-serverinstalled, the restart fails again and leaves a fresh denial to analyze. Read the report the same way you did in week 6:sudo sealert -a /var/log/audit/audit.log | lessSearch for
/port 8888to jump to the alert, which readsSELinux is preventing /usr/sbin/httpd from name_bind access on the tcp_socket port 8888, then press q to leave the pager. The first suggestion is the one that matters:If you want to allow /usr/sbin/httpd to bind to network port 8888 Then you need to modify the port type. Do # semanage port -a -t PORT_TYPE -p tcp 8888 where PORT_TYPE is one of the following: http_cache_port_t, http_port_t, ...That command is the next exercise. Leave
httpdstopped and the firewall as it is; the next exercise starts from here.