Exercise

Configure Apache to Listen on 8888 Exercise

Task

Move the web server on servera off port 80 and onto port 8888, open that port in the firewall, then find out why httpd refuses to start.

Host
servera, from workstation
Prerequisite
Allow HTTP Traffic
  1. Allow 8888/tcp in the firewall

    ssh student@servera
    sudo firewall-cmd --add-port=8888/tcp --permanent
    sudo firewall-cmd --reload
    sudo firewall-cmd --list-all

    The zone now reports ports: 8888/tcp alongside its services. This is the other order from the last exercise: write the permanent configuration, then --reload to put it into effect.

  2. Point Apache's Listen line at 8888

    sudo vim /etc/httpd/conf/httpd.conf

    Search for the line with /^Listen 80 and press Enter. Press C to change the rest of the line, type Listen 8888, press Esc, then write the file with :wq.

    grep ^Listen /etc/httpd/conf/httpd.conf

    The file should now show Listen 8888 and nothing else on that line.

  3. Restart httpd and watch it fail

    sudo systemctl restart httpd.service
    systemctl status httpd.service --no-pager

    The restart reports Job for httpd.service failed because the control process exited with error code, and the status output names the reason:

    (13)Permission denied: AH00072: make_sock: could not bind to address 0.0.0.0:8888
    no listening sockets available, shutting down

    The firewall is open and no other process holds 8888, so neither of those is the problem. Something denied Apache permission to use the port.

  4. Confirm SELinux is the cause

    sudo setenforce 0
    sudo systemctl restart httpd.service
    systemctl is-active httpd.service

    The service reports active the moment SELinux stops enforcing, which names the culprit. Put the host back before going on:

    sudo systemctl stop httpd.service
    sudo setenforce 1
  5. Read what sealert recommends

    sudo dnf install -y setroubleshoot-server
    sudo systemctl restart httpd.service

    With setroubleshoot-server installed, the restart fails again and leaves a fresh denial to analyze. Read the report the same way you did in week 6:

    sudo sealert -a /var/log/audit/audit.log | less

    Search for /port 8888 to jump to the alert, which reads SELinux is preventing /usr/sbin/httpd from name_bind access on the tcp_socket port 8888, then press q to leave the pager. The first suggestion is the one that matters:

    If you want to allow /usr/sbin/httpd to bind to network port 8888
    Then you need to modify the port type.
    Do
    # semanage port -a -t PORT_TYPE -p tcp 8888
        where PORT_TYPE is one of the following: http_cache_port_t, http_port_t, ...

    That command is the next exercise. Leave httpd stopped and the firewall as it is; the next exercise starts from here.