Exercise

Configure SELinux to Allow HTTP on 8888 Exercise

Task

Give port 8888 a label httpd is allowed to bind to, start the web server, read the page from workstation, then return servera to the state it started the week in.

Host
servera, from workstation
Prerequisite
Configure Apache to Listen on 8888
  1. Inspect the ports httpd may bind to

    ssh student@servera
    sudo semanage port -l | grep ^http
    http_cache_port_t              tcp      8080, 8118, 8123, 10001-10010
    http_cache_port_t              udp      3130
    http_port_t                    tcp      80, 81, 443, 488, 8008, 8009, 8443, 9000

    8888 is on none of those lines, which is exactly what the denial said. Port 80 is there, which is why the server ran before you moved it.

  2. Label 8888 with http_port_t

    sudo semanage port -a -t http_port_t -p tcp 8888
    sudo semanage port -l | grep ^http

    8888 now appears on the http_port_t line. List your own changes on their own:

    sudo semanage port -l -C
  3. Start httpd and request the page from workstation

    sudo systemctl start httpd.service
    systemctl is-active httpd.service

    Apache binds 8888 and reports active. Leave the server and ask for the page across the network:

    exit
    curl http://servera:8888

    The page arrives: <h1>Welcome to servera</h1>. Three things had to be true at once: the firewall allows the port, SELinux labels the port, and Apache listens on it.

  4. Put servera back the way you found it

    ssh student@servera
    sudo systemctl disable --now httpd.service
    sudo semanage port -d -t http_port_t -p tcp 8888
    sudo firewall-cmd --permanent --remove-port=8888/tcp
    sudo firewall-cmd --permanent --remove-service=http
    sudo firewall-cmd --reload

    Then undo the edit from the previous exercise, so the package removal leaves nothing behind in /etc/httpd:

    sudo vim /etc/httpd/conf/httpd.conf

    Search with /^Listen 8888, press C, type Listen 80, press Esc, and save with :wq. Then remove what you installed:

    sudo dnf remove -y httpd setroubleshoot-server
    sudo rm -f /var/www/html/index.html

    servera ends the week the way it started: no web server, no local port label, and a firewall allowing cockpit, dhcpv6-client, and ssh.