Exercise
Configure SELinux to Allow HTTP on 8888 Exercise
Task
Give port 8888 a label httpd is allowed to
bind to, start the web server, read the page from
workstation, then return
servera to the state it started the week
in.
- Host
-
servera, fromworkstation - Prerequisite
- Configure Apache to Listen on 8888
-
Inspect the ports httpd may bind to
ssh student@servera sudo semanage port -l | grep ^httphttp_cache_port_t tcp 8080, 8118, 8123, 10001-10010 http_cache_port_t udp 3130 http_port_t tcp 80, 81, 443, 488, 8008, 8009, 8443, 90008888 is on none of those lines, which is exactly what the denial said. Port 80 is there, which is why the server ran before you moved it.
-
Label 8888 with http_port_t
sudo semanage port -a -t http_port_t -p tcp 8888 sudo semanage port -l | grep ^http8888 now appears on the
http_port_tline. List your own changes on their own:sudo semanage port -l -C -
Start httpd and request the page from workstation
sudo systemctl start httpd.service systemctl is-active httpd.serviceApache binds 8888 and reports
active. Leave the server and ask for the page across the network:exit curl http://servera:8888The page arrives:
<h1>Welcome to servera</h1>. Three things had to be true at once: the firewall allows the port, SELinux labels the port, and Apache listens on it. -
Put servera back the way you found it
ssh student@servera sudo systemctl disable --now httpd.service sudo semanage port -d -t http_port_t -p tcp 8888 sudo firewall-cmd --permanent --remove-port=8888/tcp sudo firewall-cmd --permanent --remove-service=http sudo firewall-cmd --reloadThen undo the edit from the previous exercise, so the package removal leaves nothing behind in
/etc/httpd:sudo vim /etc/httpd/conf/httpd.confSearch with
/^Listen 8888, press C, typeListen 80, press Esc, and save with:wq. Then remove what you installed:sudo dnf remove -y httpd setroubleshoot-server sudo rm -f /var/www/html/index.htmlserveraends the week the way it started: no web server, no local port label, and a firewall allowingcockpit,dhcpv6-client, andssh.