Cyber Security · मराठी आवृत्ती
Apache VirtualHost config समजून घ्या
या page मध्ये
Apache मध्ये directives साधारण एका line वर लिहितात; Nginx सारखा semicolon नाही. Sections angle brackets मध्ये असतात.
# /etc/httpd/conf.d/mysite.conf (Ubuntu: /etc/apache2/sites-available/mysite.conf)
<VirtualHost *:80>
ServerName example.com
ServerAlias www.example.com
ServerAdmin webmaster@example.com
DocumentRoot /var/www/mysite
DirectoryIndex index.html index.php
<Directory /var/www/mysite>
Options -Indexes +FollowSymLinks
AllowOverride All
Require all granted
</Directory>
ErrorDocument 404 /404.html
ErrorLog /var/log/httpd/mysite_error.log
CustomLog /var/log/httpd/mysite_access.log combined
</VirtualHost>
Ubuntu वर example logs साठी ${APACHE_LOG_DIR}/mysite_error.log सारखा path वापरतात; साधारण /var/log/apache2 कडे जातो. Amazon Linux example मध्ये /var/log/httpd आहे.
| Directive | काय काम करतं? |
|---|---|
<VirtualHost *:80> |
Port 80 साठी VirtualHost; Listen configuration सुद्धा लागते |
ServerName / ServerAlias |
मुख्य hostname / अतिरिक्त नावं |
DocumentRoot |
URL साठी document root folder |
DirectoryIndex |
Directory request साठी file |
<Directory path> |
Disk वरच्या folder चे rules |
Options -Indexes |
Automatic directory listing बंद |
AllowOverride All |
.htaccess overrides allow; app ला आवश्यक scope द्या |
Require all granted |
या context मध्ये सर्व requests allow (Apache 2.4) |
ErrorLog / CustomLog |
प्रत्येक site च्या वेगळ्या logs |
Listen |
Apache bind करणारे ports (httpd.conf/ports.conf) |
ServerTokens Prod + ServerSignature Off |
Version details कमी करा |
ServerName/ServerAlias site ची नावं; DocumentRoot disk वर content folder; DirectoryIndex directory request साठी file. Directory section disk path चे access/options ठरवतो. Options -Indexes automatic listing बंद करतो. AllowOverride All .htaccess मधल्या allowed configuration categories वापरू देतो; app ला गरज असेल तेवढंच allow करा. Require all granted त्या context मध्ये requests allow करतो; पूर्ण site ची सर्व security आपोआप ठरत नाही.
Listen server कोणत्या endpoints वर bind होतो ते सांगतो. फक्त VirtualHost *:80 लिहिल्याने missing Listen directive ची जागा भरत नाही. ServerTokens Prod आणि ServerSignature Off अनावश्यक version details कमी करतात.
Inline comments टाळा
Require all granted # allow all अशी trailing comment चुकीची parse होऊ शकते. Comment स्वतंत्र line वर # ने सुरू करा.
Default VirtualHost कसा ठरतो?
त्या IP:port च्या VirtualHosts मध्ये Host शी ServerName/ServerAlias match करतात. Match नसेल तर त्या group मधला पहिला VirtualHost fallback असतो. सामान्य wildcard include मध्ये config files alphabetical order ने load होतात, म्हणून Ubuntu मध्ये 000-default.conf नाव उपयोगी पडतं. Actual order पाहण्यासाठी sudo apachectl -S किंवा Ubuntu वर sudo apache2ctl -S वापरा:
*:80 is a NameVirtualHost
default server example.com (/etc/httpd/conf.d/mysite.conf:1)
port 80 namevhost example.com (/etc/httpd/conf.d/mysite.conf:1)
alias www.example.com
Security मध्ये उपयोग
Indexes enabled आणि index file नसल्यास directory मधल्या file names दिसू शकतात. Backups/configs leak होऊ नयेत म्हणून listing बंद ठेवा आणि sensitive files web root बाहेर ठेवा. .htaccess permissions आणि override scope गरजेनुसार मर्यादित ठेवा.
Practice
आपल्या server वर योग्य apachectl -S/apache2ctl -S command वापरून port 80 चा default vhost आणि config path लिहा.