Ravindra Bagale · Cyber Securityसर्व coursesया course चे lessonsशोधाEnglish

Cyber Security · मराठी आवृत्ती

Apache VirtualHost config समजून घ्या

रवींद्र बागले यांच्या course वर आधारित · सहज मराठीत explanation

या page मध्ये

Apache मध्ये directives साधारण एका line वर लिहितात; Nginx सारखा semicolon नाही. Sections angle brackets मध्ये असतात.

# /etc/httpd/conf.d/mysite.conf   (Ubuntu: /etc/apache2/sites-available/mysite.conf)
<VirtualHost *:80>
    ServerName  example.com
    ServerAlias www.example.com
    ServerAdmin webmaster@example.com

    DocumentRoot /var/www/mysite
    DirectoryIndex index.html index.php

    <Directory /var/www/mysite>
        Options -Indexes +FollowSymLinks
        AllowOverride All
        Require all granted
    </Directory>

    ErrorDocument 404 /404.html
    ErrorLog  /var/log/httpd/mysite_error.log
    CustomLog /var/log/httpd/mysite_access.log combined
</VirtualHost>

Ubuntu वर example logs साठी ${APACHE_LOG_DIR}/mysite_error.log सारखा path वापरतात; साधारण /var/log/apache2 कडे जातो. Amazon Linux example मध्ये /var/log/httpd आहे.

Directive काय काम करतं?
<VirtualHost *:80> Port 80 साठी VirtualHost; Listen configuration सुद्धा लागते
ServerName / ServerAlias मुख्य hostname / अतिरिक्त नावं
DocumentRoot URL साठी document root folder
DirectoryIndex Directory request साठी file
<Directory path> Disk वरच्या folder चे rules
Options -Indexes Automatic directory listing बंद
AllowOverride All .htaccess overrides allow; app ला आवश्यक scope द्या
Require all granted या context मध्ये सर्व requests allow (Apache 2.4)
ErrorLog / CustomLog प्रत्येक site च्या वेगळ्या logs
Listen Apache bind करणारे ports (httpd.conf/ports.conf)
ServerTokens Prod + ServerSignature Off Version details कमी करा

ServerName/ServerAlias site ची नावं; DocumentRoot disk वर content folder; DirectoryIndex directory request साठी file. Directory section disk path चे access/options ठरवतो. Options -Indexes automatic listing बंद करतो. AllowOverride All .htaccess मधल्या allowed configuration categories वापरू देतो; app ला गरज असेल तेवढंच allow करा. Require all granted त्या context मध्ये requests allow करतो; पूर्ण site ची सर्व security आपोआप ठरत नाही.

Listen server कोणत्या endpoints वर bind होतो ते सांगतो. फक्त VirtualHost *:80 लिहिल्याने missing Listen directive ची जागा भरत नाही. ServerTokens Prod आणि ServerSignature Off अनावश्यक version details कमी करतात.

Inline comments टाळा

Require all granted # allow all अशी trailing comment चुकीची parse होऊ शकते. Comment स्वतंत्र line वर # ने सुरू करा.

Default VirtualHost कसा ठरतो?

त्या IP:port च्या VirtualHosts मध्ये Host शी ServerName/ServerAlias match करतात. Match नसेल तर त्या group मधला पहिला VirtualHost fallback असतो. सामान्य wildcard include मध्ये config files alphabetical order ने load होतात, म्हणून Ubuntu मध्ये 000-default.conf नाव उपयोगी पडतं. Actual order पाहण्यासाठी sudo apachectl -S किंवा Ubuntu वर sudo apache2ctl -S वापरा:

*:80   is a NameVirtualHost
       default server example.com (/etc/httpd/conf.d/mysite.conf:1)
       port 80 namevhost example.com (/etc/httpd/conf.d/mysite.conf:1)
               alias www.example.com

Security मध्ये उपयोग

Indexes enabled आणि index file नसल्यास directory मधल्या file names दिसू शकतात. Backups/configs leak होऊ नयेत म्हणून listing बंद ठेवा आणि sensitive files web root बाहेर ठेवा. .htaccess permissions आणि override scope गरजेनुसार मर्यादित ठेवा.

Practice

आपल्या server वर योग्य apachectl -S/apache2ctl -S command वापरून port 80 चा default vhost आणि config path लिहा.