顯示具有 apache 標籤的文章。 顯示所有文章
顯示具有 apache 標籤的文章。 顯示所有文章

2021年1月1日 星期五

[Apache] Updating http server to https

Background

No one will delay the importance of https, to secure the data transaction between client and server, however in the past when https is not very common in Internet, we developers suffer from registration cost of a certificate and complicated setup of Apache server. One of our client although not specifically request, needs https at all time of their official web site.


Solutions

Steps are not difficult nowadays to complete the https setup, here is my system setup. 

- A LAMP docker image (mattrayner/lamp:latest-1804) https://hub.docker.com/r/mattrayner/lamp which has already setup and work in production.

- Amazon lightsail service for hosting

- A valid hostname registered in hosting speed with full control of the domain name through the domain name panel

Steps

1. Register the SSL certificate (FREE) in letsencrypt (https://letsencrypt.org/) through lightsail web terminal or any ways you can think of accessing the virtual server. Install software-properties-common and certbot accordingly (Details refer to https://lightsail.aws.amazon.com/ls/docs/en_us/articles/amazon-lightsail-using-lets-encrypt-certificates-with-wordpress)

2. Specify the domain name and the wildcard in the environment variable, use certbot to request Let's Encrypt for the new certificate.

3. Use the following command to start certbot in interactive mode, follow the instruction to complete the registration.

sudo certbot -d $DOMAIN -d $WILDCARD --manual --preferred-challenges dns certonly

Note: There is a process where Let's Encrypt verifies the ownership of the domain, and you as the domain owner needs to add a TXT DNS record to complete the challenge. I am stucked at this as I wrongly follow the unclear instructions of Let's Encrypt's instruction. The TXT record required to fill in your DNS panel is _acme-challenge.example.com with a series of long string, but I wrongly put the whole address in the below table which caused failure of the challenges. It indeed needs only the first part "_acme-challenge" since the .goldenthumb.com.hk has already added for you during the DNS enquiry, so NO NEED to put the whole address to the name field of the DNS record panel.




4. Complete the challenges in the interactive shell and your certificate will be issued. Mark down the directory in which the certificates are stored

5. Update the docker-compose file volumes configuration so that volume is mapped to include the certificate files in the docker container, they will be used as https's certificate afterwards, at the same time, add 443:443 port mapping in ports configuration to allow correct functions of https

6. You can also map the path /etc/apache2/sites-available to local for easy access and configure the apache web server settings

7. Update the 000-default.conf to read the certificate files in step 5, the file sample is as follows

https://drive.google.com/file/d/1usQ9kHb38SyCxW8oqYT1fMAja1_Xj54S/view

The sample configuration includes pointing the certificate files, setting up 443 port based virtual server, redirecting all non https request permenantly to the https URL

8. Update the docker-compose file again, add build configuration and remove image configuration, because we are adding custom commands / scripts to the new yml file

9. Create a new dockerFile with source using the LAMP container (mattrayner/lamp:latest-1804), add the following custom commands in the dockerFile yml

- a2enmod ssl

- service apache2 restart

10. Navigate to lightsail management panel, open the port inbound for port 443 used in https

11. Stop the running containers, rebuild and make the containers up again, your server is now https protected


Certificate Renewal

1. Run "/usr/bin/certbot renew >> /var/log/certbot"

2. Reply the interactive terminal, provide emails, agree terms etc.

3. Add DNS record (TXT) for the challenges  






4. Create a file to accept the second challenge  





5. Restart the web server

Congrats, certificate renewed

References



2015年5月25日 星期一

Setup VCS Using Redmine + Git

We all know that Git is a very good VCS, with redmine, like Bugzilla, we have even better control and graphical view on our repository, and this is undoubtedly aid development. The following is how to make the whole VCS system happens.

What we need
1) Git (of course!)
2) Redmine
3) Apache Server

Procedure
1) Install all the necessary components respectively
sudo apt-get install apache2
sudo apt-get install mysql-server
sudo apt-get install redmine-mysql
sudo apt-get install libapache2-mod-passenger
sudo apt-get install redmine
sudo apt-get install git-core

2) Set up soft link from redmine source to the Apache source
sudo ln -s /usr/share/redmine/public /var/www/redmine

3) mod passenger needs www-data to execute, add the following to /etc/apache2/mods-available/passenger.conf
vi /etc/apache2/mods-available/passenger.conf
PassengerDefaultUser www-data

 4) Add redmine's web directory to Apache2's sites-available/default

                RailsBaseURI /redmine
                PassengerAppRoot /usr/share/redmine
                RailsEnv production
                PassengerResolveSymlinksInDocumentRoot on
5) Setup plugin linkage
 ln -s /var/cache/redmine/default/plugin_assets /usr/share/redmine/public/

6) Create new repository (server side), note that the directory should be with owner "www-data"
cd /var/www
mkdir test-repo.git
cd test-repo.git
git --bare init
git update-server-info
chown -R www-data.www-data .

 7) Enable webDAV
a2enmod dav_fs
a2enmod dav

If high security is required, carry on, if not, restart apache and all services will be done

8) Create the following file
/etc/apache2/conf.d/git.conf

9) Configure the repository path for authentication
        DAV on
        AuthType Basic
        AuthName "Git"
        AuthUserFile /etc/apache2/passwd.git
        Require valid-user

10) Create user which can access the repository
 htpasswd -c /etc/apache2/passwd.git

11) Restart Apache service
/etc/init.d/apache2 restart

Done! You have made a git VCS with redmine geared!

Almost forgot, modifying the config file in .git directory is necessary for authentication when pushing
[remote "origin"]
fetch = +refs/heads/*:refs/remotes/origin/*
url = http://username:password@git.repository.url/repo.git

References:
- Linking git remote server to Apache
http://blog.bobbyallen.me/2012/07/23/installing-a-git-server-using-apache-webdav-on-ubuntu-server-12-04/

- Installing Apache + Git + Redmine
http://blog.chiichen.com/2014/05/raspberry-pi-redmine.html

- Git config fix on http/https authentication
http://stackoverflow.com/questions/5264949/cannot-push-git-to-remote-repository-with-http-https

- Others
https://randomthoughtsgr.wordpress.com/2011/10/17/redmine-sub-uri-and-apache-configuration/

2015年1月7日 星期三

[Apache] Overriding .htacess Files in Server

Sometimes, we may want to control the download behavior  through http server, in this case, we often need to override the htaccess config file to achieve.


Scenario 1: No authentication is needed
1) Make .htacess file with the below content
  
   
     Allow from all
     Satisfy any
   

2) After that, put the file to the directory, the following is the result (hierarchy level)

downFolder
     yourFileName
    .htacess 

So everytime the user download the file, they will not be asked for password


Scenario 2: Authentication with Username and Password

1) Make .htacess file with the below content
  
    AuthType Basic
    AuthName "yourProtectedMsg"
    AuthUserFile pathOfYourHtapasswdFile
    Require user loginUsrName
  

2) After that, make a .htpasswd file from the following URL
http://www.htaccesstools.com/htpasswd-generator/

3) Put .htacess, .htpasswd file to the same directory as your file
downFolder
     yourFileName
    .htacess 
    .htpasswd

So everytime the user download the file, they will be asked for password