Re: [users@httpd] Command line method to get virtual hosts and DocumentRoot?

2016-01-28 Thread Pete Houston
On Thu, Jan 28, 2016 at 05:03:41PM +, Rose, John B wrote: > Is there a command line method to list all the virtual hosts and each > DocumentRoot? Should be pretty simple to construct with Apache::ConfigParser. https://metacpan.org/pod/Apache::ConfigParser Pete -- Openstrike - improving

Re: [users@httpd] Circumstances when mod_php would run faster than PHP-FPM?

2016-01-12 Thread Pete Houston
On Tue, Jan 12, 2016 at 06:56:40PM +, Rose, John B wrote: > For event ... > > > StartServers3 > MinSpareThreads 20 > MaxSpareThreads 25 > ServerLimit 16 > ThreadsPerChild 16 > MaxRequestWorkers 256 >

Re: [users@httpd] How to force browsers doesn't use cache

2015-11-16 Thread Pete Houston
On Mon, Nov 16, 2015 at 06:19:37PM -0200, Ronaldo Luiz de Carvalho wrote: > There are a way to setting apache in a way to force the users site browsers > doesn't use their cache? You can use the Header directive to set the appropriate value of the Cache-Control header.

Re: [users@httpd] Error executing script through Apache

2015-10-16 Thread Pete Houston
On Fri, Oct 16, 2015 at 02:21:45PM +, David Johnson wrote: > What would be different about being logged in as www at the command line and > calling a script vs. running Apache as www and calling it through the > intranet? The SELinux context will be different. Check the audit log to see if

Re: [users@httpd] Error executing script through Apache

2015-10-16 Thread Pete Houston
On Fri, Oct 16, 2015 at 02:37:24PM +, David Johnson wrote: > Please forgive my ignorance, but what can I do now to resolve this? Depending on your current SELinux policy and what precisely it is that you want to allow you could either adjust an appropriate boolean, correct any files/dirs with

Re: [users@httpd] Using LogLevel?

2015-06-27 Thread Pete Houston
If you look carefully at the documentation at http://httpd.apache.org/docs/2.4/mod/core.html#loglevel you will see that it says: Context:server config, virtual host, directory The absense of .htaccess from that list indicates that it cannot be set in the .htaccess file. Set it in

Re: [users@httpd] Apache24 - how to optimize httpd.conf

2015-06-08 Thread Pete Houston
On Mon, Jun 08, 2015 at 02:35:24PM -0700, Motty Cruz wrote: Should Fix: Optimize images Leverage browser caching Consider Fixing: Eliminate render-blocking JavaScript and CSS in above-the-fold content Minify CSS Minify HTML All of those bar one are content issues and therefore unconnected

Re: [users@httpd] exclude website from directory rules

2015-06-02 Thread Pete Houston
Use a virtual host to override the server-level defaults. http://httpd.apache.org/docs/2.4/vhosts/ HTH, Pete On Tue, Jun 02, 2015 at 12:17:44PM -0400, Tim Dunphy wrote: There is a generic Directory index rule at Apache level like below that is expecting the serving domain to point to any of

Re: [users@httpd] Safari - Apache error when connecting using safari with beast mitigation

2015-04-30 Thread Pete Houston
On Thu, Apr 30, 2015 at 09:07:36AM +, Or Lindner wrote: Hi, I am running apache version 2.2.0. [description of problem snipped] There is maybe an apache patch for that problem? Since 2.2.0 there have been over 40 releases of stable branches of apache. These subsequent releases will

Re: [users@httpd] Re: mod_proxy and mod_nss - occasional SSL Proxy: I don't have the name of the host we're supposed to connect to so I can't verify that we are connecting to who we think we should b

2015-04-21 Thread Pete Houston
Hello Jamie, On Tue, Apr 21, 2015 at 11:55:27AM -0400, Jamie Johnson wrote: Sorry to hit this again, but I've made no headway short of setting NSSProxyCheckPeerCN off, is this not reproducible? Is there another list I should be asking this on? As mod_nss is a third-party module it's quite

Re: [users@httpd] AuthBasic Questions: Modify the pop-up message? Change auth cache time?

2015-04-14 Thread Pete Houston
On Tue, Apr 14, 2015 at 07:14:55AM -0500, Tom Browder wrote: I now have basic authorization (under TLS) working okay, but I would like to influence the user experience a bit via Apache behavior if possible. A few questions if you please: 1. Can I modify the pop-up message? Possibly. You

Re: [users@httpd] one apache virtual domain won't start

2015-03-27 Thread Pete Houston
On Wed, Mar 18, 2015 at 08:57:27PM -0700, Dave Stevens wrote: I have a Ubuntu 14.04 box with 8 domains. At first they all worked but yesterday one stopped serving pages, browser says -- Server not found the config looks ok, domain-specific configs are in sites-enabled, there are access errors,

Re: [users@httpd] Looking for a new maintainer for FableTech Server Status for Apache

2015-03-08 Thread Pete Houston
to maintain and support ftss in a similar way. Please let me know if you would be happy for us to do so (off-list is fine). Thanks, Pete Houston On Tue, Feb 17, 2015 at 07:37:17PM +0100, Morten Shearman Kirkegaard wrote: Going forward we will not be able to maintain the project, so we are looking

Re: [users@httpd] Single web page site settings questions ... i.e. KeepAlive,

2014-12-19 Thread Pete Houston
On Fri, Dec 12, 2014 at 03:18:57PM +, Rose, John B wrote: For a one page web site The page will have a very large number of visitors in a short time. There will be simple text updates on the page and users will check back frequently to see the updates. Say 100k visitors each

Re: [users@httpd] mod_userdir question

2014-12-03 Thread Pete Houston
As Carlos's question suggests that he might be quite new to all this, it's probably worth pointing out that for simple, low-volume applications there is no requirement to load any language-specific module into apache. All one needs is mod_cgi (or mod_cgid) to get started and then it's pretty

Re: [users@httpd] Help needed with event MPM configuration

2014-11-04 Thread Pete Houston
On Tue, Nov 04, 2014 at 03:58:25PM +, Rajalakshmi Iyer wrote: The server has a KeepAliveTimeout of 120 seconds. That is probably the longest KeepAliveTimeout I have seen. Is there some particular reason that you have it so high? In 2.4 the default value is 5 seconds, which ought to be a

Re: [users@httpd] Apache Upgrade

2014-10-17 Thread Pete Houston
On Fri, Oct 17, 2014 at 10:53:03AM +, pratibha.dhank...@wipro.com wrote: Can someone please suggest steps to upgrade Apache 2.2.21 to 2.2.29? It's a little urgent requirement. http://httpd.apache.org/docs/2.2/install.html#upgrading Pete -- Openstrike - improving business through open

Re: [users@httpd] Version check urgent

2014-10-10 Thread Pete Houston
On Fri, Oct 10, 2014 at 07:10:47AM +, pratibha.dhank...@wipro.com wrote: Currently in our application we have Apache 2.0 version installed on windows server 2003. Could you please let us know if same Apache 2.0 version will support for Windows server2012 or not? If not which version

Re: [users@httpd] Proposed simple shell-shock protection

2014-09-29 Thread Pete Houston
On Mon, Sep 29, 2014 at 01:09:19PM -0500, Sharon Zastre wrote: Is it safe to assume that a fix/patch/upgrade will become available to address the shellshock vulnerability? Yes, but not in apache. The vulnerability dubbed shellshock is a flaw in bash and patches and upgrades are already widely

Re: [users@httpd] enabling htaccess in vhosts

2014-09-06 Thread Pete Houston
No need for Google, just go straight to the source: http://httpd.apache.org/docs/2.4/howto/htaccess.html Pete On Fri, Sep 05, 2014 at 07:53:07PM -0600, Matthew Smith wrote: How do I do so? I googled but can't figure it out. -- Openstrike - improving business through open source

Re: [users@httpd] Apache 2.2:How to enable module: mod_expires.c

2014-08-09 Thread Pete Houston
On Sat, Aug 09, 2014 at 02:14:36PM +, Mark jensen wrote: and I have found this line in conf file: LoadModule expires module modules/mod_expires.so but ExpireDefault didn't work There's no such directive in Apache 2.2 as ExpireDefault. Perhaps if you tried ExpiresDefault you might have

Re: [users@httpd] Use Allow from IP when there is a proxy exist?

2014-08-07 Thread Pete Houston
On Thu, Aug 07, 2014 at 09:19:10PM +, Mark jensen wrote: How can I make Apache to deal with the client IP not the proxy IP? Use mod_remoteip. Pete -- Openstrike - improving business through open source http://www.openstrike.co.uk/ or call 01722 770036 / 07092 020107 pgp8PAUHGkopd.pgp

Re: [users@httpd] Order of application of sites-enabled configs

2014-08-06 Thread Pete Houston
On Wed, Aug 06, 2014 at 02:20:26AM -0700, M Busche wrote: I notice that the default virtual host configuration file name is 000-default.conf.  I presume the convention of starting virtual host configuration file names with a three digit number governs the order in which the configurations

Re: [users@httpd] Confirmation on Vulnerability Status of Apache HTTP V2.0.50 and when bundled with Brocade FOS V7.1.X

2014-07-06 Thread Pete Houston
On Tue, Jun 24, 2014 at 12:45:19AM -0400, Kee, Siokkwan wrote: We have an issue currently where documentation released from Brocade indicates Apache HTTP V 2.0.50 is listed as non-vulnerable when bundled together with Brocade FOS V7.1.1. As Brocade has listed this as a non-vulnerability, the

Re: [users@httpd] mod_rewrite RewriteCond

2014-06-27 Thread Pete Houston
Hello Michael, The obvious question is why are you using mod_rewrite for access control in the first place? There are other, lighter modules whose purpose actually is access control and which will allow you to use CIDR notation etc. I suggest you take a look at mod_authz_host instead. Pete --

Re: [users@httpd] mod_rewrite RewriteCond

2014-06-27 Thread Pete Houston
You can set up a reverse proxy and include access control like this: LoadModule proxy_module modules/mod_proxy.so LoadModule proxy_http_module modules/mod_proxy_http.so ProxyRequests Off VirtualHost 10.0.0.1:80 ServerName reverse-proxy.example.com Location / allow

Re: [users@httpd] MaxClients exceeded error message

2014-06-27 Thread Pete Houston
On Fri, Jun 27, 2014 at 03:39:42PM +, Rose, John B wrote: What is the impact of not having a ListenBacklogs Directive in your config? This is covered pretty well in the documentation: http://httpd.apache.org/docs/2.4/mod/mpm_common.html#listenbacklog A cursory read of this tells us that

Re: [users@httpd] Maxservers

2014-06-20 Thread Pete Houston
On Wed, Jun 18, 2014 at 06:03:39PM +, Jesus Tellez wrote: I have Apache 2.0.59 That's an eight-year-old version of a legacy branch. If you don't have a truly excellent reason for sticking with that, I suggest that you think about upgrading. and configured start servers=8, but on

Re: [users@httpd] AH00169 and AH00163

2014-04-29 Thread Pete Houston
Thowe are not errors; they are notices. Pete -- Openstrike - improving business through open source http://www.openstrike.co.uk/ or call 01722 770036 / 07092 020107 pgpbD5yARvy_l.pgp Description: PGP signature

Re: [users@httpd] similar proxy rules causing warning

2014-04-23 Thread Pete Houston
On Wed, Apr 23, 2014 at 03:41:54PM -0600, eric tse wrote: Have proxy rules proxyPass /ABC http://domain.com/abc/ proxyPass /AbC http://domain.com/abc/ And get The Apache service named reported the following error: [xxx xxx xx xx:xx:xx 20xx] [info] worker http://domain.com/abc/ already

Re: [users@httpd] https

2014-04-04 Thread Pete Houston
From the openssl documentation at http://www.openssl.org/docs/apps/req.html is this list of example field values: [ req_distinguished_name ] C = GB ST = Test State or Province L = Test Locality O =

Re: [users@httpd] How to create Custom Http Status code

2014-03-28 Thread Pete Houston
The HTTP status codes are defined in httpd.h, so you could just edit them there and recompile. However, I advise strongly against using custom HTTP status codes for what should hopefully be obvious reasons. Perhaps this is an XY problem? Pete On Fri, Mar 28, 2014 at 04:38:06PM +0530, Sailaja

Re: [users@httpd] FancyIndexing IndexOrderDefault

2014-03-20 Thread Pete Houston
According to the documentation[1] IndexOrderDefault is a separate directive, so your configuration should be on two lines like this: IndexOptions FancyIndexing IndexOrderDefault Descending Name There is actually an example of this, but it is in the comments. Search for JAKA. HTH, Pete [1]

Re: [users@httpd] setting up fresh instance with SSL; httpd exiting 1 with no log

2014-03-05 Thread Pete Houston
On Tue, Mar 04, 2014 at 05:24:59PM -0800, john gale wrote: However, now httpd simply exits with status 1 and no output, either on standard out or standard error. In that case your next port of call is the httpd error log. Always consult this for the detail and raise the LogLevel to get ever

Re: [users@httpd] Vhosts behind NAT

2014-01-24 Thread Pete Houston
On Fri, Jan 24, 2014 at 11:07:35AM +0400, mn wrote: Does it possible to configure the apache so it distinguishes name abc.* and cde.* (used by clients externally) and returns different pages (provided two VirtualHosts are configured)? Which Directives are imlpemented in the case? Or, maybe,

Re: [users@httpd] Apache Directory Level access control

2014-01-21 Thread Pete Houston
On Tue, Jan 21, 2014 at 12:39:27PM -0500, James B. Byrne wrote: Directory /HLL_Operations Require group management staff /Directory Do you really have a directory at the very top level of your O/S filesystem called /HLL_Operations? It seems more likely that this will be in some

Re: [users@httpd] Apache Directory Level access control

2014-01-21 Thread Pete Houston
On Tue, Jan 21, 2014 at 03:17:35PM -0500, James B. Byrne wrote: On Tue, January 21, 2014 14:58, Pete Houston wrote: On Tue, Jan 21, 2014 at 12:39:27PM -0500, James B. Byrne wrote: Directory /HLL_Operations Require group management staff /Directory Do you really have

Re: [users@httpd] Re: Curious inability to mod_rewrite absolute paths

2014-01-08 Thread Pete Houston
On Mon, Jan 06, 2014 at 12:45:27AM -0500, Borden Rhodes wrote: I understand from the docs that Alias directives can't be used in .htaccess files. Is this correct? This inability is partly why I kept struggling with RewriteRules - the other was to force myself to practise regexes and advanced

Re: [users@httpd] Re: Curious inability to mod_rewrite absolute paths

2014-01-02 Thread Pete Houston
On Wed, Jan 01, 2014 at 09:55:48PM -0500, Borden Rhodes wrote: I notice in the log that httpd passes the requests for the first two images through RewriteRule in the .htaccess file. However, the call to fetch /images/bowler.jpeg *doesn't* go through the RewriteRule, but instead (line 50

Re: [users@httpd] Memory leak on 2.2.16

2013-11-25 Thread Pete Houston
Well, two things jump out from your list of modules. Firstly, there's this: mpm_itk_module (static) Does the problem occur if you use prefork instead? Secondly, there's this: cgi_module (shared) cgid_module (shared) Since I'm unfamiliar with mpm_itk, it may not be a problem there but

Re: [users@httpd] undefined reference to tls client method

2013-11-01 Thread Pete Houston
Hello David, On Fri, Nov 01, 2013 at 03:21:35AM -0700, David Benfell wrote: I built openssl from source. I'm trying to get TLS 1.2 working, which the old and crufty openssl on Centos 6.4 doesn't do. Do I need to do something different to get the development libraries in place? Since it is the

Re: [users@httpd] Virtual Hosts and SSL Puzzler

2013-10-22 Thread Pete Houston
On Tue, Oct 22, 2013 at 08:26:57AM -0400, Dennis Putnam wrote: I get a gray globe indicating partial encryption which does not prevent eavesdropping. I have no clue how to debug this or even where to look. Can someone point me in the right direction? Thanks. This is usually indicative of a

Re: [users@httpd] Printing Request Details received at Apache

2013-10-21 Thread Pete Houston
On Mon, Oct 21, 2013 at 01:19:35PM +0530, santosh kumar wrote: What i need is , i want to print the whole request details which is being received at Apache end. It sounds like mod_log_forensic might be what you are after. http://httpd.apache.org/docs/2.4/mod/mod_log_forensic.html Pete --

Re: [users@httpd] Help me understand Waiting for Connection

2013-10-20 Thread Pete Houston
On Fri, Oct 11, 2013 at 10:52:13AM -0500, Jonathan Dart wrote: If I request http://localhost/server-status; every 1 second for 5 seconds, on the last request apache reports that it has 5 active requests all with a Request of /server-status and a Mode of Operation of Waiting for Connection.

Re: [users@httpd] Apache in production without squid

2013-10-14 Thread Pete Houston
If your apache installation is sufficiently well tuned and has enough resources (chiefly RAM) then it should be fine. For a public example, see http://httpd.apache.org/server-status presently indicating over 800 slots. Good luck, Pete -- Openstrike - improving business through open source

Re: [users@httpd] Apache not recording client addresses correctly

2013-10-01 Thread Pete Houston
On Mon, Sep 30, 2013 at 06:03:37PM -0700, Andrew Daviel wrote: huh! wtf? - if I enable /server-status, the correct address for the client asking for /server-status, is not just logged, but resolved, even though HostnameLookups is off. But other requests still get the 98.32 address. This

Re: [users@httpd] Virtual Hosts Possible for SSL ?

2013-10-01 Thread Pete Houston
On Tue, Oct 01, 2013 at 04:25:05PM +0100, John McIntyre wrote: Am I doomed to failiure, or is what I'm trying to do, actually possible? No, you are almost there. The problem is that for some reason you have an asterisk in your VirtualHost declaration for domain2. Change that the the actual IP

Re: [users@httpd] Apache2 hidden files folders

2013-09-24 Thread Pete Houston
On Tue, Sep 24, 2013 at 06:21:23PM +0200, Sós Dániel wrote: IndexIgnore .??* *~ *# HEADER* README* RCS CVS *,v *,t The first term there will prohibit display of your dotfiles. Try removing it and use this instead: IndexIgnore *~ *# HEADER* README* RCS CVS *,v *,t Also, be very careful

Re: [users@httpd] Apache2 hidden files folders

2013-09-24 Thread Pete Houston
On Tue, Sep 24, 2013 at 06:39:09PM +0200, Sós Dániel wrote: This not work, not listing dot files: IndexIgnore *~ *# HEADER* README* RCS CVS *,v *,t It works for me in Apache 2.2.24. Which specific version are you running? Are you sure there are no other IndexIgnore directives in your

Re: [users@httpd] Queries regarding the feasibility of achieving a use-case with HTTPD

2013-09-02 Thread Pete Houston
I take that sentence to be referring to the relationship between the client IP address and the session and to have no connection with the session duration. You as the developer can set the cookie in any way you require. All the best, Pete -- Openstrike - improving business through open source

Re: [users@httpd] Queries regarding the feasibility of achieving a use-case with HTTPD

2013-08-25 Thread Pete Houston
On Sat, Aug 24, 2013 at 04:44:46PM +0530, Ajay Garg wrote: Is the above workflow possible by merely using HTTPD, or some form of external proxy-software (like squid) is required? Yes, this is possible with just httpd. If it is indeed possible to achieve the above with just HTTPD, I will be

Re: [users@httpd] Domain Name not working on localhost

2013-08-05 Thread Pete Houston
Most likely your (new) ISP is not set up to route traffic out and then back in again. Instead, on your client set up a hosts file entry with the private IP address of the server on your LAN and you should be fine. Good luck, Pete -- Openstrike - improving business through open source

Re: [users@httpd] Re: apache service interruption

2013-08-02 Thread Pete Houston
On Thu, Aug 01, 2013 at 10:49:59PM -0700, Grant wrote: Do you do this only when under DoS attack or all the time? All the time. Won't you potentially prevent legitimate users from making a single connection if they're connecting with a shared IP from a university campus (for example)? Yes.

Re: [users@httpd] Re: apache service interruption

2013-07-30 Thread Pete Houston
On Mon, Jul 29, 2013 at 11:25:26PM -0700, Grant wrote: ModSecurity looks good and I think it works with nginx as well as apache. Is everyone who isn't running OSSEC HIDS or ModSecurity vulnerable to a single client requesting too many pages and interrupting the service? Not everyone, no.

Re: [users@httpd] Logging Base64 decoded info in access_log

2013-07-27 Thread Pete Houston
On Fri, Jul 26, 2013 at 12:39:37PM -0700, Jignesh Badani wrote: Thanks Pete, yes, post processing the log file nightly is the option I was considering. I am doing it currently on a per request basis. But I was hoping to avoid it if I could do it in real time by calling on B64 decode on the

Re: [users@httpd] Log Time != Server Time

2013-06-21 Thread Pete Houston
Yes, it's pretty simple, assuming that you mean that apache should run as UTC (GMT) and the other, non-apache processes on the machine should be unaffected: $ export TZ=GMT $ apachectl stop $ apachectl start Make sure to include this env var in the apache boot script too.

Re: [users@httpd] default linux apache password

2013-06-13 Thread Pete Houston
On Thu, Jun 13, 2013 at 01:37:33PM +0200, Rafnews wrote: All files/folder that are under /publi_html should have apache as user/group permissions. This statement is incorrect and is the cause of your problems. The httpd process owner should not be the owner of your users' files, it only

Re: [users@httpd] users file/folder access outside public_html

2013-05-25 Thread Pete Houston
On Sat, May 25, 2013 at 01:39:51PM +0200, Rafnews wrote: Questions: 1. how can i allow user to have access to folder/files outside public_html ? You could use aliases or a specific handler. 2. how can i secure that user A has access to his own files ONLY ? This is called authorisation and

Re: [users@httpd] option indexes and rewrite

2013-05-25 Thread Pete Houston
I would use DirectoryIndex and mod_autoindex for this and certainly would not go anywhere near mod_rewrite. DirectoryIndex c-en.html Options +Indexes I'd humbly suggest however that you try to avoid filenames with leading spaces. As you are new to it, it is also worth pointing

Re: [users@httpd] Re: File renders differently when opened through Apache or direct, why?

2013-05-11 Thread Pete Houston
On Sat, May 11, 2013 at 01:34:47PM +0200, Bo Berglund wrote: Since the data being transferred to FireFox looks exactly like what is being used when I open the file directly in FireFox, why does FireFox not display it in the same way? When you open the file directly from the filesystem, there

Re: [users@httpd] Rewrite Rule Rewriting root site

2013-04-19 Thread Pete Houston
On Mon, Apr 15, 2013 at 06:57:13PM -0400, Chris Arnold wrote: We have a server at http://rootsite.net. We also have another site/app that runs at http://apps.rootsite.net. We host client applications on our server using apache so the above site/app needs to be

Re: [users@httpd] Apache not responding to external requests

2013-04-19 Thread Pete Houston
On Fri, Apr 19, 2013 at 08:44:48AM -0500, Neil Aggarwal wrote: This is strange. I did a fresh install of CentOS 6.4 on a virtual server and then did a yum install httpd. The apache server responds to local requests but not requests over eth0. I checked the Listen directive in httpd.conf

Re: [users@httpd] RewriteRule help

2013-04-12 Thread Pete Houston
No need to use RewriteRule for that, simply use Redirect. Redirect /products/flash /flash http://httpd.apache.org/docs/2.4/mod/mod_alias.html#redirect Pete -- Openstrike - improving business through open source http://www.openstrike.co.uk/ or call 01722 770036 / 07092 020107

Re: [users@httpd] How to run httpd server on random port on every bootup

2013-03-26 Thread Pete Houston
Yes, there is. You can use -C to specify the default port. See http://httpd.apache.org/docs/2.4/programs/httpd.html#options and http://httpd.apache.org/docs/2.4/mod/mpm_common.html#listen - just make sure you don't over-ride it in your httpd.conf. However, I cannot think of any use case for this.

Re: [users@httpd] Errorlog for cgi and Perl

2013-03-20 Thread Pete Houston
On Tue, Mar 19, 2013 at 08:29:56PM -0400, Pierre Forget wrote: If I make a voluntary error in my Perl script, I get in the /httpd/domainname/logs/error_log: [Tue Mar 19 20:19:25.500222 2013] [cgid:error] [pid 17263:tid 2921331520] [client 24.122.245.237:56995] End of script output before

Re: [users@httpd] Upgrade Apache from 1.3.22 to the latest version

2013-03-14 Thread Pete Houston
On Thu, Mar 14, 2013 at 10:27:55AM +0530, vitthal@tatamotors.com wrote: We have Apache version(Oracle HTTP Server Powered by Apache/1.3.22 (Unix) running on 9i E-businees suite(9.2.0). What is the step by step procedure of upgrading it to the latest version. Start by reading this:

Re: [users@httpd] AliasMatch and permission problem

2013-02-16 Thread Pete Houston
On Sat, Feb 16, 2013 at 12:00:15PM +0100, Gergely Buday wrote: I created a 'web' group and put my user and apache into it, and gave 640 for the files and 750 for the dirs. ... $ ls -ld wp-admin/ drwxr-x--- 9 gergoe web 4096 Sep 7 08:54 wp-admin/ What do you suggest to fix this? You

Re: [users@httpd] AliasMatch and permission problem

2013-02-16 Thread Pete Houston
On Sat, Feb 16, 2013 at 12:37:12PM +0100, Gergely Buday wrote: Pete Houston wrote: If it still fails after that, check the audit log to make sure the directory has the right context. Oops, could you explain what a context is? This one: http://httpd.apache.org/docs/2.2/mod/directive

Re: [users@httpd] Disable custom modules for a specific directory in my web server

2013-02-14 Thread Pete Houston
Hello Chris, Not sure how well it would work for your particular situation, given the embedded nature, but one approach to this may be to run 2 completely separate apache instances. This is often done on servers to distinguish between lightweight and heavy content: eg. have one stripped down

Re: [users@httpd] WebDav setup

2013-01-18 Thread Pete Houston
On Fri, Jan 18, 2013 at 12:39:36PM +0200, Johan Moraal wrote: Location /usr/local/apache2/htdocs That's not the correct argument for Location. Location takes a web path, not a filesystem path. Eg. if your FQDN is www.foo.com and you wanted a Location section to match http://www.foo.com/bar/ you

Re: [users@httpd] forward proxy with SSL Termination

2013-01-11 Thread Pete Houston
On Fri, Jan 11, 2013 at 11:37:44AM +0200, Chris Datfung wrote: How can I configure Apache to forward proxy requests while terminating SSL connections for inspection and then reencrypt the traffic? That won't be trivial, which is a good thing otherwise https would be pretty pointless from a

Re: [users@httpd] Default configuration: who replies with a 403 Forbidden document?

2012-12-13 Thread Pete Houston
On Thu, Dec 13, 2012 at 11:14:29AM +0100, Daniele Imbrogino wrote: But why the client on 192.168.1.3 receives also a (very basic) HTML page explaining the error, if I don't have any ErrorDocument directive? (and the few present in httpd.conf by default are commented) This is explained in the

Re: [users@httpd] re-write rule

2012-12-06 Thread Pete Houston
Your regex in this line: RewriteRule ^stuff$ https://diversity.umn.edu/disability/request/exam[R=301,L] does not match stuff.html so you could change it to ^/stuff\.html$ or similar. Enable the rewrite log if you want to see what the rewrite engine is doing in detail. Good luck, Pete --

Re: [users@httpd] ScriptAlias/cgi-bin for apache instance on port 8080

2012-11-14 Thread Pete Houston
If you look in the error log it should tell you precisely which path it is that has not been found, ie. after all the aliasing and so forth this will tell you precisely where on the filesystem it is looking for the content that is not found. HTH, Pete -- Openstrike - improving business through

Re: [users@httpd] Is there any way to encrypt/obfuscate apache conf files

2012-11-09 Thread Pete Houston
Hello Sudip, On Fri, Nov 09, 2012 at 01:51:53PM +0530, Bhattacharya, Sudip wrote: Is there any way to obfuscate/encrypt conf files in Apache? I'm not aware of a direct method. Perhaps mod_macro could be used for obfuscation. I have put my configuration entries in a separate config file, and

Re: [users@httpd] Need help with multiple SSL certs + multiple domains

2012-11-07 Thread Pete Houston
Make sure each set of virtual hosts which requires a different certificate is run on a unique IP+port combination. eg: IP:PortServernameCertificate 10.0.0.1:8000 www.foo.com *.foo.com 10.0.0.1:8000 www2.foo.com *.foo.com 10.0.0.1:8001 www.bar.com *.bar.com 10.0.0.1:8001

Re: [users@httpd] Set multiple DocumentRoot

2012-10-29 Thread Pete Houston
On Sun, Oct 28, 2012 at 04:04:36PM +1100, jupiter wrote: VirtualHost *:80 ServerName 192.168.1.101 DocumentRoot /tmp /VirtualHost The 8080 works, but 80 got an error of Permission denied: file permissions deny server access: /tmp/index.html. I don't see any permission problems:

Re: [users@httpd] public_html folder in chroot environment

2012-10-26 Thread Pete Houston
On Fri, Oct 26, 2012 at 10:35:35AM +0530, val john wrote: Seems like apache not getting username second time when using * character That's correct - it is only the first occurrence of an asterisk in the UserDir path which is replaced. Since you are already chrooting individual users into their

Re: [users@httpd] Set multiple DocumentRoot

2012-10-26 Thread Pete Houston
On Fri, Oct 26, 2012 at 08:02:11PM +1000, jupiter wrote: I need to set DocumentRoot to two directories, one for development and one for testing. But the server has only one IP address, and there is no DNS. Is it possible? If so, please give an example. Use different ports. You can set up two

Re: [users@httpd] Locking Down httpd w/virtualhosts

2012-10-24 Thread Pete Houston
On Tue, Oct 23, 2012 at 12:38:39PM +1000, Nick Edwards wrote: was hoping for a general cgi solution tha works the same, perhaps its there and my google fu is failing me today? Something like sbox? http://stein.cshl.org/software/sbox/ If not, could this be a feature request, it can not be that

Re: [users@httpd] apache 2.4.3 and Require instead of Allow from

2012-10-22 Thread Pete Houston
On Mon, Oct 22, 2012 at 11:44:44PM +0200, Alain Roger wrote: How can i do to restrict this folder/website to 2 ip addresses (e.g. 192.168.1.10 and 192.168.2.50) ? Require ip 192.168.1.10 192.168.2.50 as specified in the documentation at

Re: [users@httpd] How to conditionally enable mod_deflate?

2012-10-19 Thread Pete Houston
This sounds like a job for mod_negotiation to me. Any reason not to use that instead? Pete On Fri, Oct 19, 2012 at 09:14:35PM +0530, Bhattacharya, Sudip wrote: I need to conditionally enable mod_deflate for clients who send a particular custom HTTP Request Header. -- Openstrike - improving

Re: [users@httpd] Uploading files to Apache Server

2012-09-24 Thread Pete Houston
On Mon, Sep 24, 2012 at 05:22:11PM +0530, Bhattacharya, Sudip wrote: Also note that the file uploads will be via a JAVA application (not servlet/manual uploads). So whatever is the option, it should enable uploads via a java application. The files to upload will vary from 1mb to 30mb to upto

Re: [users@httpd] can't display or download images on new Apache install

2012-09-19 Thread Pete Houston
On Wed, Sep 19, 2012 at 11:04:46AM -0400, Rick Lopez wrote: However, if I open the index.html file as a file with Firefox it works fine. I see the following message in the Firefox error console. security error: content at 192.168.1.10 may not load or link to

Re: [users@httpd] can't display or download images on new Apache install

2012-09-19 Thread Pete Houston
On Wed, Sep 19, 2012 at 01:08:32PM -0400, Rick Lopez wrote: Thanks for the reply. To clarify I am running Apache 2.4.3. I also used Kompozer to create the index.html file so I assumed it was creating the correct syntax. Kompozer created this for the embedded jpg file:

Re: [users@httpd] Apache 3.4.3 or 3.3.1 Pre-Compiled Versions

2012-09-12 Thread Pete Houston
On Wed, Sep 12, 2012 at 06:07:18AM -0700, Frank Mancini wrote: Does anyone know where I can get a pre-compiled version for both Linux and Solaris of Apache 3.4.3 and 3.3.1? Those versions do not exist (yet). A reasonable guess for the former would be

Re: [users@httpd] What verification does Apache do as part of SSLVerifyClient?

2012-09-09 Thread Pete Houston
On Sun, Sep 09, 2012 at 08:36:30AM -0500, Tom Browder wrote: So the client cert. does contain the private key? Then its password is all that is protecting it? No, the key is normally (but not always) kept separately. Mark, in your experience, what is the best way to distribute client

Re: [users@httpd] Can somebody help me to understand the strange GET requests logged in access.log and error.log ?

2012-08-13 Thread Pete Houston
On Mon, Aug 13, 2012 at 06:07:20PM +0200, Carlo Traversa wrote: but I still see GET requests in the access.log So is there something I did wrong or I didn't understand? The access log will (by default) contain all the requests to the server which are handled by apache, even if that handling is

Re: [users@httpd] Error compiling httpd 2.2.11 with openssl 0.9.8 on rhel 6

2012-07-26 Thread Pete Houston
On Wed, Jul 25, 2012 at 04:56:48PM -0700, Fleishman.Mark wrote: I compiled openssl 0.9.8x using these options, and it compiled and installed ok: ./config --prefix=/apps/openssl/0.9.8x --openssldir=/apps/openssl/0.9.8x/openssl shared Here are the compile options I am using with httpd

Re: [users@httpd] SSI not working

2012-07-18 Thread Pete Houston
On Wed, Jul 18, 2012 at 06:00:45PM -0400, Dunkle, Edward (Edward) wrote: Options +IncludesNOEXEC FollowSymLinks Don't do that. If you mix +/- options with non-+/- options you'll have problems. Instead use maybe Options +IncludesNOEXEC +FollowSymLinks HTH, Pete -- Openstrike

Re: [users@httpd] apache changes status code from 500 to 200

2012-07-11 Thread Pete Houston
Sounds like you want mod_asis: http://httpd.apache.org/docs/2.4/mod/mod_asis.html Pete -- Openstrike - improving business through open source http://www.openstrike.co.uk/ or call 01722 770036 / 07092 020107 pgpjatXwibclp.pgp Description: PGP signature

Re: [users@httpd] apache changes status code from 500 to 200

2012-07-11 Thread Pete Houston
On Wed, Jul 11, 2012 at 03:21:12PM +0200, Ruud Dozijn wrote: I have put this in my httpd.conf: Location /cgi SetHandler perl-script PerlHandler ModPerl::Registry Options ExecCGI ErrorDocument 400 /handlers/400.h /Location Location /handlers SetHandler send-as-is

Re: [users@httpd] chinese character support

2012-06-23 Thread Pete Houston
On Wed, Jun 20, 2012 at 02:17:53PM -0500, Terry wrote: This is my first experience with a non-english character set so please excuse me if the answers are obvious. We have a Centos 5 box with apache 2.2.3 serving several english websites. We have a request from the customer to serve up a

Re: [users@httpd] trouble with virtualhost in http/https

2012-06-06 Thread Pete Houston
You cannot have 2 https sites with different certificates sharing the same IP+port combination. This is a restriction of how https works and is outlined in the documentation here: http://httpd.apache.org/docs/2.4/ssl/ssl_faq.html#vhosts If you ensure that your https vhosts have either different

Re: [users@httpd] Denial of Service due to multiplication of httpd running

2012-05-24 Thread Pete Houston
On Wed, May 23, 2012 at 07:47:37PM -0700, Bill Unruh wrote: But this is clearly a horrible kludge. Is there any way I can figure out what is triggering these versions of httpd to be piling up? Since you've looked at the logs and not found anything there (or at least eliminated what problems

Re: [users@httpd] Rewrite Role: navigation toolbar trouble

2012-05-24 Thread Pete Houston
If you can solve it with a symlink in the filesystem then the equivalent in the httpd configuration is to use an Alias. Pete -- Openstrike - improving business through open source http://www.openstrike.co.uk/ or call 01722 770036 / 07092 020107 pgpSpcXfWVOSK.pgp Description: PGP signature

Re: [users@httpd] Denial of Service due to multiplication of httpd running

2012-05-24 Thread Pete Houston
A dozen or so idle processes is perfectly normal for prefork (which you are clearly running, BTW). Only worry about this if there are a consistently high number of idle processes (say 30 or more for a lightly loaded server) in which case you can tune the value of MaxSpareServers to suit. Have a

Re: [users@httpd] Redirecting a domain to another using Rewrite rules

2012-05-17 Thread Pete Houston
On Wed, May 16, 2012 at 07:39:17PM -0400, Desilets, Alain wrote: When I try to go to www.wiki-translation.com, I see the url wiki-translation.wiki4us.com in the browser (which is not what I want... I want to keep the original www.wiki-translation.com url). In that case the approach will

Re: [users@httpd] Redirecting a domain to another using Rewrite rules

2012-05-16 Thread Pete Houston
On Wed, May 16, 2012 at 05:06:24AM -0700, Desilets, Alain wrote: I need to forward a domain www.wiki-translation.com to a different location wiki-translation.wiki4us.com, while preserving the original url. I have been trying to do this for 30 mins now, using Rewrite rules, and nothing

Re: [users@httpd] Help troubleshooting performance issue, after 1000 total children Apache no longer responds to HTTP requests. Not MaxClients issue?

2012-05-03 Thread Pete Houston
On Thu, May 03, 2012 at 08:33:58AM -0300, Luis Fernando Alen wrote: Perhaps your prefork settings are the cause of the issue. Look, you have 80 StartServers and 120 MaxSpareServers, and with such settings, apache can spawn 9600 (80*120) children. That's not how prefork works. I think you are

  1   2   >