Re: Certbot error - SOLVED (?)

2023-04-24 Thread Patrick O'Callaghan
On Mon, 2023-04-24 at 10:44 -0700, Samuel Sieb wrote: > On 4/24/23 05:51, Tim via users wrote: > > That site's whole bit about sites-available and sites-enabled, with > > symlinking, is a rat's nest of directories that I've never > > encountered > > before.  We already have an /etc/httpd/conf.d/ th

Re: Certbot error - SOLVED (?)

2023-04-24 Thread Patrick O'Callaghan
On Mon, 2023-04-24 at 12:27 -0400, Jeffrey Walton wrote: > > Why? Because being unfamiliar with Apache (and Certbot) I was > > foolishly > > following an online step-by-step guide: > > > > https://www.linuxshelltips.com/install-apache-fedora-linux/ > > > > I've since seen the error of my ways and

Re: Certbot error - SOLVED (?)

2023-04-24 Thread Samuel Sieb
On 4/24/23 05:51, Tim via users wrote: That site's whole bit about sites-available and sites-enabled, with symlinking, is a rat's nest of directories that I've never encountered before. We already have an /etc/httpd/conf.d/ that can hold all extra config files. And you can easily create an extr

Re: Certbot error - SOLVED (?)

2023-04-24 Thread Jeffrey Walton
On Mon, Apr 24, 2023 at 5:14 AM Patrick O'Callaghan wrote: > > On Sun, 2023-04-23 at 14:56 -0700, Samuel Sieb wrote: > > On 4/23/23 14:50, Patrick O'Callaghan wrote: > > > I had a look at /var/log/httpd/error_log and found this: > > > > > > httpd: could not open error log file > > > /var/www/

Re: Certbot error - SOLVED (?)

2023-04-24 Thread Patrick O'Callaghan
On Mon, 2023-04-24 at 22:21 +0930, Tim via users wrote: > Samuel Sieb: > > > As someone else mentioned, why are you writing logs to the web > > > server > > > data directory?  There's a directory (/var/log/httpd) that's > > > already > > > intended for that.  The file context is most likely going t

Re: Certbot error - SOLVED (?)

2023-04-24 Thread Tim via users
Samuel Sieb: >> As someone else mentioned, why are you writing logs to the web server >> data directory? There's a directory (/var/log/httpd) that's already >> intended for that. The file context is most likely going to be >> wrong, which is why selinux is (rightly) blocking it. Patrick O'Callag

Re: Certbot error - SOLVED (?)

2023-04-24 Thread Patrick O'Callaghan
On Sun, 2023-04-23 at 14:56 -0700, Samuel Sieb wrote: > On 4/23/23 14:50, Patrick O'Callaghan wrote: > > I had a look at /var/log/httpd/error_log and found this: > > > > httpd: could not open error log file > > /var/www/bree.org.uk/error.log > > > > I rechecked and that file definitely exist

Re: Certbot error - SOLVED (?)

2023-04-23 Thread Tim via users
On Sun, 2023-04-23 at 15:29 -0700, Mike Wright wrote: > I don't understand how his logs are accessible to the web. They are not > under the DocumentRoot. error.log is above it and access.log is next to > it. Is it somehow possible for a client to reach above / ? Normally, they aren't. But Pa

Re: Certbot error - SOLVED (?)

2023-04-23 Thread Todd Zullinger
Chris Adams wrote: > Once upon a time, Mike Wright said: >> I don't understand how his logs are accessible to the web. They are >> not under the DocumentRoot. error.log is above it and access.log is >> next to it. Is it somehow possible for a client to reach above / ? > > I didn't look at the

Re: Certbot error - SOLVED (?)

2023-04-23 Thread Chris Adams
Once upon a time, Mike Wright said: > I don't understand how his logs are accessible to the web. They are > not under the DocumentRoot. error.log is above it and access.log is > next to it. Is it somehow possible for a client to reach above / ? I didn't look at the posted configs (I haven't ru

Re: Certbot error - SOLVED (?)

2023-04-23 Thread Patrick O'Callaghan
On Sun, 2023-04-23 at 18:58 -0400, Jeffrey Walton wrote: > On Sun, Apr 23, 2023 at 6:53 PM Jeffrey Walton > wrote: > > > > On Sun, Apr 23, 2023 at 5:51 PM Patrick O'Callaghan > > wrote: > > > > > > On Mon, 2023-04-24 at 05:06 +0930, Tim via users wrote: > > > > On Sun, 2023-04-23 at 12:21 -0700

Re: Certbot error - SOLVED (?)

2023-04-23 Thread Jeffrey Walton
On Sun, Apr 23, 2023 at 6:53 PM Jeffrey Walton wrote: > > On Sun, Apr 23, 2023 at 5:51 PM Patrick O'Callaghan > wrote: > > > > On Mon, 2023-04-24 at 05:06 +0930, Tim via users wrote: > > > On Sun, 2023-04-23 at 12:21 -0700, T.C. Hollingsworth wrote: > > > > Webroot authentication is pretty simple

Re: Certbot error - SOLVED (?)

2023-04-23 Thread Jeffrey Walton
On Sun, Apr 23, 2023 at 5:51 PM Patrick O'Callaghan wrote: > > On Mon, 2023-04-24 at 05:06 +0930, Tim via users wrote: > > On Sun, 2023-04-23 at 12:21 -0700, T.C. Hollingsworth wrote: > > > Webroot authentication is pretty simple, what trips most people up > > > is > > > it puts it in a dot direct

Re: Certbot error - SOLVED (?)

2023-04-23 Thread Mike Wright
On 4/23/23 15:08, Chris Adams wrote: Once upon a time, Patrick O'Callaghan said: httpd: could not open error log file /var/www/bree.org.uk/error.log Putting the log under /var/www is very bad practice, as that could be remotely accessible now (and share all kinds of useful information to

Re: Certbot error - SOLVED (?)

2023-04-23 Thread Chris Adams
Once upon a time, Patrick O'Callaghan said: > httpd: could not open error log file /var/www/bree.org.uk/error.log Putting the log under /var/www is very bad practice, as that could be remotely accessible now (and share all kinds of useful information to attackers). Rather than do that, and d

Re: Certbot error - SOLVED (?)

2023-04-23 Thread Samuel Sieb
On 4/23/23 14:50, Patrick O'Callaghan wrote: I had a look at /var/log/httpd/error_log and found this: httpd: could not open error log file /var/www/bree.org.uk/error.log I rechecked and that file definitely exists and is writable by root (which httpd runs as). However a suspicion arose and

Re: Certbot error - SOLVED (?)

2023-04-23 Thread Patrick O'Callaghan
On Mon, 2023-04-24 at 05:06 +0930, Tim via users wrote: > On Sun, 2023-04-23 at 12:21 -0700, T.C. Hollingsworth wrote: > > Webroot authentication is pretty simple, what trips most people up > > is > > it puts it in a dot directory /.well-known/acme-challenge/ and a > > lot > > of open source packag