Enable SELinux in centos 5.5 and support Apache FTP phpMyAdmin Solution

Source: Internet
Author: User

If you are new to Redhat Enterprise Linux4 or Fedora Core 2 or later/CentOS 4, Apache will often fail to run normally and report errors such as "Permission denied, even angry.
In fact, this is because SELinux is activated in these systems, and the user's apache configuration conflicts with SELinux's Configuration Policy, only through proper adjustment, make apache configuration and access comply with the policy to work properly.
1. phpmyadmin cannot run in non-default/var/www/html directory
Generally, when a virtual host is configured, access/phpmyadmin prompts 403 access denied, and the log prompts Permission denied, this is because the Directory and file attributes that phpmyadmin prevents do not meet the context requirements.
If phpmyadmin is placed in the/web directory, run the following command:
Chcon-R-t httpd_user_content_t/web
In this case, the/web and all its subdirectories/files, including the phpmyadmin file, obtain the httpd_user_content_t attribute. If the traditional Unix attribute is readable to httpd, try again.
2. the VM in the/home directory cannot run.
Similar to Issue 1, but according to the context definition above, the/home directory must be of the httpd_user_content_t type for the $ HOME/www, public_html, or web directory, therefore, we recommend that you place the content of the web page in your $ HOME/www or web or public_html file and make sure that its attribute is httpd_user_content_t. Run the following command to view the content:
Ls-Z/home/abc/
Drwxr-xr-x abc user_u: object_r: user_home_dir_t tmp
Drwxrwxr-x abc user_u: object_r: httpd_user_content www
If not, you can use chcon to change the Directory and file level by level until the last access is available:
Chcon-R-t httpd_user_content_t/home/abc/web
Chcon-t user_home_dir_t/home/abc
3. CGI program cannot run
If the cgi program is stored in/var/www/cgi-bin/and cannot be executed, in case of a 403 or 500 error, you can check the cgi program attributes as defined in The SELinux contexts file, /var/www/cgi-bin/must contain the httpd_sys_script_exec_t attribute. Use the ls-Z command to view the changes. If not, use the following command:
Chcon-t httpd_sys_script_exec_t/var/www/cgi-bin/*. cgi
If it is cgi in the VM, refer to question 2 to enable normal use of common functions, and then set the context of the cgi File to httpd_sys_script_exec_t through chcon.
4. the Setuid/gid program cannot be run.
For example, SqWebMail and qmailadmin in the early stage require the support of setuid/gid, but this will be strictly restricted in SELinux. The first method is a thorough method, which can retain the security of the system, through:
Audit2allow-l-I/var/log/messages
Convert the information rejected by SELinux to the corresponding policy allow command, add these commands to the corresponding configuration file in src of SELinux policy, regenerate the policy, and load it. However, this is relatively troublesome.
The other method is the easiest, but apache will not be protected. First, determine that the SELinux type is targeted:
Cat/etc/selinux/config | grep SELINUXTYPE
Then, remove apache from SELinux protection:
Setsebool-P httpd_disable_trans 1
Restart apache:
/Etc/init. d/httpd restart
4. Use ftp (the vsftpd method selunix does not seem to have any restrictions on proftpd. I use proftpd but it is still usable)
[Root @ jboss01 sbin] # cd/usr/sbin
[Root @ jboss01 sbin] #./setsebool-P ftp_home_dir = 1
In this way, all apache mandatory checks fail and the programs that require setuid/gid can be used normally. However, this poses a risk of increasing the number of vulnerabilities. This method is the final method to minimize the lack of system security when the system is in urgent need and urgent need. It is not a good method to cancel SELinux.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.