CentOS 6下Apache的https虛擬機器主機實踐,centoshttps
題目:
1、建立httpd伺服器,要求:
提供兩個基於名稱的虛擬機器主機:
(a)www1.buybybuy.com,分頁檔目錄為/web/vhosts/www1;錯誤記錄檔為/var/log/httpd/www1.err,訪問日誌為/var/log/httpd/www1.access;
(b)www2.buybybuy.com,分頁檔目錄為/web/vhosts/www2;錯誤記錄檔為/var/log/httpd/www2.err,訪問日誌為/var/log/httpd/www2.access;
(c)為兩個虛擬機器主機建立各自的首頁檔案index.html,內容分別為其對應的主機名稱;
(d)通過www1.buybybuy.com/server-status輸出httpd工作狀態相關資訊,且只允許提供帳號密碼才能訪問(status:status);
2、為上面的第2個虛擬機器主機提供https服務,使得使用者可以通過https安全的訪問此web網站;
(1)要求使用認證認證,認證中要求使用的國家(CN)、州(Beijing)、城市(Beijing)和組織(Quintin Ltd);
(2)設定部門為Ops,主機名稱為www2.buybybuy.com,郵件為admin@buybybuy.com;
===============================================================================
準備環境與材料:
CentOS 6 兩部(一部也可以)
Apache 2.2
使用網域名稱buybybuy.com
1.建立httpd伺服器
建立所需檔案夾:
# mkdir -p /web/vhosts/www{1,2}
(a)、(b)
因為伺服器內建httpd,無需安裝
所以直接編輯httpd設定檔:httpd.conf
# vim /etc/httpd/conf/httpd.conf
注釋掉:
DocumentRoot
取消注釋:
#NameVirtualHost *:80
修改:
ServerName localhost:80
在底部添加以下虛擬機器主機配置
<VirtualHost *:80>
ServerAdmin admin@buybybuy.com
DocumentRoot /web/vhosts/www1
ServerName www1.buybybuy.com
ErrorLog logs/www1.err
CustomLog logs/www1.access combined
</VirtualHost>
<Directory /web/vhosts/www1>
Options Indexes FollowSymLinks
AllowOverride All
Order allow,deny
Allow from all
</Directory>
<VirtualHost *:80>
ServerAdmin admin@buybybuy.com
DocumentRoot /web/vhosts/www2
ServerName www2.buybybuy.com
ErrorLog logs/www2.err
CustomLog logs/www2.access combined
</VirtualHost>
<Directory /web/vhosts/www2>
Options Indexes FollowSymLinks
AllowOverride All
Order allow,deny
Allow from all
</Directory>
配置好後發現
Apache 403 error, (13)Permission denied: access to / denied問題
檢查了一圈httpd.conf和目錄許可權,均沒有發現問題。
發現是因為系統啟動了SELINUX導致的。
臨時關閉SELINUX
setenforce 0
永久關閉
vim /etc/selinux/config
修改
SELINUX=enforcing
改成
SELINUX=disabled
(c)
在www1和www2中分別建立index.html,內容分別為www1.buybybuy.com和www2.buybybuy.com
# vim /web/vhosts/www1/index.html
# vim /web/vhosts/www2/index.html
(d)
建立一個訪問賬戶,按提示操作
# htpasswd -c /etc/httpd/conf.d/.htpasswd webadmin
修改httpd.conf,加入
<Location /server-status>
AuthType Basic
AuthName "Administrator privateeee"
AuthUserFile "/etc/httpd/conf.d/.htpasswd"
Require user "webadmin"
SetHandler server-status
Order deny,allow
Deny from all
Allow from 192.168.3.3
</Location>
2.將www2.buybybuy.com設定為https
需要使用OpenSSL產生自我簽署憑證,確保OpenSSL已安裝.
# httpd -M | grep ssl
如果沒有則安裝
# yum install mod_ssl openssl
在CentOS A伺服器上配置CA服務,再給當前伺服器(CentOS B)的https頒發認證.
CentOS A:
初始化CA服務,建立所需要的檔案(/etc/pki/CA/)
# touch index.txt 建立索引檔案
# echo 01 > serial 建立序號檔案
CA自簽認證
產生私密金鑰
# (umask 077; openssl genrsa -out /etc/pki/CA/private/cakey.pem 2048)
使用私密金鑰產生簽署憑證
# openssl req -new -x509 -key /etc/pki/CA/private/cakey.pem -days 7300 -out /etc/pki/CA/cacert.pem
CentOS B:
# mkdir /etc/httpd/ssl
# cd /etc/httpd/ssl
產生秘鑰
# (umask 007;openssl genrsa -out httpd.key 1024)
產生請求檔案
# openssl req -new -key httpd.key -out httpd.csr
Country Name (2 letter code) [XX]:CN
State or Province Name (full name) []:Beijing
Locality Name (eg, city) [Default City]:Beijing
Organization Name (eg, company) [Default Company Ltd]:Quintin Ltd
Organizational Unit Name (eg, section) []:Ops
Common Name (eg, your name or your server's hostname) []:www2.buybybuy.com
Email Address []:admin@buybybuy.com
把產生的檔案發送到CA伺服器 CentOS A:
# scp httpd.csr root@192.168.3.67:/tmp/
回到CentOS A:
簽署
# openssl ca -in /tmp/httpd.csr -out /etc/pki/CA/certs/www2.buybybuy.com.crt -days 365
將產生的crt傳回CentOS B
# scp /etc/pki/CA/certs/www2.buybybuy.com.crt root@192.168.3.60:/etc/httpd/ssl/
回到CentOS B:
配置httpd的ssl配置(ssl.conf):
# cd /etc/httpd/conf.d/
備份
# cp ssl.conf{,.bak}
編輯ssl.conf
修改
<VirtualHost _default_:443>
為
<VirtualHost *:443>
DocumentRoot "/web/vhosts/www2"
ServerName www2.buybybuy.com
認證位置
SSLCertificateFile /etc/pki/tls/certs/localhost.crt
=>
SSLCertificateFile /etc/httpd/ssl/www2.buybybuy.com.crt
私密金鑰位置
SSLCertificateKeyFile /etc/pki/tls/private/localhost.key
=>
SSLCertificateKeyFile /etc/httpd/ssl/httpd.key
配置完畢檢查設定檔語法錯誤:
# httpd -t
重啟httpd:
# service httpd restart
查看443連接埠是否已開啟:
ss -tnl
使用s_client在CentOS A上做測試:
# openssl s_client -connect 192.168.3.60:443 -CAfile /etc/pki/CA/cacert.pem
GET / HTTP/1.1
Host: www2.buybybuy.com
HTTP/1.1 200 OK
Date: Wed, 05 Oct 2016 11:20:16 GMT
Server: Apache/2.2.15 (CentOS)
Last-Modified: Fri, 30 Sep 2016 13:33:02 GMT
ETag: "bf4e8-21-53db9a230598a"
Accept-Ranges: bytes
Content-Length: 33
Connection: close
Content-Type: text/html; charset=UTF-8
www2.buybybuy.com</br>
welcome!
測試成功!
去瀏覽器訪問格式:
https://www2.buybybuy.com