Mostrando entradas con la etiqueta Apache Server. Mostrar todas las entradas
Mostrando entradas con la etiqueta Apache Server. Mostrar todas las entradas

miércoles, 4 de diciembre de 2013

Servidor virtual seguro en apache (SSl)

Para crear un servidor virtual seguro en Apache, Este código es por defecto de SSL para apache2:
<ifmodule mod_ssl.c>
<VirtualHost *:80>
 ServerAdmin webmaster@localhost

 DocumentRoot /var/www
 
  Options FollowSymLinks
  AllowOverride None
 
 
  Options Indexes FollowSymLinks MultiViews
  AllowOverride None
  Order allow,deny
  allow from all
 

 ScriptAlias /cgi-bin/ /usr/lib/cgi-bin/
 
  AllowOverride None
  Options +ExecCGI -MultiViews +SymLinksIfOwnerMatch
  Order allow,deny
  Allow from all
 

 ErrorLog ${APACHE_LOG_DIR}/error.log

 # Possible values include: debug, info, notice, warn, error, crit,
 # alert, emerg.
 LogLevel warn

 CustomLog ${APACHE_LOG_DIR}/ssl_access.log combined

 Alias /doc/ "/usr/share/doc/"
 
  Options Indexes MultiViews FollowSymLinks
  AllowOverride None
  Order deny,allow
  Deny from all
  Allow from 127.0.0.0/255.0.0.0 ::1/128
 

 #   SSL Engine Switch:
 #   Enable/Disable SSL for this virtual host.
 SSLEngine on
        SSLCertificateFile /etc/apache2/mis-ssl/apache.pem
 SSLCertificateKeyFile /etc/apache2/mis-ssl/apache.pem

 #   A self-signed (snakeoil) certificate can be created by installing
 #   the ssl-cert package. See
 #   /usr/share/doc/apache2.2-common/README.Debian.gz for more info.
 #   If both key and certificate are stored in the same file, only the
 #   SSLCertificateFile directive is needed.
 # SSLCertificateFile    /etc/ssl/certs/ssl-cert-snakeoil.pem
 # SSLCertificateKeyFile /etc/ssl/private/ssl-cert-snakeoil.key

 #   Server Certificate Chain:
 #   Point SSLCertificateChainFile at a file containing the
 #   concatenation of PEM encoded CA certificates which form the
 #   certificate chain for the server certificate. Alternatively
 #   the referenced file can be the same as SSLCertificateFile
 #   when the CA certificates are directly appended to the server
 #   certificate for convinience.
 #SSLCertificateChainFile /etc/apache2/ssl.crt/server-ca.crt

 #   Certificate Authority (CA):
 #   Set the CA certificate verification path where to find CA
 #   certificates for client authentication or alternatively one
 #   huge file containing all of them (file must be PEM encoded)
 #   Note: Inside SSLCACertificatePath you need hash symlinks
 #         to point to the certificate files. Use the provided
 #         Makefile to update the hash symlinks after changes.
 #SSLCACertificatePath /etc/ssl/certs/
 #SSLCACertificateFile /etc/apache2/ssl.crt/ca-bundle.crt

 #   Certificate Revocation Lists (CRL):
 #   Set the CA revocation path where to find CA CRLs for client
 #   authentication or alternatively one huge file containing all
 #   of them (file must be PEM encoded)
 #   Note: Inside SSLCARevocationPath you need hash symlinks
 #         to point to the certificate files. Use the provided
 #         Makefile to update the hash symlinks after changes.
 #SSLCARevocationPath /etc/apache2/ssl.crl/
 #SSLCARevocationFile /etc/apache2/ssl.crl/ca-bundle.crl

 #   Client Authentication (Type):
 #   Client certificate verification type and depth.  Types are
 #   none, optional, require and optional_no_ca.  Depth is a
 #   number which specifies how deeply to verify the certificate
 #   issuer chain before deciding the certificate is not valid.
 #SSLVerifyClient require
 #SSLVerifyDepth  10

 #   Access Control:
 #   With SSLRequire you can do per-directory access control based
 #   on arbitrary complex boolean expressions containing server
 #   variable checks and other lookup directives.  The syntax is a
 #   mixture between C and Perl.  See the mod_ssl documentation
 #   for more details.
 #
 #SSLRequire (    %{SSL_CIPHER} !~ m/^(EXP|NULL)/ \
 #            and %{SSL_CLIENT_S_DN_O} eq "Snake Oil, Ltd." \
 #            and %{SSL_CLIENT_S_DN_OU} in {"Staff", "CA", "Dev"} \
 #            and %{TIME_WDAY} >= 1 and %{TIME_WDAY} <= 5 \
 #            and %{TIME_HOUR} >= 8 and %{TIME_HOUR} <= 20       ) \
 #           or %{REMOTE_ADDR} =~ m/^192\.76\.162\.[0-9]+$/
 #

 #   SSL Engine Options:
 #   Set various options for the SSL engine.
 #   o FakeBasicAuth:
 #     Translate the client X.509 into a Basic Authorisation.  This means that
 #     the standard Auth/DBMAuth methods can be used for access control.  The
 #     user name is the `one line' version of the client's X.509 certificate.
 #     Note that no password is obtained from the user. Every entry in the user
 #     file needs this password: `xxj31ZMTZzkVA'.
 #   o ExportCertData:
 #     This exports two additional environment variables: SSL_CLIENT_CERT and
 #     SSL_SERVER_CERT. These contain the PEM-encoded certificates of the
 #     server (always existing) and the client (only existing when client
 #     authentication is used). This can be used to import the certificates
 #     into CGI scripts.
 #   o StdEnvVars:
 #     This exports the standard SSL/TLS related `SSL_*' environment variables.
 #     Per default this exportation is switched off for performance reasons,
 #     because the extraction step is an expensive operation and is usually
 #     useless for serving static content. So one usually enables the
 #     exportation for CGI and SSI requests only.
 #   o StrictRequire:
 #     This denies access when "SSLRequireSSL" or "SSLRequire" applied even
 #     under a "Satisfy any" situation, i.e. when it applies access is denied
 #     and no other module can change it.
 #   o OptRenegotiate:
 #     This enables optimized SSL connection renegotiation handling when SSL
 #     directives are used in per-directory context.
 #SSLOptions +FakeBasicAuth +ExportCertData +StrictRequire
 
  SSLOptions +StdEnvVars
 
 
  SSLOptions +StdEnvVars
 

 #   SSL Protocol Adjustments:
 #   The safe and default but still SSL/TLS standard compliant shutdown
 #   approach is that mod_ssl sends the close notify alert but doesn't wait for
 #   the close notify alert from client. When you need a different shutdown
 #   approach you can use one of the following variables:
 #   o ssl-unclean-shutdown:
 #     This forces an unclean shutdown when the connection is closed, i.e. no
 #     SSL close notify alert is send or allowed to received.  This violates
 #     the SSL/TLS standard but is needed for some brain-dead browsers. Use
 #     this when you receive I/O errors because of the standard approach where
 #     mod_ssl sends the close notify alert.
 #   o ssl-accurate-shutdown:
 #     This forces an accurate shutdown when the connection is closed, i.e. a
 #     SSL close notify alert is send and mod_ssl waits for the close notify
 #     alert of the client. This is 100% SSL/TLS standard compliant, but in
 #     practice often causes hanging connections with brain-dead browsers. Use
 #     this only for browsers where you know that their SSL implementation
 #     works correctly.
 #   Notice: Most problems of broken clients are also related to the HTTP
 #   keep-alive facility, so you usually additionally want to disable
 #   keep-alive for those clients, too. Use variable "nokeepalive" for this.
 #   Similarly, one has to force some clients to use HTTP/1.0 to workaround
 #   their broken HTTP/1.1 implementation. Use variables "downgrade-1.0" and
 #   "force-response-1.0" for this.
 BrowserMatch "MSIE [2-6]" \
  nokeepalive ssl-unclean-shutdown \
  downgrade-1.0 force-response-1.0
 # MSIE 7 and newer should be able to use keepalive
 BrowserMatch "MSIE [17-9]" ssl-unclean-shutdown

</virtualhost>
</ifmodule>
En su contenido podemos ver la siguientes lineas:
SSLEngine on 
SSLCertificateFile /etc/ssl/certs/ssl-cert-snakeoil.pem 
SSLCertificateKeyFile /etc/ssl/private/ssl-cert-snakeoil.key

SSLEngine on : Activa o desactiva SSL
SSLCertificateFile /etc/ssl/certs/ssl-cert-snakeoil.pem : Certificado digital del propio servidor Apache
SSLCertificateKeyFile /etc/ssl/private/ssl-cert-snakeoil.key : Clave privada del servidor Apache.

Pero en su lugar tendremos que modificar esto ultimo para nuestro certificado; crearemos un certificado para acceder a nuestra pagina web de forma segura.

Lo primero es instalar el paquete openssl:

apt-get install openssl

Crearemos un certificado autofirmado para el servidor web:

mkdir /etc/apache2/mis-ssl/
make-ssl-cert /usr/share/ssl-cert/ssleay.cnf /etc/apache2/mis-ssl/apache.pem

Cuando se solicite el nombre del servidor HTTP indicamos el nombre DNS que corresponda a la IP del certificado, por ejemplo: autofirmado.ssl.test.com

Al crear otro nombre para el servidor HTTP debe resolver a una IP mediante un servidor DNS o mediante el fichero /etc/hosts , así que en ese archivo añadimos un nuevo host, y luego hacemos un reset a apache2:

127.0.0.1    autofirmado.ssl.test.com

Lo que hacemos con esto es que cuando accedamos a autofirmado.ssl.test.es, lo hacemos de forma segura.

Hay que asegurase de que el fichero /etc/apache2/ports.conf incluya el valor Listen 443, y por supuesto habilitar el soporte SSL en apache:

a2enmod ssl
a2ensite default-ssl
/etc/init.d/apache2 restart

Bien, pues ahora en el navegador, en la barra de direcciones indicamos:

https://autofirmado.ssl.test.com

Dará un aviso de Autoridad de certificación(AC), que la firma del certificado del servidor no está reconocida. Añadir la correspondiente excepción de seguridad y permitir descargar.

martes, 3 de diciembre de 2013

Configurar virtualHost

En la configuración de Apache 2, existe un directorio /etc/apache2/sites-available donde se definen los virtualhosts, cada virtualhost en un fichero de texto de configuración distinto, así crea los dos ficheros siguientes en la ruta /etc/apache2/sites-available .

Fichero configuración virtualhost: Empresa1

<VirtualHost IP_Servidor_Web:80>
   DocumentRoot /var/www/empresa1/
   ServerName www.empresa1.com.
   ServerAlias empresa1.com empresa1.es www.empresa1.es
</VirtualHost>

Fichero configuración virtualhost: Empresa2

<VirtualHost IP_Servidor_Web:80>
   DocumentRoot /var/www/empresa2/
   ServerName www.empresa2.com.
   ServerAlias empresa2.com empresa2.es www.empresa2.es
</VirtualHost>

VirtualHost IP_Servidor_Web:80 define la IP del servidor web donde se aloja la páginia de la empresa, en este caso empresa1. El puesto TCP para el protocolo HTTP por defecto es el 80, definido en la configuración principal del servidor, mediante la directiva Listen, se pueden configurar más directivas y puertos de escucha. El servidor responderá a peticiones de cualquiera de esas direcciones y puertos. Por ejemplo, para hacer que el servidor acepte conexiones en los puertos 80 y 8080, usa:

Listen 80
Listen 8080

Para hacer que el servidor acepte conexiones en dos direcciones IP y puertos diferentes,usa:
Listen 192.168.200.250:80
Listen 192.168.200.251:8080


DocumentRoot /var/www/empresa1/ : Definición de la ruta donde está alojada la página web en el servidor, en este caso: /var/www/empresa1/ mediante la directiva DocumentRoot.

ServerName www.empresa1.com : Definición del nombre DNS que buscará la página alojada en la ruta anterior del servidor mediante la directiva ServerName. Es el nombre que escribes en el navegador para visitar la página.

ServerAlias empresa1.com : La directiva ServerAlias permite definir otros nombres DNS para la misma página.

martes, 4 de diciembre de 2012

Modulos activados de Apache

Para que Apache Server funcione perfectamente tenemos que tener activado los
 siguientes módulos:

alias.conf -> ../mods-available/alias.conf
alias.load -> ../mods-available/alias.load
auth_basic.load -> ../mods-available/auth_basic.load
authn_file.load -> ../mods-available/authn_file.load
authz_default.load -> ../mods-available/authz_default.load
authz_groupfile.load -> ../mods-available/authz_groupfile.load
authz_host.load -> ../mods-available/authz_host.load
authz_user.load -> ../mods-available/authz_user.load
autoindex.conf -> ../mods-available/autoindex.conf
autoindex.load -> ../mods-available/autoindex.load
cgi.load -> ../mods-available/cgi.load
deflate.conf -> ../mods-available/deflate.conf
deflate.load -> ../mods-available/deflate.load
dir.conf -> ../mods-available/dir.conf
dir.load -> ../mods-available/dir.load
env.load -> ../mods-available/env.load
mime.conf -> ../mods-available/mime.conf
mime.load -> ../mods-available/mime.load
negotiation.conf -> ../mods-available/negotiation.conf
negotiation.load -> ../mods-available/negotiation.load
php5.conf -> ../mods-available/php5.conf
php5.load -> ../mods-available/php5.load
reqtimeout.conf -> ../mods-available/reqtimeout.conf
reqtimeout.load -> ../mods-available/reqtimeout.load
[B]rewrite.load[/B] -> ../mods-available/rewrite.load
setenvif.conf -> ../mods-available/setenvif.conf
setenvif.load -> ../mods-available/setenvif.load
status.conf -> ../mods-available/status.conf
status.load -> ../mods-available/status.load

Para la activación del modulo sería así:

sudo a2enmod rewrite

Consejo: siempre revisar configuración de un equipo que este bien configurado.

lunes, 3 de diciembre de 2012

Configuración Apache server

En la configuración de Apache Server en linux hay que mirar cual es el "site" que tenemos activado, para verlo hay que entrar en:

/etc/apache2/site-enabled/

Por defecto tienes un enlace simbólico apuntado al archivo origen que esta en /site-available/, el archivo es 000-default:

ServerAdmin info@mysite.es

#default
        DocumentRoot /var/www/
       
                Options Indexes FollowSymLinks MultiViews
                AllowOverride All
                Order allow,deny
                Allow from all
       

        ErrorLog /var/log/apache2/error.log

        # Possible values include: debug, info, notice, warn, error, crit,
        # alert, emerg.
        LogLevel warn

        CustomLog /var/log/apache2/access.log combined

    Alias /doc/ "/usr/share/doc/"
   
        Options Indexes MultiViews FollowSymLinks
        AllowOverride None
        Order deny,allow
        Deny from all
        Allow from 127.0.0.0/255.0.0.0 ::1/128
   

Podremos tener varios archivos disponibles y activar el que queramos con los comandos, siempre que estén en el directorio site-available:

a2ensite 000-default
Activa 000-default.

a2dissite 000-default 
Desactiva 000-default.

Siempre que se haga un cambio en la configuración del servidor hay que hacer un reset, para eso hay que hacer:

sudo service apache2 restart

Configuración

DocumentRoot Es una directiva en la que se especifica el directorio desde el cuál httpd servirá los ficheros. Eso quiere decir que una petición de acceso al index.html de nuestra web desde el navegador apuntará a /var/www/index.html

AllowOverride Si el valor es none los ficheros .htaccess, son ignorados, cuando es All entonces cualquier directiva que tenga Context .htaccess puede ser usada en los ficheros.

Indexes Permite el uso de directivas que controlan el indexado de directorios

Se usan para englobar un grupo de directivas que se aplicarán solamente al directorio especificado y a sus subdirectorios.

Para profundizar más en la configuración de nuestro apache entrar aquí.