Apache (httpd)
Apache HTTP Server (httpd) is one of the most widely used web servers. This article covers installation, configuration structure, virtual hosts, module management, SSL certificates, and SELinux-related settings.
Versions Across Distributions
Section titled “Versions Across Distributions”Install httpd
Section titled “Install httpd”Install Apache and common utilities using DNF:
sudo dnf install httpd httpd-tools -yAfter installation, start the service and enable it at boot:
sudo systemctl start httpdsudo systemctl enable httpdVerify the service is running:
sudo systemctl status httpdOpen the HTTP and HTTPS firewall ports:
sudo firewall-cmd --permanent --add-service=httpsudo firewall-cmd --permanent --add-service=httpssudo firewall-cmd --reloadOpen a browser and navigate to the server’s IP address. If you see the default test page, the installation was successful.
Configuration File Structure
Section titled “Configuration File Structure”Apache configuration files are distributed across multiple directories. Understanding their structure helps with future maintenance:
| Path | Description |
|---|---|
/etc/httpd/conf/httpd.conf | Main configuration file |
/etc/httpd/conf.d/ | Additional configuration fragment directory (.conf files auto-loaded) |
/etc/httpd/conf.modules.d/ | Module loading configuration directory |
/var/www/html/ | Default website root directory |
/var/log/httpd/ | Log directory (access_log, error_log) |
View the key parameters in the main configuration file:
grep -v '^\s*#' /etc/httpd/conf/httpd.conf | grep -v '^$'Common global configuration directives include:
ServerRoot "/etc/httpd"Listen 80ServerAdmin root@localhostServerName your-domain.com:80DocumentRoot "/var/www/html"After modifying the configuration, always check the syntax before reloading:
sudo apachectl configtestsudo systemctl reload httpdVirtual Host Configuration
Section titled “Virtual Host Configuration”Virtual hosts allow hosting multiple websites on a single server. It is recommended to create a separate configuration file for each site in /etc/httpd/conf.d/.
Create Site Directory and Page
Section titled “Create Site Directory and Page”sudo mkdir -p /var/www/example.com/htmlsudo mkdir -p /var/www/example.com/logecho '<h1>Welcome to example.com</h1>' | sudo tee /var/www/example.com/html/index.htmlSet directory ownership:
sudo chown -R apache:apache /var/www/example.comWrite Virtual Host Configuration
Section titled “Write Virtual Host Configuration”sudo tee /etc/httpd/conf.d/example.com.conf << 'EOF'<VirtualHost *:80> ServerName example.com ServerAlias www.example.com DocumentRoot /var/www/example.com/html
ErrorLog /var/www/example.com/log/error.log CustomLog /var/www/example.com/log/access.log combined
<Directory /var/www/example.com/html> AllowOverride All Require all granted </Directory></VirtualHost>EOFVerify and Apply
Section titled “Verify and Apply”sudo apachectl configtestsudo systemctl reload httpdTo add more sites, repeat the steps above and create the corresponding .conf files.
Enable and Manage Modules
Section titled “Enable and Manage Modules”Apache extends functionality through modules. On EL systems, module configuration is located in the /etc/httpd/conf.modules.d/ directory.
View Loaded Modules
Section titled “View Loaded Modules”httpd -MInstall Additional Modules
Section titled “Install Additional Modules”Using mod_ssl and mod_rewrite as examples:
sudo dnf install mod_ssl -ymod_rewrite is included in the default httpd installation. Just confirm it is loaded:
httpd -M | grep rewriteEnable .htaccess Rewrites
Section titled “Enable .htaccess Rewrites”Set AllowOverride All in the virtual host or directory configuration to enable rewrite rules in .htaccess files. Create an example .htaccess:
sudo tee /var/www/example.com/html/.htaccess << 'EOF'RewriteEngine OnRewriteCond %{HTTPS} offRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]EOFSSL/TLS Configuration
Section titled “SSL/TLS Configuration”Using a Self-Signed Certificate (Test Environment)
Section titled “Using a Self-Signed Certificate (Test Environment)”After installing mod_ssl, a self-signed certificate is automatically generated, allowing immediate HTTPS access. The certificate is located at:
- Certificate:
/etc/pki/tls/certs/localhost.crt - Private key:
/etc/pki/tls/private/localhost.key
Using Let’s Encrypt Free Certificates (Production)
Section titled “Using Let’s Encrypt Free Certificates (Production)”Install Certbot:
sudo dnf install epel-release -ysudo dnf install certbot python3-certbot-apache -yRequest a certificate:
sudo certbot --apache -d example.com -d www.example.comCertbot will automatically modify the Apache configuration and set up the HTTPS virtual host.
Set Up Automatic Renewal
Section titled “Set Up Automatic Renewal”sudo certbot renew --dry-runCertbot automatically creates a systemd timer for certificate renewal. Confirm the timer is enabled:
sudo systemctl status certbot-renew.timerManual SSL Virtual Host Configuration
Section titled “Manual SSL Virtual Host Configuration”If you need to configure SSL manually, use the following template:
sudo tee /etc/httpd/conf.d/example.com-ssl.conf << 'EOF'<VirtualHost *:443> ServerName example.com DocumentRoot /var/www/example.com/html
SSLEngine on SSLCertificateFile /etc/pki/tls/certs/example.com.crt SSLCertificateKeyFile /etc/pki/tls/private/example.com.key SSLCertificateChainFile /etc/pki/tls/certs/chain.crt
<Directory /var/www/example.com/html> AllowOverride All Require all granted </Directory></VirtualHost>EOFSELinux and httpd
Section titled “SELinux and httpd”On SELinux-enabled systems, Apache is subject to additional security policy restrictions. Here are common scenarios and how to handle them.
Check Current SELinux Status
Section titled “Check Current SELinux Status”getenforcesestatusModify SELinux Context for Website Directories
Section titled “Modify SELinux Context for Website Directories”If website files are placed in a non-default directory (not under /var/www/), the correct SELinux context must be set:
sudo semanage fcontext -a -t httpd_sys_content_t "/data/www(/.*)?"sudo restorecon -Rv /data/wwwAllow httpd to Make Network Connections
Section titled “Allow httpd to Make Network Connections”When Apache needs to act as a reverse proxy or connect to a backend database:
sudo setsebool -P httpd_can_network_connect onAllow httpd to Connect to Databases
Section titled “Allow httpd to Connect to Databases”sudo setsebool -P httpd_can_network_connect_db onAllow httpd to Send Email
Section titled “Allow httpd to Send Email”sudo setsebool -P httpd_can_sendmail onAllow httpd to Read User Home Directories
Section titled “Allow httpd to Read User Home Directories”If the UserDir module is enabled:
sudo setsebool -P httpd_enable_homedirs onUse Non-Standard Ports
Section titled “Use Non-Standard Ports”If Apache listens on a non-standard port (e.g., 8080), add it to the SELinux policy:
sudo semanage port -a -t http_port_t -p tcp 8080Troubleshoot SELinux Denials
Section titled “Troubleshoot SELinux Denials”If you encounter issues caused by SELinux, check the audit log:
sudo ausearch -m avc -ts recentsudo sealert -a /var/log/audit/audit.logInstall the setroubleshoot tool for more detailed recommendations:
sudo dnf install setroubleshoot-server -yCommon Operations Quick Reference
Section titled “Common Operations Quick Reference”# Start / Stop / Restart / Reloadsudo systemctl start httpdsudo systemctl stop httpdsudo systemctl restart httpdsudo systemctl reload httpd
# View real-time access logsudo tail -f /var/log/httpd/access_log
# View real-time error logsudo tail -f /var/log/httpd/error_log
# View httpd version and compile parametershttpd -V
# List all virtual host configurationshttpd -SFurther Reading
Section titled “Further Reading”- Nginx Reverse Proxy — Alternative web server
- Getting Started with SELinux — Understanding SELinux’s impact on web services