Skip to content

Apache (httpd)

Apache HTTP Server (httpd) is one of the most widely used web servers. This article covers installation, configuration structure, virtual hosts, module management, SSL certificates, and SELinux-related settings.

Live version data by pkgseek.com

Install Apache and common utilities using DNF:

Install Apache
sudo dnf install httpd httpd-tools -y

After installation, start the service and enable it at boot:

Start and enable httpd
sudo systemctl start httpd
sudo systemctl enable httpd

Verify the service is running:

Check httpd status
sudo systemctl status httpd

Open the HTTP and HTTPS firewall ports:

Configure firewall
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload

Open a browser and navigate to the server’s IP address. If you see the default test page, the installation was successful.

Apache configuration files are distributed across multiple directories. Understanding their structure helps with future maintenance:

PathDescription
/etc/httpd/conf/httpd.confMain configuration file
/etc/httpd/conf.d/Additional configuration fragment directory (.conf files auto-loaded)
/etc/httpd/conf.modules.d/Module loading configuration directory
/var/www/html/Default website root directory
/var/log/httpd/Log directory (access_log, error_log)

View the key parameters in the main configuration file:

View main config (filtering comments and blank lines)
grep -v '^\s*#' /etc/httpd/conf/httpd.conf | grep -v '^$'

Common global configuration directives include:

httpd.conf key directives
ServerRoot "/etc/httpd"
Listen 80
ServerAdmin root@localhost
ServerName your-domain.com:80
DocumentRoot "/var/www/html"

After modifying the configuration, always check the syntax before reloading:

Check syntax and reload
sudo apachectl configtest
sudo systemctl reload httpd

Virtual hosts allow hosting multiple websites on a single server. It is recommended to create a separate configuration file for each site in /etc/httpd/conf.d/.

Create website directory structure
sudo mkdir -p /var/www/example.com/html
sudo mkdir -p /var/www/example.com/log
echo '<h1>Welcome to example.com</h1>' | sudo tee /var/www/example.com/html/index.html

Set directory ownership:

Set directory permissions
sudo chown -R apache:apache /var/www/example.com
Create virtual host configuration file
sudo tee /etc/httpd/conf.d/example.com.conf << 'EOF'
<VirtualHost *:80>
ServerName example.com
ServerAlias www.example.com
DocumentRoot /var/www/example.com/html
ErrorLog /var/www/example.com/log/error.log
CustomLog /var/www/example.com/log/access.log combined
<Directory /var/www/example.com/html>
AllowOverride All
Require all granted
</Directory>
</VirtualHost>
EOF
Test configuration and reload
sudo apachectl configtest
sudo systemctl reload httpd

To add more sites, repeat the steps above and create the corresponding .conf files.

Apache extends functionality through modules. On EL systems, module configuration is located in the /etc/httpd/conf.modules.d/ directory.

List all loaded modules
httpd -M

Using mod_ssl and mod_rewrite as examples:

Install mod_ssl
sudo dnf install mod_ssl -y

mod_rewrite is included in the default httpd installation. Just confirm it is loaded:

Confirm mod_rewrite is loaded
httpd -M | grep rewrite

Set AllowOverride All in the virtual host or directory configuration to enable rewrite rules in .htaccess files. Create an example .htaccess:

Create .htaccess rewrite example
sudo tee /var/www/example.com/html/.htaccess << 'EOF'
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
EOF

Using a Self-Signed Certificate (Test Environment)

Section titled “Using a Self-Signed Certificate (Test Environment)”

After installing mod_ssl, a self-signed certificate is automatically generated, allowing immediate HTTPS access. The certificate is located at:

  • Certificate: /etc/pki/tls/certs/localhost.crt
  • Private key: /etc/pki/tls/private/localhost.key

Using Let’s Encrypt Free Certificates (Production)

Section titled “Using Let’s Encrypt Free Certificates (Production)”

Install Certbot:

Install Certbot
sudo dnf install epel-release -y
sudo dnf install certbot python3-certbot-apache -y

Request a certificate:

Request a certificate with Certbot
sudo certbot --apache -d example.com -d www.example.com

Certbot will automatically modify the Apache configuration and set up the HTTPS virtual host.

Test automatic renewal
sudo certbot renew --dry-run

Certbot automatically creates a systemd timer for certificate renewal. Confirm the timer is enabled:

Check renewal timer status
sudo systemctl status certbot-renew.timer

If you need to configure SSL manually, use the following template:

SSL virtual host configuration example
sudo tee /etc/httpd/conf.d/example.com-ssl.conf << 'EOF'
<VirtualHost *:443>
ServerName example.com
DocumentRoot /var/www/example.com/html
SSLEngine on
SSLCertificateFile /etc/pki/tls/certs/example.com.crt
SSLCertificateKeyFile /etc/pki/tls/private/example.com.key
SSLCertificateChainFile /etc/pki/tls/certs/chain.crt
<Directory /var/www/example.com/html>
AllowOverride All
Require all granted
</Directory>
</VirtualHost>
EOF

On SELinux-enabled systems, Apache is subject to additional security policy restrictions. Here are common scenarios and how to handle them.

Check SELinux status
getenforce
sestatus

Modify SELinux Context for Website Directories

Section titled “Modify SELinux Context for Website Directories”

If website files are placed in a non-default directory (not under /var/www/), the correct SELinux context must be set:

Set SELinux context for a custom directory
sudo semanage fcontext -a -t httpd_sys_content_t "/data/www(/.*)?"
sudo restorecon -Rv /data/www

When Apache needs to act as a reverse proxy or connect to a backend database:

Allow httpd to make network connections
sudo setsebool -P httpd_can_network_connect on
Allow httpd to connect to databases
sudo setsebool -P httpd_can_network_connect_db on
Allow httpd to send email
sudo setsebool -P httpd_can_sendmail on

If the UserDir module is enabled:

Allow httpd to access user home directories
sudo setsebool -P httpd_enable_homedirs on

If Apache listens on a non-standard port (e.g., 8080), add it to the SELinux policy:

Add custom port to SELinux
sudo semanage port -a -t http_port_t -p tcp 8080

If you encounter issues caused by SELinux, check the audit log:

Troubleshoot SELinux denial records
sudo ausearch -m avc -ts recent
sudo sealert -a /var/log/audit/audit.log

Install the setroubleshoot tool for more detailed recommendations:

Install SELinux troubleshooting tools
sudo dnf install setroubleshoot-server -y
httpd daily operations commands
# Start / Stop / Restart / Reload
sudo systemctl start httpd
sudo systemctl stop httpd
sudo systemctl restart httpd
sudo systemctl reload httpd
# View real-time access log
sudo tail -f /var/log/httpd/access_log
# View real-time error log
sudo tail -f /var/log/httpd/error_log
# View httpd version and compile parameters
httpd -V
# List all virtual host configurations
httpd -S