RHEL7: Configure Apache group-managed content.

Share this link

Note: This is an RHCE 7 exam objective.

Prerequisites

First, follow the instructions to install an Apache web server.

Note: Don’t forget to install the httpd-manual package. This could help you a lot with any syntax issue.

Main Configuration

To allow only a group of users (here nikos and steve from the team) to access a specific directory (here private), edit the /etc/httpd/conf/httpd.conf file and paste the following lines at the end:

<Directory "/var/www/html/private">
AuthType Basic
AuthName "Password protected area"
AuthGroupFile /etc/httpd/conf/team
AuthUserFile /etc/httpd/conf/passwd
Require group team
</Directory>

Check the configuration file:

# apachectl configtest
Syntax OK

Create the /var/www/html/private directory and assign the correct SELinux context:

# mkdir -p /var/www/html/private
# restorecon -R /var/www/html/private

Create the /etc/httpd/conf/team file and paste the following line:

team: nikos steve

Create the /etc/httpd/conf/passwd file, add the nikos and steve accounts with their own passwords:

# htpasswd -c /etc/httpd/conf/passwd nikos
New password: nikos
Re-type new password: nikos
Adding password for user nikos
# htpasswd /etc/httpd/conf/passwd steve
New password: steve
Re-type new password: steve
Adding password for user steve

Restart the httpd service:

# systemctl restart httpd

Configuration Check

To check the configuration, type:

# yum install -y elinks
# elinks http://localhost/private/
(No Ratings Yet)
Loading...
11 comments on “RHEL7: Configure Apache group-managed content.
  1. chamambom says:

    @certdepot, thanks for such an awesome blog for Redhat preparation. I will be taking my exam soon and have one grey area with regard to these 2 objectives :

    – configure access restrictions on directories
    – configure group-managed content

    Correct me if I am wrong but this is how I am understanding them:

    Configure group-managed content——this one seems to be similar to setting up group authing using this config below just like how you explained it

    AuthGroupFile /etc/httpd/conf/team

    It also overlaps with this objective Configure access restrictions on directories

    on the group managed content, I have seen others doing the same configurations we do when setting up samba or nfs group collaborations

    using the chmod 2770 and chmod g+t

    I am against the chmod 2770 as the objectives seem to be in relation to access via apache not via the filesytem but I might be wrong.

    • CertDepot says:

      I think you are correct.

    • Lisenet says:

      Configure group-managed content – this is chmod 2770 (content that is managed by a group).

      Configure access restrictions on directories – this is AuthGroupFile /etc/httpd/conf/team.

      • chamambom says:

        @Lisenet, the reason why I am saying that is because htpasswd users don’t exist in the file system and the group also doesn’t exist in the filesystem [and by filesystem I mean via useradd command] … so what group would you create the users for since the auth userfile and the authgroup file have users and groups that don’t exist in /etc/passwd or group?

        • Lisenet says:

          It’s very simple, therefore I’m a bit puzzled on what you don’t understand with these objectives. Group managed content is for web developers to upload files to a webserver. We do that in production all the time, configure chmod 2770 so that devs can push changes to webroots.

          Access restrictions on directories are purely for web users to require login to be able to see content. These users don’t need nor don’t have to have Linux accounts. An example would be a WordPress login page which you want to configure restrictions on.

          • chamambom says:

            I understand them perfectly, only they seem intertwined…and as you can see @lisenet , on this post it only validates what I have been saying and while what you are saying is true ….I guess I’ll have to take the RHCE and try to read between the lines on that kind of question.

          • Lisenet says:

            This post has a misleading headline – it covers access restrictions on directories, but the title says “Configure Apache group-managed content”. This is not correct.

            By adding Apache users to the group file (AuthGroupFile) does not grant any management permissions for content, it only allows access on directories.

            There is no reading between the lines, the fact that the post has an incorrect headline doesn’t validate your statement 🙂

            CertDepot, can you fix the headline please?

          • CertDepot says:

            I understand you concern. However, can you let me what you want to change?
            The content of the tutorial or the title of the tutorial?

          • Lisenet says:

            I think that changing the title of the tutorial is sufficient.

          • CertDepot says:

            What are you proposing for the title?

          • chamambom says:

            @Lisenet ,yes group managed content is how you are explaining it ,but i guess a lot of people like me are confusing it with the apache group restricted access.I am just glad that the exams are usually explicit about what they want you to do ….. so yes ,the way you explain it is the same way that works for samba ,nfs collaborative shares .

Leave a Reply

Upcoming Events (Local Time)

There are no events.

Follow me on Twitter

Archives

vceplus-200-125    | boson-200-125    | training-cissp    | actualtests-cissp    | techexams-cissp    | gratisexams-300-075    | pearsonitcertification-210-260    | examsboost-210-260    | examsforall-210-260    | dumps4free-210-260    | reddit-210-260    | cisexams-352-001    | itexamfox-352-001    | passguaranteed-352-001    | passeasily-352-001    | freeccnastudyguide-200-120    | gocertify-200-120    | passcerty-200-120    | certifyguide-70-980    | dumpscollection-70-980    | examcollection-70-534    | cbtnuggets-210-065    | examfiles-400-051    | passitdump-400-051    | pearsonitcertification-70-462    | anderseide-70-347    | thomas-70-533    | research-1V0-605    | topix-102-400    | certdepot-EX200    | pearsonit-640-916    | itproguru-70-533    | reddit-100-105    | channel9-70-346    | anderseide-70-346    | theiia-IIA-CIA-PART3    | certificationHP-hp0-s41    | pearsonitcertification-640-916    | anderMicrosoft-70-534    | cathMicrosoft-70-462    | examcollection-cca-500    | techexams-gcih    | mslearn-70-346    | measureup-70-486    | pass4sure-hp0-s41    | iiba-640-916    | itsecurity-sscp    | cbtnuggets-300-320    | blogged-70-486    | pass4sure-IIA-CIA-PART1    | cbtnuggets-100-101    | developerhandbook-70-486    | lpicisco-101    | mylearn-1V0-605    | tomsitpro-cism    | gnosis-101    | channel9Mic-70-534    | ipass-IIA-CIA-PART1    | forcerts-70-417    | tests-sy0-401    | ipasstheciaexam-IIA-CIA-PART3    | mostcisco-300-135    | buildazure-70-533    | cloudera-cca-500    | pdf4cert-2v0-621    | f5cisco-101    | gocertify-1z0-062    | quora-640-916    | micrcosoft-70-480    | brain2pass-70-417    | examcompass-sy0-401    | global-EX200    | iassc-ICGB    | vceplus-300-115    | quizlet-810-403    | cbtnuggets-70-697    | educationOracle-1Z0-434    | channel9-70-534    | officialcerts-400-051    | examsboost-IIA-CIA-PART1    | networktut-300-135    | teststarter-300-206    | pluralsight-70-486    | coding-70-486    | freeccna-100-101    | digitaltut-300-101    | iiba-CBAP    | virtuallymikebrown-640-916    | isaca-cism    | whizlabs-pmp    | techexams-70-980    | ciscopress-300-115    | techtarget-cism    | pearsonitcertification-300-070    | testking-2v0-621    | isacaNew-cism    | simplilearn-pmi-rmp    | simplilearn-pmp    | educationOracle-1z0-809    | education-1z0-809    | teachertube-1Z0-434    | villanovau-CBAP    | quora-300-206    | certifyguide-300-208    | cbtnuggets-100-105    | flydumps-70-417    | gratisexams-1V0-605    | ituonline-1z0-062    | techexams-cas-002    | simplilearn-70-534    | pluralsight-70-697    | theiia-IIA-CIA-PART1    | itexamtips-400-051    | pearsonitcertification-EX200    | pluralsight-70-480    | learn-hp0-s42    | giac-gpen    | mindhub-102-400    | coursesmsu-CBAP    | examsforall-2v0-621    | developerhandbook-70-487    | root-EX200    | coderanch-1z0-809    | getfreedumps-1z0-062    | comptia-cas-002    | quora-1z0-809    | boson-300-135    | killtest-2v0-621    | learncia-IIA-CIA-PART3    | computer-gcih    | universitycloudera-cca-500    | itexamrun-70-410    | certificationHPv2-hp0-s41    | certskills-100-105    | skipitnow-70-417    | gocertify-sy0-401    | prep4sure-70-417    | simplilearn-cisa    |
http://www.pmsas.pr.gov.br/wp-content/    | http://www.pmsas.pr.gov.br/wp-content/    |