RHEL7: Deploy an Apache basic CGI application.

Share this link

Note: This is an RHCE 7 exam objective.

Prerequisites

First, follow the instructions to install an Apache web server.

Configuration Procedure

Create the /var/www/cgi-bin/hello.pl Perl script and insert the following lines:

#!/usr/bin/perl
print "Content-type: text/html\n\n";
print "Hello, World!";

Make this script executable:

# chmod 755 /var/www/cgi-bin/hello.pl

Restart the httpd service:

# systemctl restart httpd

Check the SELinux httpd_enable_cgi boolean is on (it is on by default):

# getsebool httpd_enable_cgi
httpd_enable_cgi --> on

Note: Another SELinux boolean useful to remember is httpd_can_sendmail: it allows the httpd server to send emails.

Check the httpd service:

# yum install -y elinks
# elinks http://localhost/cgi-bin/hello.pl

Alternatively, if you want to use a directory other than the /var/www/cgi-bin/ default (/webapp for example), you will have some additional steps.

Create the /webapp directory:

# mkdir /webapp

Move the hello.pl file into it:

# mv /var/www/cgi-bin/hello.pl /webapp

Set up SElinux configuration for the /webapp directory:

# yum install -y setroubleshoot-server
# semanage fcontext -a -t httpd_sys_script_exec_t "/webapp(/.*)?"
# restorecon -R /webappelinks /usr/share/httpd/manual/howto/cgi.html

Edit the /etc/httpd/conf/httpd.conf file and replace the ‘ScriptAlias‘ option with the following line:

ScriptAlias /cgi-bin/ "/webapp/"

In the same file, where the configuration of your website (or virtual host) is located, add the following lines:

<Directory "/webapp">
AllowOverride None
Options None
Require all granted
</Directory>

In the same stanza, you can optionally add the following lines (but it doesn’t seem mandatory):

Options ExecCGI
AddHandler cgi-script .pl

Check the configuration file:

# apachectl configtest
Syntax OK

Restart the httpd service:

# systemctl restart httpd

Testing Time

Check the execution of the Perl script:

# yum install -y elinks
# elinks http://localhost/cgi-bin/hello.pl

Useful Tip

If you don’t remember the syntax of any directive, type:

# yum -y install httpd-manual
# elinks /usr/share/httpd/manual/howto/cgi.html
(4 votes, average: 5.00 out of 5)
Loading...
14 comments on “RHEL7: Deploy an Apache basic CGI application.
  1. codingberg says:

    “Options ExecCGI” and “AddHandler cgi-script .pl” should be added only if you don’t specify ScriptAlias directive within VirtualHost. Otherwise, if you use ScriptAlias you can indeed skip it.

  2. alexritm says:

    do I need to use particularly a Perl test script for this task? or it can be PHP or Python one? or it can be requested to deploy any of them on the exam?

  3. Jaz says:

    You should also include how to work on WSGI script followed by mod_wsgi package.

  4. twostep says:

    When the problem is with opening cgi page “500 Internal Server Error”, you have to verify also the httpd error log file, because when selinux is not set properly, the warning is not displaying in /var/log/audit/audit.log,
    but in /var/log/httpd/error_log only.

    According to http://selinuxproject.org/page/NB_AL:
    “…It is not mandatory for SELinux-aware applications to audit events or even log them in the audit log. The decision is made by the application designer.”

  5. jeromeza says:

    For examples on syntax it’s easier to check the httpd manual:

    yum -y install httpd-manual
    elinks /usr/share/httpd/manual/howto/cgi.html

  6. ehasbun says:

    How about wsgi scripts? Are those worth learning?

  7. jank says:

    I wonder, do you need to hardcode the cgi script into the apache configuration
    e.g.
    ScriptAlias /cgi-bin/ “/webapp/cgi.html”
    versus
    ScriptAlias /cgi-bin/ “/webapp/”

    The first one if you do a
    elinks http://localhost/cgi-bin/
    versus
    elinks http://localhost/cgi-bin/cgi.html

    Both are correct are but is there a best practice?

    • Sam says:

      Think about the problem this way: which is the most effective and gives you the more versatile options. If you are doing the exam, answer the question given.
      From a practical point of view, how would you access multiple script files?

Leave a Reply

Upcoming Events (Local Time)

There are no events.

Follow me on Twitter

Archives

vceplus-200-125    | boson-200-125    | training-cissp    | actualtests-cissp    | techexams-cissp    | gratisexams-300-075    | pearsonitcertification-210-260    | examsboost-210-260    | examsforall-210-260    | dumps4free-210-260    | reddit-210-260    | cisexams-352-001    | itexamfox-352-001    | passguaranteed-352-001    | passeasily-352-001    | freeccnastudyguide-200-120    | gocertify-200-120    | passcerty-200-120    | certifyguide-70-980    | dumpscollection-70-980    | examcollection-70-534    | cbtnuggets-210-065    | examfiles-400-051    | passitdump-400-051    | pearsonitcertification-70-462    | anderseide-70-347    | thomas-70-533    | research-1V0-605    | topix-102-400    | certdepot-EX200    | pearsonit-640-916    | itproguru-70-533    | reddit-100-105    | channel9-70-346    | anderseide-70-346    | theiia-IIA-CIA-PART3    | certificationHP-hp0-s41    | pearsonitcertification-640-916    | anderMicrosoft-70-534    | cathMicrosoft-70-462    | examcollection-cca-500    | techexams-gcih    | mslearn-70-346    | measureup-70-486    | pass4sure-hp0-s41    | iiba-640-916    | itsecurity-sscp    | cbtnuggets-300-320    | blogged-70-486    | pass4sure-IIA-CIA-PART1    | cbtnuggets-100-101    | developerhandbook-70-486    | lpicisco-101    | mylearn-1V0-605    | tomsitpro-cism    | gnosis-101    | channel9Mic-70-534    | ipass-IIA-CIA-PART1    | forcerts-70-417    | tests-sy0-401    | ipasstheciaexam-IIA-CIA-PART3    | mostcisco-300-135    | buildazure-70-533    | cloudera-cca-500    | pdf4cert-2v0-621    | f5cisco-101    | gocertify-1z0-062    | quora-640-916    | micrcosoft-70-480    | brain2pass-70-417    | examcompass-sy0-401    | global-EX200    | iassc-ICGB    | vceplus-300-115    | quizlet-810-403    | cbtnuggets-70-697    | educationOracle-1Z0-434    | channel9-70-534    | officialcerts-400-051    | examsboost-IIA-CIA-PART1    | networktut-300-135    | teststarter-300-206    | pluralsight-70-486    | coding-70-486    | freeccna-100-101    | digitaltut-300-101    | iiba-CBAP    | virtuallymikebrown-640-916    | isaca-cism    | whizlabs-pmp    | techexams-70-980    | ciscopress-300-115    | techtarget-cism    | pearsonitcertification-300-070    | testking-2v0-621    | isacaNew-cism    | simplilearn-pmi-rmp    | simplilearn-pmp    | educationOracle-1z0-809    | education-1z0-809    | teachertube-1Z0-434    | villanovau-CBAP    | quora-300-206    | certifyguide-300-208    | cbtnuggets-100-105    | flydumps-70-417    | gratisexams-1V0-605    | ituonline-1z0-062    | techexams-cas-002    | simplilearn-70-534    | pluralsight-70-697    | theiia-IIA-CIA-PART1    | itexamtips-400-051    | pearsonitcertification-EX200    | pluralsight-70-480    | learn-hp0-s42    | giac-gpen    | mindhub-102-400    | coursesmsu-CBAP    | examsforall-2v0-621    | developerhandbook-70-487    | root-EX200    | coderanch-1z0-809    | getfreedumps-1z0-062    | comptia-cas-002    | quora-1z0-809    | boson-300-135    | killtest-2v0-621    | learncia-IIA-CIA-PART3    | computer-gcih    | universitycloudera-cca-500    | itexamrun-70-410    | certificationHPv2-hp0-s41    | certskills-100-105    | skipitnow-70-417    | gocertify-sy0-401    | prep4sure-70-417    | simplilearn-cisa    |
http://www.pmsas.pr.gov.br/wp-content/    | http://www.pmsas.pr.gov.br/wp-content/    |