Showing posts with label Apache. Show all posts
Showing posts with label Apache. Show all posts

Tuesday, May 18, 2021

How to Proxy Secure WebSockets (WSS) in a Subfolder with Apache mod_proxy_wstunnel

Routing secure WebSocket connections (wss://) originating from a specific URL subfolder (such as /websocket1) to a local backend daemon (running on an internal TCP port like 2085) requires configuring Apache's mod_proxy_wstunnel.

Prerequisites: Enable Apache modules: proxy, proxy_http, proxy_wstunnel, and rewrite.

Apache VirtualHost Configuration

# Enable proxy tunneling for WebSockets
RewriteEngine On

# Detect WebSocket upgrade request headers for /websocket1
RewriteCond %{REQUEST_URI} ^/websocket1 [NC]
RewriteCond %{HTTP:Upgrade} websocket [NC]
RewriteCond %{HTTP:Connection} upgrade [NC]
RewriteRule ^/websocket1/(.*)$ ws://127.0.0.1:2085/$1 [P,L]

# Normal HTTP proxy fallback (if needed):
ProxyPass /websocket1 http://127.0.0.1:2085/
ProxyPassReverse /websocket1 http://127.0.0.1:2085/

Reload Apache to apply:

sudo systemctl reload apache2

Wednesday, July 8, 2020

How to Rebuild Apache httpd to Change suexec AP_DOC_ROOT from /var/www to /home (CentOS & RHEL)

Standard RPM packages of Apache httpd in CentOS and RHEL compile suexec with a hardcoded document root of /var/www (--with-suexec-docroot=/var/www). However, web control panels like Virtualmin host customer accounts under /home. When suexec executes a user script under /home, it aborts with "command not in docroot". Here is how to rebuild the official upstream httpd SRPM with AP_DOC_ROOT set to /home.

Compilation Flag: --with-suexec-docroot=/home

Rebuilding the RPM

# 1. Install build tools and dependencies
yum install rpm-build redhat-rpm-config gcc make -y
yum-builddep httpd -y

# 2. Download and unpack httpd SRPM
mkdir -p ~/rpmbuild/{BUILD,RPMS,SOURCES,SPECS,SRPMS}
cd ~/rpmbuild/SRPMS
yumdownloader --source httpd
rpm -ivh httpd-*.src.rpm

# 3. Edit SPECS/httpd.spec and modify suexec docroot
cd ~/rpmbuild/SPECS
sed -i 's|--with-suexec-docroot=/var/www|--with-suexec-docroot=/home|g' httpd.spec

# 4. Rebuild binary RPM
rpmbuild -bb httpd.spec

# 5. Install the custom suexec binary
rpm -Uvh --force ~/rpmbuild/RPMS/x86_64/httpd-*.rpm

Confirm the new docroot:

suexec -V | grep AP_DOC_ROOT

Monday, June 22, 2020

[Solved] Fixing Apache suexec and mod_fcgid: Error Reading Data from FastCGI Server

When running PHP applications under Apache using mod_fcgid combined with suexec privilege separation, web requests may suddenly abort with HTTP 500 Internal Server Errors and the following message in Apache error logs:

Error Message: End of script output before headers: php.fcgi • mod_fcgid: error reading data from FastCGI server

Root Cause

suexec enforces strict security checks on the FastCGI wrapper script and user directory:

  1. The wrapper script and parent directories must be owned exclusively by the virtual server user and group—not root or apache.
  2. File permissions cannot be group-writeable (chmod 755 is required, 775 or 777 causes instant suexec rejection).
  3. The target script must reside strictly inside the compiled suexec document root (e.g. /home/user/public_html).

Resolution Steps

Inspect /var/log/httpd/suexec.log to reveal the exact permission violation, and enforce correct ownership:

# Fix permissions and ownership
chown -R user:user /home/user/fcgi-bin /home/user/public_html
chmod 755 /home/user/fcgi-bin/php.fcgi
chmod 755 /home/user/public_html

Wednesday, July 31, 2013

How to Install mod_flvx and mod_h264_streaming on cPanel Apache 2

Serving progressive download video files (such as MP4 and FLV) with seeking capabilities directly from Apache on a cPanel/WHM server requires compiling custom Apache modules: mod_flvx for FLV streaming and mod_h264_streaming for pseudo-streaming H.264/MP4 files.

Environment: cPanel / WHM • EasyApache • Apache 2.2 / 2.4 • H.264 / FLV Streaming

1. Persistent Hook Script

To ensure modules are compiled and reinstalled automatically whenever cPanel runs EasyApache, add the build commands to /scripts/after_apache_make_install:

#!/bin/bash
cd /usr/local/src

# Compile mod_flvx
wget http://people.apache.org/~pquerna/modules/mod_flvx.c
/usr/local/apache/bin/apxs -i -c mod_flvx.c

# Compile mod_h264_streaming
wget http://h264.code-shop.com/download/apache_mod_h264_streaming-2.2.7.tar.gz
tar -zxvf apache_mod_h264_streaming-2.2.7.tar.gz
cd mod_h264_streaming-2.2.7
./configure --with-apxs='/usr/local/apache/bin/apxs'
make && make install

# Update cPanel Apache configuration distiller
/usr/local/cpanel/bin/apache_conf_distiller --update

Ensure the hook script is executable:

chmod +x /scripts/after_apache_make_install

2. Apache Global Configuration

Add the module declarations and file extension handlers to /usr/local/apache/conf/includes/pre_virtualhost_global.conf:

LoadModule h264_streaming_module modules/mod_h264_streaming.so
<IfModule mod_h264_streaming.c>
    AddHandler h264-streaming.extensions .mp4
</IfModule>

LoadModule flvx_module modules/mod_flvx.so
<IfModule mod_flvx.c>
    AddHandler flv-stream .flv
</IfModule>

3. Rebuild with EasyApache

Execute EasyApache through WHM or the command line to finalize the build. Once complete, video seeking will work seamlessly over HTTP.

Friday, August 3, 2012

How to Configure PHP-FPM and Apache 2.4 with mod_proxy_fcgi in Virtualmin (CentOS & Debian)

The Apache 2.4 series introduced mod_proxy_fcgi, enabling Apache to communicate directly with PHP-FPM via TCP/IP sockets without requiring older third-party modules like mod_fastcgi or mod_fcgid. This setup provides superior performance and memory isolation for multi-tenant web servers running Virtualmin.

Environment: Apache 2.4.x • PHP-FPM 5.x • Virtualmin • CentOS 6 / Debian 6

1. Installing PHP-FPM

Install the latest PHP-FPM packages using Remi (CentOS) or Dotdeb (Debian):

# On CentOS:
yum install php-fpm -y

# On Debian:
apt-get install php5-fpm -y

2. Compiling Apache 2.4 from Source (CentOS 6)

If your distribution does not ship Apache 2.4 in its default repositories, compile from source with event MPM and mod_proxy_fcgi:

yum install pcre-devel -y
cd /usr/src
wget https://archive.apache.org/dist/httpd/httpd-2.4.25.tar.bz2
wget https://archive.apache.org/dist/apr/apr-1.5.2.tar.bz2
wget https://archive.apache.org/dist/apr/apr-util-1.5.4.tar.bz2

tar -jxf httpd-2.4.25.tar.bz2
tar -jxf apr-1.5.2.tar.bz2
tar -jxf apr-util-1.5.4.tar.bz2

mv apr-1.5.2 httpd-2.4.25/srclib/apr
mv apr-util-1.5.4 httpd-2.4.25/srclib/apr-util

cd httpd-2.4.25
./configure --prefix=/opt/apache2 --with-mpm=event --enable-rewrite --enable-proxy --enable-proxy-fcgi --enable-ssl --with-included-apr
make && make install

3. Virtualmin Apache VirtualHost Integration

To route PHP requests from Virtualmin virtual hosts to their respective PHP-FPM pools via mod_proxy_fcgi, configure the VirtualHost directive:

<VirtualHost *:80>
    ServerName example.com
    DocumentRoot /home/example/public_html

    ProxyPassMatch ^/(.*\.php(/.*)?)$ fcgi://127.0.0.1:9000/home/example/public_html/$1

    <Directory /home/example/public_html>
        Options -Indexes +FollowSymLinks
        AllowOverride All
        Require all granted
    </Directory>
</VirtualHost>

This allows each virtual server in Virtualmin to leverage isolated PHP-FPM user pools with event-driven concurrency.

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...