Showing posts with label Virtualmin. Show all posts
Showing posts with label Virtualmin. Show all posts

Wednesday, July 8, 2020

How to Rebuild Apache httpd to Change suexec AP_DOC_ROOT from /var/www to /home (CentOS & RHEL)

Standard RPM packages of Apache httpd in CentOS and RHEL compile suexec with a hardcoded document root of /var/www (--with-suexec-docroot=/var/www). However, web control panels like Virtualmin host customer accounts under /home. When suexec executes a user script under /home, it aborts with "command not in docroot". Here is how to rebuild the official upstream httpd SRPM with AP_DOC_ROOT set to /home.

Compilation Flag: --with-suexec-docroot=/home

Rebuilding the RPM

# 1. Install build tools and dependencies
yum install rpm-build redhat-rpm-config gcc make -y
yum-builddep httpd -y

# 2. Download and unpack httpd SRPM
mkdir -p ~/rpmbuild/{BUILD,RPMS,SOURCES,SPECS,SRPMS}
cd ~/rpmbuild/SRPMS
yumdownloader --source httpd
rpm -ivh httpd-*.src.rpm

# 3. Edit SPECS/httpd.spec and modify suexec docroot
cd ~/rpmbuild/SPECS
sed -i 's|--with-suexec-docroot=/var/www|--with-suexec-docroot=/home|g' httpd.spec

# 4. Rebuild binary RPM
rpmbuild -bb httpd.spec

# 5. Install the custom suexec binary
rpm -Uvh --force ~/rpmbuild/RPMS/x86_64/httpd-*.rpm

Confirm the new docroot:

suexec -V | grep AP_DOC_ROOT

Wednesday, June 3, 2020

How to Install Virtualmin with Multiple PHP and MySQL Versions on CentOS 8

Deploying a production web hosting stack on CentOS 8 with Virtualmin requires modern multi-PHP support (allowing legacy applications to run PHP 5.6 or 7.2 while modern apps run PHP 7.4 or 8.0) and reliable database server management via Remi repositories.

Stack: CentOS 8 • Virtualmin 6.x • Remi Software Collections (SCL) • MySQL 8.0 • Multi-PHP

1. Fix Perl UTF-8 Locale Warnings

cat << 'EOF' > /etc/environment
LANGUAGE=en_US.utf8
LC_ALL=en_US.utf-8
LANG=en_US.utf8
LC_TYPE=en_US.utf8
EOF

2. Enable EPEL and Remi Repositories

dnf install epel-release -y
dnf install https://rpms.remirepo.net/enterprise/remi-release-8.rpm -y
dnf module reset php -y
dnf module enable php:remi-7.4 -y

3. Installing Parallel PHP Versions

dnf install php56-php-fpm php72-php-fpm php74-php-fpm php80-php-fpm -y

4. Install Virtualmin

wget http://software.virtualmin.com/gpl/scripts/install.sh
sh install.sh

Wednesday, October 22, 2014

Automating Low-Cost Server Backups to Amazon Glacier with glacier-cmd (cPanel & Virtualmin)

Amazon Glacier provides an extremely cost-effective cold-storage solution for archiving periodic server backups (such as weekly full-system and MySQL snapshots) without paying standard S3 active storage pricing. Here is how to configure automated Glacier uploads using the command-line utility glacier-cmd on cPanel and Virtualmin servers.

Components: Amazon Glacier Vault • glacier-cmd Python CLI • Automated root cron backup workflow

1. Installing glacier-cmd

Install Python setup tools and the Glacier command-line interface:

yum install git python python-setuptools -y
cd /usr/src

# For cPanel servers, link git to system path if needed:
[ ! -f /usr/bin/git ] && ln -s /usr/local/cpanel/3rdparty/bin/git /usr/bin/git

git clone https://github.com/uskudnik/amazon-glacier-cmd-interface
cd amazon-glacier-cmd-interface
python setup.py install

2. Configuring AWS Credentials

Create ~/.glacier-cmd in the root home directory:

[aws]
access_key=YOUR_AWS_ACCESS_KEY_ID
secret_key=YOUR_AWS_SECRET_ACCESS_KEY

[glacier]
region=us-east-1
bookkeeping=True
bookkeeping-sqlite-db=/root/.glacier-cmd-db

3. Uploading Backups to a Vault

Create your backup vault and upload archives with automatic multipart chunking:

# Create a new vault
glacier-cmd mkvault server-backups

# Upload a backup archive with description
glacier-cmd upload --description "cPanel Weekly Full Backup $(date +%Y-%m-%d)" server-backups /backup/weekly-backup.tar.gz

Friday, August 3, 2012

How to Configure PHP-FPM and Apache 2.4 with mod_proxy_fcgi in Virtualmin (CentOS & Debian)

The Apache 2.4 series introduced mod_proxy_fcgi, enabling Apache to communicate directly with PHP-FPM via TCP/IP sockets without requiring older third-party modules like mod_fastcgi or mod_fcgid. This setup provides superior performance and memory isolation for multi-tenant web servers running Virtualmin.

Environment: Apache 2.4.x • PHP-FPM 5.x • Virtualmin • CentOS 6 / Debian 6

1. Installing PHP-FPM

Install the latest PHP-FPM packages using Remi (CentOS) or Dotdeb (Debian):

# On CentOS:
yum install php-fpm -y

# On Debian:
apt-get install php5-fpm -y

2. Compiling Apache 2.4 from Source (CentOS 6)

If your distribution does not ship Apache 2.4 in its default repositories, compile from source with event MPM and mod_proxy_fcgi:

yum install pcre-devel -y
cd /usr/src
wget https://archive.apache.org/dist/httpd/httpd-2.4.25.tar.bz2
wget https://archive.apache.org/dist/apr/apr-1.5.2.tar.bz2
wget https://archive.apache.org/dist/apr/apr-util-1.5.4.tar.bz2

tar -jxf httpd-2.4.25.tar.bz2
tar -jxf apr-1.5.2.tar.bz2
tar -jxf apr-util-1.5.4.tar.bz2

mv apr-1.5.2 httpd-2.4.25/srclib/apr
mv apr-util-1.5.4 httpd-2.4.25/srclib/apr-util

cd httpd-2.4.25
./configure --prefix=/opt/apache2 --with-mpm=event --enable-rewrite --enable-proxy --enable-proxy-fcgi --enable-ssl --with-included-apr
make && make install

3. Virtualmin Apache VirtualHost Integration

To route PHP requests from Virtualmin virtual hosts to their respective PHP-FPM pools via mod_proxy_fcgi, configure the VirtualHost directive:

<VirtualHost *:80>
    ServerName example.com
    DocumentRoot /home/example/public_html

    ProxyPassMatch ^/(.*\.php(/.*)?)$ fcgi://127.0.0.1:9000/home/example/public_html/$1

    <Directory /home/example/public_html>
        Options -Indexes +FollowSymLinks
        AllowOverride All
        Require all granted
    </Directory>
</VirtualHost>

This allows each virtual server in Virtualmin to leverage isolated PHP-FPM user pools with event-driven concurrency.

Tuesday, July 3, 2012

How to Fix Postfix SASL Authentication Failure and Chroot Errors with saslauthd

When configuring Cyrus SASL (saslauthd) to authenticate SMTP users in Postfix on CentOS / RHEL with Virtualmin, you may encounter persistent user/password authentication failures even when credentials are valid.

Environment: CentOS 6.x / RHEL • Virtualmin • Postfix • Cyrus SASL (saslauthd)

1. Identifying the Symptom: /var/log/maillog

Checking /var/log/maillog often reveals that Postfix cannot communicate with the SASL authentication daemon:

warning: SASL authentication failure: cannot connect to saslauthd server: No such file or directory

2. The Chroot Trap and Secondary SMTP Failures

A common workaround suggested in forums is moving or binding the saslauthd socket into the Postfix spool directory (e.g. /var/spool/postfix/var/run/saslauthd). While that may resolve socket visibility, running Postfix processes inside a chroot jail introduces a severe secondary failure: outbound emails will fail to send entirely.

You will see delivery attempts stall in the active queue with errors like:

postfix/qmgr: from=<root@domain.com>, size=421, nrcpt=1 (queue active)
postfix/smtp: fatal: unknown service: smtp/tcp
postfix/qmgr: warning: private/smtp socket: malformed response
postfix/qmgr: warning: transport smtp failure -- see a previous warning/fatal/panic logfile record for the problem description
postfix/master: warning: process /usr/libexec/postfix/smtp pid 29443 exit status 1
postfix/master: warning: /usr/libexec/postfix/smtp: bad command startup -- throttling
postfix/error: to=<user@example.com>, relay=none, delay=1.1, delays=0.1/1/0/0.03, dsn=4.3.0, status=deferred (unknown mail transport error)

Root Cause: When the Postfix smtp client daemon runs chrooted, it cannot access /etc/services to resolve the network port name smtp/tcp, causing the transport to abort and defer all outgoing mail.

3. The Permanent Solution: Disable Chroot for SMTP

To resolve both the SASL socket communication and the transport errors cleanly, configure the Postfix smtp process to run unchrooted.

Step 1: Edit master.cf

Open /etc/postfix/master.cf in your text editor:

nano /etc/postfix/master.cf

Locate the smtp service definition:

# ==========================================================================
# service type  private unpriv  chroot  wakeup  maxproc command + args
#               (yes)   (yes)   (yes)   (never) (100)
# ==========================================================================
smtp      unix  -       -       -       -       -       smtp

The 5th column controls chroot. A hyphen (-) defaults to enabled (yes). Change the 5th column from - (or y) to n:

smtp      unix  -       -       n       -       -       smtp

Step 2: Restart Services

Restart both saslauthd and postfix so the configuration changes take effect:

service saslauthd restart
service postfix restart

4. Verification

Once services are restarted, monitor the mail log while sending a test message or authenticating a mail client:

tail -f /var/log/maillog

SASL authentication will succeed immediately without socket connection errors, and the mail queue will flush smoothly without transport or chroot exceptions.

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...