Xen 07 - domU - WWW system - apache2 + mod_security2 + mod_suphp + php5 + php5_suhosin
Xen on Debian 4 Learning · Previous: domU - Base (Golden image) · Next: domU - DNS system - djbdns
The Slovak original of this document: Xen 07 - domU - WWW system - apache2 + mod_security2 + mod_suphp + php5 + php5_suhosin (slovensky).
|=---------------------------------=[ XEN ]=-------------------------------=| +---------------------------------------------------------------------------+ | | | XEN-server domU (REAL SERVER HW) | | Debian 4.0 Etch | | WWW SYSTEM | | | +---------------------------------------------------------------------------+ |=-------------------------------=[ BH 2008 ]=-----------------------------=| The BASE system is what further virtual machines are built from.
1. Creating a new virtual machine
Creating the logical partitions for the new system
==================================================
# lvcreate -L 1.5G -n www-disk system_vhosts
# lvcreate -L 1G -n www-var system_vhosts
# lvcreate -L 1G -n www-varlog system_vhosts
# lvcreate -L 0.5G -n www-tmp system_vhosts
# lvcreate -L 2G -n www-usr system_vhosts
# lvcreate -L 0.5G -n www-swap system_vhosts
# mkswap /dev/system_vhosts/www-swap
Creating the VM from the base LVM partitions (snapshots)
========================================================
# lvcreate -s -L 1.5G -n snap-base-disk /dev/system_vhosts/base-disk
# lvcreate -s -L 1G -n snap-base-var /dev/system_vhosts/base-var
# lvcreate -s -L 1G -n snap-base-varlog /dev/system_vhosts/base-varlog
# lvcreate -s -L 0.5G -n snap-base-tmp /dev/system_vhosts/base-tmp
# lvcreate -s -L 2G -n snap-base-usr /dev/system_vhosts/base-usr
# lvcreate -s -L 0.5G -n snap-base-swap /dev/system_vhosts/base-swap
# dd if=/dev/system_vhosts/snap-base-disk of=/dev/system_vhosts/www-disk bs=1024k // (1610612736 bytes (1.6 GB) copied, 50.4256 seconds, 31.9 MB/s)
# dd if=/dev/system_vhosts/snap-base-var of=/dev/system_vhosts/www-var bs=1024k // (1073741824 bytes (1.1 GB) copied, 33.2976 seconds, 32.2 MB/s)
# dd if=/dev/system_vhosts/snap-base-varlog of=/dev/system_vhosts/www-varlog bs=1024k // (1073741824 bytes (1.1 GB) copied, 33.5406 seconds, 32.0 MB/s)
# dd if=/dev/system_vhosts/snap-base-tmp of=/dev/system_vhosts/www-tmp bs=1024k // (536870912 bytes (537 MB) copied, 16.2542 seconds, 33.0 MB/s)
# dd if=/dev/system_vhosts/snap-base-usr of=/dev/system_vhosts/www-usr bs=1024k // (2147483648 bytes (2.1 GB) copied, 66.4581 seconds, 32.3 MB/s)
Config of the newly created system
==================================
# cp /etc/xen/base.cfg /etc/xen/www.cfg
# nano /etc/xen/www.cfg
-----------------------
disk = [ 'phy:system_vhosts/www-disk,sda1,w', 'phy:system_vhosts/www-swap,sda2,w', 'phy:system_vhosts/www-var,sda3,w', 'phy:system_vhosts/www-varlog,sda4,w', 'phy:system_vhosts/www-tmp,sda5,w', 'phy:system_vhosts/www-usr,sda6,w' ]
name = 'www'
vif = [ 'ip=10.0.0.2' ]
Starting the new system
=======================
# xm create -c www.cfg
Configuring the domU - www
===========================
# nano /etc/hostname
--------------------
www
# nano /etc/network/interfaces
------------------------------
auto eth0
iface eth0 inet static
address 10.0.0.2
gateway 10.0.0.254
netmask 255.0.0.0
-------------------------------2. Setting up the network (NAT-ed network)
----
dom0
----
# nano /etc/xen/xend-config.sxp
-------------------------------
(network-script network-nat)
(vif-script vif-nat)
Enable SNAT for the network 10.0.0.0/255.0.0.0
----------------------------------------------
# iptables -t nat -A POSTROUTING -s 10.0.0.0/255.0.0.0 -j SNAT --to-source 192.168.254.254
Redirect requests for 192.168.254.254:22222 to 10.0.0.2:22
----------------------------------------------------------
# iptables -t nat -A PREROUTING -p tcp -s xx.xx.xx.xx -d 192.168.254.254 --dport 22222 -j DNAT --to-destination 10.0.0.2:223. Installing the web server (apache2) + mod_suphp + php5 + php5_suhosin + php5_mysql + php5_pgsql
Switch to the console of the web server
---------------------------------------
# xm console www
Mod_security
==============
Adding the GPG key of the Debian developer of mod_security (Alberto Gonzalez Iniesta)
# gpg --keyserver pgpkeys.pca.dfn.de --recv-keys C514AF8E4BA401C3
# gpg --fingerprint C514AF8E4BA401C3
# gpg --export -a C514AF8E4BA401C3 | apt-key add -
Adding the package source for mod_security to sources.list
==========================================================
# nano /etc/apt/sources.list
----------------------------
# mod_security for apache
deb http://etc.inittab.org/~agi/debian/libapache-mod-security2/ etch/
---------------------------------------------------------------------------------
Install apache2 + mod_php5 + mod_suphp + php5-suhosin + php5_mysql + php5_pgsql
---------------------------------------------------------------------------------
Apache2 + mod_php5 + mod_suphp + php5_mysql + php5_pgsql
========================================================
# apt-get install apache2
# apt-get install libapache2-mod-php5
# apt-get install libapache2-mod-suphp
# apt-get install php5-suhosin
# apt-get install php5-mysql
# apt-get install php5-pgsql
# apt-get install ssl-cert
# mkdir /etc/apache2/mod_security2
# mkdir /var/log/mod_security2
----------------
Config apache2
----------------
# nano /etc/apache2/ports.conf
------------------------------
Listen 10.0.0.2:80
Edit /usr/sbin/make-ssl-cert so that it issues certificates valid for ten years.
Debian Etch has a bug and by default generates certificates for 30 days, which is rather short.
======================================================================================
# nano /usr/sbin/make-ssl-cert (Change line number 118 and add '-days 3650' there = 10 years)
----------------------------------------------------------------------------------------------
# L.H. OFF -> openssl req -config $TMPFILE -new -x509 -nodes -out $output -keyout $output > /dev/null 2>&1
# L.H. UPDATE
openssl req -config $TMPFILE -new -x509 -nodes -days 3650 -out $output -keyout $output > /dev/null 2>&1
Create the directory for ssl
----------------------------
# mkdir /etc/apache2/ssl
# nano /etc/apache2/apache2.conf (Turn off the display of some sensitive information)
-------------------------------------------------------------------------------------
ServerTokens Prod
ServerSignature Off
# nano /etc/apache2/conf.d/charset (set the default charset)
------------------------------------------------------------
AddDefaultCharset WINDOWS-1250
-----------------------
Install mod-security2
-----------------------
# wget http://etc.inittab.org/~agi/debian/libapache-mod-security2/etch/mod-security2-common_2.1.5-1etch1_all.deb
# wget http://etc.inittab.org/~agi/debian/libapache-mod-security2/etch/libapache2-mod-security2_2.1.5-1etch1_i386.deb
# dpkg -i mod-security2-common_2.1.5-1etch1_all.deb
# dpkg -i libapache2-mod-security2_2.1.5-1etch1_i386.deb
----------------------
Config mod_security2
----------------------
# mkdir -p /chroot/apache2/tmp
# mkdir -p /chroot/apache2/var/run /chroot/apache2/var/www
# cd /etc/apache2/mod_security2
# wget http://www.modsecurity.org/download/modsecurity-core-rules_2.1-1.4.3.tar.gz
# tar -xzvf modsecurity-core-rules_2.1-1.4.3.tar.gz
# rm modsecurity-core-rules_2.1-1.4.3.tar.gz
# echo "Include /etc/apache2/mod_security2/*.conf" >> /etc/apache2/httpd.conf
# nano /etc/apache2/mod_security2/modsecurity_crs_10_config.conf
----------------------------------------------------------------
SecDebugLog /var/log/mod_security2/modsec_debug.log
SecAuditLog /var/log/mod_security2/modsec_audit.log
SecChrootDir /chroot/apache2
# nano /etc/init.d/apache2
--------------------------
In the function apache_stop(), comment everything out down to "PID=" and change that line to:
PID=`cat /chroot/apache2/var/run/apache2.pid`
# /etc/init.d/apache2 start
----------------------
Config php5
----------------------
# nano /etc/php5/apache2/php.ini
--------------------------------
safe_mode = On
safe_mode_allowed_env_vars = PHP_
open_basedir = /var/www/
expose_php = Off
display_errors = Off
log_errors = On
error_log = /var/log/php_error.log
register_globals = Off
magic_quotes_gpc = Off
file_uploads = Off
session.use_trans_sid = 0
disable_functions = proc_nice, proc_terminate, proc_get_status, proc_close, proc_open, ini_alter, dl, system, exec, pfsockopen, fsockopen, curl_init, curl_setopt, curl_exec, curl_close, leak, shell_exec, proc_open, syslog, link, readlink, symlink, error_log, ini_restore, openlog, passthru, socket_create, socket_write, shmop_close, shmop_delete, shmop_open, shmop_read, shmop_size, shmop_size
disable_classes = posix
allow_url_fopen = Off
allow_url_include = Off
max_execution_time = 30
max_input_time = 60
memory_limit = 8M
upload_max_filesize = 262144
upload_tmp_dir = /tmp
post_max_size = 262144
--------------------------------END->/etc/php5/apache2/php.ini
------------------
Config DOMENA1
------------------
Create a so-called self-signed certificate
------------------------------------------
# make-ssl-cert /usr/share/ssl-cert/ssleay.cnf /etc/apache2/ssl/www.domena1.sk.pem
----------------
SK, Slovakia, Mesto, www.domena1.sk, web, www.domena1.sk, webmaster@domena1.sk
# nano /etc/apache2/sites-available/www.domena1.sk
--------------------------------------------------
<VirtualHost 10.0.0.2:80>
ServerAdmin webmaster@domena1.sk
ServerName www.domena1.sk
ServerAlias domena1.sk
DocumentRoot /var/www/www.domena1.sk
ServerSignature off
ErrorLog /var/log/apache2/www.domena1.sk-error.log
CustomLog /var/log/apache2/www.domena1.sk-access.log common
LogLevel warn
suPHP_Engine on
AddHandler x-httpd-php .php .php3 .php4 .php5
suPHP_AddHandler x-httpd-php
suPHP_ConfigPath /etc/php5/sites/www.domena1.sk
</VirtualHost>
!!! NOT yet !!!
<VirtualHost 10.0.0.2:443>
SSLEngine On
SSLCertificateFile /etc/apache2/ssl/www.domena1.sk.pem
ServerAdmin webmaster@domena1.sk
ServerSignature Off
ServerName www.domena1.sk
DocumentRoot /var/www/www.domena1.sk
ServerAdmin webmaster@domena1.sk
ErrorLog /var/log/apache2/www.domena1.sk-SSLerror_log
CustomLog /var/log/apache2/www.domena1.sk-SSLaccess_log common
LogLevel warn
suPHP_Engine on
AddHandler x-httpd-php .php .php3 .php4 .php5
suPHP_AddHandler x-httpd-php
suPHP_ConfigPath /etc/php5/sites/www.domena1.sk
</VirtualHost>
--------------------------------------------------END->/etc/apache2/sites-available/www.domena1.sk
Create the directory with the php configuration for www.domena1.sk
------------------------------------------------------------------
# mkdir -p /etc/php5/sites/www.domena1.sk
# cp /etc/php5/apache2/php.ini /etc/php5/sites/www.domena1.sk/
Adjust the php config for the domain www.domena1.sk
---------------------------------------------------
# nano /etc/php5/sites/www.domena1.sk/php.ini
---------------------------------------------
open_basedir = /var/www/www.domena1.sk
upload_tmp_dir = /var/www/www.domena1.sk/tmp
error_log = /var/log/apache2/www.domena1.sk-php_error.log
Create the tmp directory for the domain www.domena1.sk
------------------------------------------------------
# mkdir -p /var/www/www.domena1.sk/tmp
# chown www.domena1.sk:www.domena1.sk /var/www/www.domena1.sk/tmp
# chmod 777 /var/www/www.domena1.sk/tmp
Enable the site named www.domena1.sk
------------------------------------
# a2ensite www.domena1.sk
Enable the ssl module
---------------------
# a2enmod ssl
----------------------
Config php5-suhosin
----------------------Current practice (checked 2026-10)
noteThe article above is kept as it was written in 2008. This section lists what has changed since and what to do instead today.
- php5: every PHP 5 branch is end-of-life (5.2, the Etch version, since January 2011; the last one, 5.6, since 2018-12-31). The Debian packages are now named without the version (
php,php-fpm,php-mysql,php-pgsql) and install a supported PHP 8 branch.php5-suhosinhas no successor there: Suhosin was written for PHP 5.x, and the article leaves its configuration empty anyway. - php.ini:
safe_mode,safe_mode_allowed_env_vars,register_globalsandmagic_quotes_gpcwere removed in PHP 5.4; drop the lines.open_basedir,expose_php,display_errors,log_errors,disable_functions,allow_url_fopenandallow_url_includestill exist and the values chosen are still sensible. - suPHP: upstream states that suPHP is no longer maintained and gets no security patches (last release 0.7.2, 2013). Running each site's PHP under its own user is done today with PHP-FPM: one pool per site with its own
user,groupandphp_admin_valuesettings, connected from Apache withmod_proxy_fcgi. That replacessuPHP_ConfigPathand the per-sitephp.inicopy. - mod_security2 install: the article adds a developer's personal repository with
apt-key, and fetches the.debfiles and the core rules withwgetover plainhttp://without checking them. Both are in Debian main now:apt install libapache2-mod-security2 modsecurity-crs. The rule set is the OWASP Core Rule Set, the successor of themodsecurity-core-rulestarball. - make-ssl-cert: do not edit
/usr/sbin/make-ssl-cert; the edit is lost with the nextssl-certupdate. The current tool has an--expiration-daysoption, and its default is already 3650 days. - Certificate lifetime: a ten-year self-signed certificate is acceptable only for an internal test host. A public site uses a certificate from a CA, issued and renewed automatically (ACME); the CA/Browser Forum rules cap such certificates at 200 days since 2026-03-15, at 100 days from 2027-03-15 and at 47 days from 2029-03-15, with RSA keys of at least 2048 bits.
- Keys made on Etch: this article predates the OpenSSL fix of 2008-05-13 (DSA-1571, see the dom0 article). A key generated with
make-ssl-certon Etch before that date was predictable and had to be replaced. - TLS settings: the 443 virtual host sets only
SSLEngine On, which in 2008 meant SSLv2 and SSLv3 were offered. Current mod_ssl has no SSLv2 and disables SSLv3 by default; restrict it further toSSLProtocol TLSv1.2 TLSv1.3. Keeping the private key in the same.pemas the certificate is described as highly discouraged in the mod_ssl documentation; use a separateSSLCertificateKeyFilereadable by root only. - chmod 777: the per-site
tmpdirectory is owned by the site user and PHP runs as that user, sochmod 700is enough; 777 lets every local account write there. - Charset and xm:
AddDefaultCharset WINDOWS-1250was a choice for Central European pages of that time; new sites are UTF-8.xm createandxm consolearexl createandxl consolesince Xen 4.5.
Sources: