Showing posts with label web server. Show all posts
Showing posts with label web server. Show all posts

Saturday, 6 December 2014

Up and Away - Setting up a LAMPi

Acknowledgements:
For guidance I found a great article by Etel Sverdlov on Digital Ocean. Written for Ubuntu 12.04 - but none the less still valid
https://www.digitalocean.com/community/tutorials/how-to-install-linux-apache-mysql-php-lamp-stack-on-ubuntu

Installing a LAMP (server) on your Raspberry Pi

This is something that I have done a number of times now, but I've always dashed in and just done it in whatever order worked. Having looked at this in a bit more of a planned manner, I read Etel Sverdlov's article first, and that made a lot of sense. What I'm attempting to present here is based upon that, but with a few updates to call out some important points.

Step 1 - Latest repositories
First of all, need to update the repositories for aptitude (I prefer aptitude to apt-get - use apt-get if you wish)

sudo aptitude update


Step 2 - Install Apache2
Apache2 is a nice web server. Get used to it and it can be really friendly to use and administer. To install:

sudo aptitude install apache2

It's pretty straight forward. You'll be asked to confirm the installation of new files - just answer 'y'. Once that is done, then it is time to test your Apache2 installation using your browser. If you are running the Pi GUI on your RasPi, point your browser at 127.0.0.1. If like me, you are setting up your RasPi to be a headless server, with only the command line interface, you'll have to point another machine on your network at the RasPi's address. You should see a web page like this:





IMPORTANT!
During the Apache2 installation, there was one message - "Could not reliably determine the server's fully qualified domain name, using 127.0.0.1 for ServerName". This possibly happened on your install too. Depending on what you want to do with your RasPi, this may need to be addressed later on. For now, I'm letting it slide. Let's call it a Priority 2 TODO

Now you may have read my previous post, where I setup multiple IP addresses on the RasPi NIC at eth0 through aliases. So when I point my browser at the root address of the alias, I still get Apache's default index page. So, the web server is running, on both aliases. This is a bit more urgent - let's say a Priority 1 TODO.

I'll come back to these points in future posts. Moving on for now.

Step 3 - Install MySQL
MySQL is quite a nice bit of kit. Haven't used it enough. And full credit to Etel, I've followed her instructions quite closely this time. In the past I was quite nervous about attempting an install without the test DB, and without other features, but as Etel rightly point's out, these aren't necessary, and fixing them now will lead to a tighter installation, better for security. Keeping in mind that this RasPi is due to be effectively a production level machine, that's what we need.

Installing MySQL is a bit more involved, with a few choices to be made. To kick off the process:

sudo aptitude install mysql-server libapache2-mod-auth-mysql php5-mysql

From this command, your system may detect some conflicts in the packages, particularly apache2-mpm-prefork vs apache2-mpm-worker. Where we go from here depends upon what you want to do with your box.

For mine, I'm going to accept removing apache2-mpm-worker module. The apache2-mpm-worker is a more memory efficient module for handling multiple calls using thread processing. However it constrains then that you should only use thread safe calls, and this module is known to have issues with PHP. If we were building a dedicated MySQL box, without the Apache and PHP components, for a large, highly scalable commercial system, I would probably recommend differently. But for a low volume server, where system performance is non-critical, where some code used may not be thread-safe, I am choosing apache2-mpm-prefork.

Set the MySQL Root password when prompted. Just get it done and dusted. You can do it later, but doing it now will help avoid forgetting later.

Next, set-up and configure the database with the following commands:

sudo mysql_install_db

sudo /usr/bin/mysql_secure_installation


The system should prompt you for the MySQL Root password:

Enter current password for root (enter for none):

OK, successfully used password, moving on...


Now come the important security choices in the MySQL installation. The first will be the choice to remove anonymous users. For me, this is a no-brainer. Unless you want to setup a publicly accessible free-to-play database server, there is no reason. To support a web server, your install should only have known users with roughly three levels of access; root for admin, developer accounts for developing (or deploying/troubleshooting), and web app/service accounts for the applications that are going to consume the database. So, that's a yes to removing anonymous users.

Remove anonymous users? [Y/n] y
... Success!


Normally, root should only be allowed to connect from 'localhost'. This ensures that someone cannot guess at the root password from the network.

Disallow root login remotely? [Y/n] y
... Success!


HOLD THE FORT! Don't let root login remotely? How will we administer this? Don't stress, before putting the RasPi to it's final config, we will create the other user accounts. If however, you are already running your RasPi through SSH, you may wish to choose 'n' for this option for now. (Just note down for later that you need to change it)

Removing the default test database is another no-brainer. For this to be a production level box, we should not have any test artifacts. If this was for a development server, or a classroom education server, I'd say keep it, but for this one, it's going.

Remove test database and access to it? [Y/n] y
- Dropping test database...
... Success!
- Removing privileges on test database...
... Success!


Reloading the privilege tables will ensure that all changes made so far will take effect immediately.

Reload privilege tables now? [Y/n] y
... Success!


Step 4 - Install PHP
Installing PHP is pretty straight forward, but there will be some more choices to be made along the way. Let's start with:

sudo aptitude install php5 libapache2-mod-php5 php5-mcrypt

Then as the chosen packages are identified, we have another choice to make, a conflict between libapache2-mod-php5filter and libapache2-mod-php5. "What's the difference?" you ask - well here goes:
  • libapache2-mod-php5filter is not thread safe, so if you opted for apache2-mpm-worker in MySQL (see above), do not use libapache2-mod-php5filter
  • libapache2-mod-php5filter does not pass PUT and OPTIONS calls to the PHP processor - sends them straight to Apache and can break WebDAV - possibly not good for collaboration platforms

So, with this reasoning together, my selection was easy - libapache2-mod-php5 stays.

Next we want to make sure that if we have a PHP coded index page for a site, that it will get recognised as the index page. This may, or may not have been put into the dir.conf file during installation. Double check by using sudo to open dir.conf in your preferred editor.

sudo nano /etc/apache2/mods-enabled/dir.conf

If necessary add index.php to the beginning of index files. The page should now look like this:

<IfModule mod_dir.c>

   DirectoryIndex index.php index.html index.cgi index.pl index.xhtml index.htm

</IfModule>


Check!

Next, you may want to add some extra modules to extend the PHP functionality. This does not need to be done right now, but if you want to, check which modules are available in the repositories first:

apt-cache search php5-

Choose your modules and install. Finally test the PHP install. Use your preferred text editor to create the following file: /var/www/info.php

<?php
phpinfo();
?>


Then restart Apache

sudo service apache2 restart

Now test the page in your browser: 127.0.0.1/info.php
If you see a page like the one below, all has been successful.

Thursday, 4 December 2014

Change Brings Challenges

For some time now I've been running a #RasPi off our router, providing the private cloud based options for file-sharing, collaboration, and getting to those important documents we forgot to bring. So far I'm very happy with ownCloud. I'm also happy with Apache as my base web server, though I have not done enough with it. A basic home page is all really.

Plus, that image has been up and running now for some time. It's image base is old (2013??) and it probably needs a spruce-up of its firm-ware. I want to put an email server on it. So far I'm considering Citadel as my front runner there.

The other problem is that I fear it may have been hacked. Either that, or with my increasing age, and the extended periods of time since I last accessed that box, I have forgotten the passwords. Ooopps! Can't have a box that has been rooted. The kid in me smells a counter hack in the making. The old bloke recognises that there was nothing on the box of any grand importance. A #rebuild with a new SD card and properly implemented security would probably avoid the potential of reclaiming a box with unknown backdoors.

Beyond this, what I'd also like is to setup the opportunity for some web services that can interface with some home-made mobile apps.

What I am uncomfortable with is our router. Yes, you can set it up to forward connections for different services and applications. It will forward incoming common protocols to the correct port on a specified IP address. I am not certain however, if you have more than one website, differentiated by port, that the router's port forwarding works that well. The interface for setting up the port forwarding is not user friendly. So, I am considering using multiple IP addresses on eth0 (#aliases), to ease the pain.

To set up for using multiple IP addresses, there are two methods. One is to a running change that is non-persistent An example of this can be found at Penguin Tutor. The method I am going to use will persist the changes when the RasPi is rebooted:

pi@exampleberry ~ $ sudo vi /etc/network/interfaces

Edit the interfaces file with vi to add the eth0:0 alias

iface eth0 inet static
  address 192.168.72.88
  netmask 255.255.255.0
  gateway 192.168.72.254
  auto eth0

iface eth0:0 inet static
  address 192.168.72.89
  netmask 255.255.255.0
  auto eth0:0

...

iface eth0:9 inet static
  address 192.168.72.98
  netmask 255.255.255.0
  gateway 192.168.72.254

Repeat as necessary for aliases eth0:1.. to eth0:x, depending upon how many aliases your box requires. Save the changes to your interfaces file and restart your network services.

pi@exampleberry ~ $ sudo /etc/init.d/networking restart

Check the results by running ifconfig.

Of course, a potential headache that I will create by doing this is that I will simply increase the exposure of my RasPi box to further intrusions. So before I go any further, its time to research how to harden my RasPi and monitor for intrusion.


Acknowledgments: Narad Shrestha's article on Tecmint (http://www.tecmint.com/create-multiple-ip-addresses-to-one-single-network-interface/), "Create Multiple IP Addresses to One Single Network Interface"

Saturday, 8 December 2012

Immediate Needs

Well it has been a while since I have had a serious play with my RPi machines. Part of the issue being our power bills – really wanting to bring those down, meant redesigning our home network. In the end I removed two big boxes, a router and a switch. Which should reduce our power consumption by a good 5kWh per day or more. But still the power bill and usage is high. It needs to come down for both the sake of the environment, and so I don't need a second job.

So with this in mind, I am going to turn my first two RPi boxes to two particularly dedicated causes. One being that of a web server for both internal and external facing sites, the second as a CUPS server.

Given that I have not decommissioned, nor do I currently run a web server, why would I do that? Is that not just creating another machine to run and draw power? Yes and No. Currently my wife and I have about 6 different 'sites' (blogs, sites etc) with freely hosted arrangements. As we expand upon what our Internet communications are doing for our professional lives, we will want to adapt our web sites, and this is likely to mean paying for web hosting. Why not run our own server, and with the money saved in hosting costs, cover a little more power usage?

The CUPS server is another no-brainer once I thought more about it. Whilst I have taken to shutting my desktop machine down at night/in the morning, I often come home to find that it is on. That's because my wife has been doing some printing, and it is my desktop that shares the printer to our home network. I think a CUPS server that can be on 24/7 might be more the go.

So with these two challenges in mind, I have set off to get it done.

Web server.
Where to start? Simple, lets do this the professional way and start with the requirements.
Web server capable of serving up a number of sites. Preferred server-side script is PHP. Preferred DB is MySQL. So a LAMP server it is then! With phpmyadmin too please!

Without too much trouble I did a quick search for blogs/posts about this and first hit I found was at www.instructables.com/id/Raspberry-Pi-Web-Server/. Good post by drcurzon, lots of screenshots and easy to follow, step-by-step instructions – hence I am not going to make a hash of it by trying to reinvent it.

The one change I found necessary was in Step 9. If in the /etc/passwd file you comment out the pi user line (assuming pi is the user that you wish to use for FTP) you will not be able to connect via FTP, nor start a new SSH session. So from my experience, do not comment out this line. Merely observe that the running of the command usermod -d /var/www pi does change the default folder to open.

The only other problem I had I caused for myself by forgetting the credentials that I set for phpmyadmin. Eventually found them by going:

sudo nano /etc/phpmyadmin/config-db.php

Now the next trick will be to put my RPi web server into my DMZ, and ensure that I can connect to it for SSH and FTP, and web of course.