Matthew Grdinic
RE: Password Protecting Directories in OS X Serve
(msg # 2. : Posted Aug 5, 03 12:37 am)
*
Posts: 3
933 QS
Mac OS X (10.2.x)
The Webmin method works as i use it allot myself. However, it is always a good idea to "earn your stripes" the good old fashion way.
So....
This works ; )
AuthName "Organic Food Network"
AuthType Basic
AuthUserFile /path_to_your_password_file/.htpassword
AuthGroupFile /dev/null
require valid-user
Then, create your password file somewhere outside of your web root with this command:
touch /path/to/file/.htpassword
Finally, use the Apche password utlity to create your accounts, i.e. a user names admin with the password of starship would be...
htpasswd -b -d /path/to/file/.htpassword admin starship
Hope this helps.
****************
However if you just want a simple password protected directory within your site, you can add the following to your http_macosxserver.conf:
******
I should note that in my above post I reccomended editing the httpd_macosxserver.conf file; however, I would now advise against editing this file manually.
Instead, add the line to your httpd.conf file else your OSX Admin Utility may stop showing your web services button.
*******
AuthType Basic
AuthName "Description of this area"
AuthUserFile /etc/httpd/passwd/passwords
Require user jdoe
The AuthUserFile specifies a file which you need to create using a program on your server called htpasswd. This is how you would create the file called passwords:
htpasswd -c /etc/httpd/passwd/passwords username
Substitute the path for your actual path to a valid passwd directory, create it if needed. You'll then be asked to provide the password for the username you entered. Once you do this and after you add the appropriate entry to your config file, your directory is then secured with this username and password.
For more information on this, see: http://httpd.apache.org/docs/howto/auth.html
Posts: 118
Hi Austin
Thanks for all the info--this helps and I'll get back to you on how it goes.
In another post about MySql administration that you might be interested in (Andreas Carlsson "MySQL ver in 10.2" Oct,22 2002 4:51am), Roger Coleman posted a link to phpMyAdmin (http://www.phpMyAdmin.net/), which puts a web interface on setting up users, restricting access to certain hosts, etc.
Original Message
(Posted Oct 19, 02 1:25 pm) bookmark* mail* reply*
Posts: 131
iBook dual USB
Mac OS X (10.2.x)
I spent a few hours last night setting up the bulletin board from phpbb.org last night and thought I would post a little tutorial for others interested. Go to http://www.phpbb.org for more information. Basically it is an open source bulletin board (forum) built with php.
All of these instructions are adapted or come directly from either http://www.phpbb.org or http://www.mysql.org. Much of this is from memory. If you see something wrong let me know so that I can fix it. This was done on a Mac OS Server 10.2.1 using Mozilla 1.2b.
o Enable php if you haven't done so already. Look in the server admin guide for instructions. Basically there are two lines to comment out in the apache conf file.
# Don't forget to add index.php to the default document name under the "General" tab for your site in Server Settings.App #
SETTING UP MYSQL (if you haven't already):
o Start MySql from the MySql Manager. Verify it is running by using either "top" or Process Viewer.app and look for the mysqld process.
# Now you need to drop into the terminal #
o Enter mysql as root account. shell% mysql -u root mysqld
# At this point you should have the "mysql>" prompt #
o Set root password: mysql> set password for root@localhost=password('new_password');
# Keep in mind that the password should be enclosed in single quotation marks and you need the semi-colon. #
o Create a new database named phpbb: mysql> create database phpbb;
# I was logged on in terminal as user "admin" so I used admin as a the user for phpbb to connect through. You could also create a new user at this point. #
o Set password for admin user: mysql> set password for admin@localhost=password('new_password');
o Grant privileges for admin: mysql> grant all on phpbb.* to admin;
o You should be all set up if you didn't get any errors. Quit. mysql>quit
SETTING UP PHPBB2:
o Download phpBB2 from http://www.phpbb.org and save the uncompressed file to /Library/Webserver/Documents/
o Uncompress the file (stuffit expander is fine) and rename (or not) "phpBB2" to "forums" (or anything else). We will assume "forums."
o chown and chmod the folder to match the rest of your /Documents folder. Chmod ./forums/config.php so that it is world writable (777). This is just temporary.
o Direct your web browser to your_webserver_address/forums
# You should be faced with the installation form. #
o Choose mysql 3.x as the database.
o Enter "localhost" as host for database.
o Enter "phpbb" as database name.
o Leave database prefix as default.
o Enter "admin" as user and enter appropriate password (that you just set up in mysql).
o The server name, server port, and script path were all correctly guessed by the installer for me. Fix these if there appears to be a problem.
o Enter the initial forum administrator account information.
o Hit submit. If no errors are reported you should be good to go.
# If you have problems at this point you may want to check that your config.php has the correct world writable permissions. #
POST INSTALLATION CLEANUP (VERY IMPORTANT):
o chmod config.php so that it is not world writable (775)
o Remove install.php, upgrade.php, and update_to_*.php files from the ./forums directory.
o Remove ./forums/docs and ./forums/db/schemas directories if desired.
POST INSTALLATION CONFIGURATION:
o Direct your browser (if you haven't already been automatically directed) to your_webserver_address/forums
o Login with forum administrator account. At the bottom of the page there should be a "Administration Panel" link. You may already be in the Administrator page.
o There are a ton of different configurations parameters at this point. Have fun.
I haven't had any problems yet and a few people in the office have successfully created account. Depending on the settings you have control over if each new account is activated. I am getting an email with a link that activates new accounts once the form is filled out.
Anyway, assuming you named the folder "forums" and it is located in your ./Library/Webserver/Documents/ folder:
sudo chown -R system ./Library/Webserver/Documents/forums
this will set forums to ownership "system"
sudo chgrp -R admin ./Library/Webserver/Documents/forums
this will set forums to group "admin"
sudo chmod -R 775 ./Library/Webserver/Documents/forums
this will set the forums directory to the typical websebserver permissions, which are owner read-write-execute, group read-write-execute, and world read-execute.
sudo chmod 777 ./Library/Webserver/Documents/forums/config.php
this changes config.php to world writable so you can run the install step.
when you are done installing, make sure you remove the files mentioned in the previous post and
sudo chmod 775 ./Library/Webserver/Documents/forums/config.php
this restore config.php to world read-execute only.
Posts: 114
Interesting discussion... we started a similar one the other day on http://webmaster.mbnx.net/MacOSX/viewtopic.php?t=52
The main reason why I need to use MacOS X Server is that it comes with mod_redirectacgi_apple which is not available under MacOS X Client. That Apache module allows you to use AppleScript CGI's and also commercial CGI's like Maxum's NetCloak.
Some other reasons for OS X Server are:
- hardware monitor
- command line tools for remote administration (systemsetup)
- optimized kernel variables (sysctl -w kern.maxproc=2048) via /System/Library/StartupItems/SystemTuning/SystemTuning
Joe.
Aaron Faby's packages are appealing. Does anyone have any experience comparing the Liyanage binaries with the Faby packages?
RE: Cgi 500 INTERNAL SERVER ERROR!!! - Reid Bundonis (Posted 07:22pm Mar 5, 2003 CDT)
Did you check the file in vi? Are you using Unix breaks?
Realm Authors David Cittadini1
Original Message
(Posted Feb 6, 03 12:56 pm) bookmark* mail* reply*
Posts: 7
PowerMac
Mac OS X (10.2.x)
I have set up a Realm inside the Server Settings->Internet->Web->Configure Web Service->Sites. What I would like to do is determine the Authors that can author against that Realm. However, when I edit the Realm and look at the Access configuration tab there are no Users or Groups listed under "Users and Groups who can also Author". How do I add a user to this list?
Thanks.
rudger zimmer
RE: Realm Authors
(msg # 1.: Posted Feb 6, 03 10:01 pm) reply *
Overall: None
Posts: 29
open up Workgroup manager, drag and drop your users from there
r.z
This is an old thread but apparently without a resolution so I thought I'd add my $.02 for anybody looking through the archives. It appears that with Server Admin 10.1.3 you cannot add users/groups in the realm config window if you are connected to a remote server. Running server admin on the server locally doesn't seem to present a problem.
- Dave
Posts: 29
PowerMac G4 DP 450
Mac OS X (10.2.x)
1GB Ram I am looking for some app maybe one that runs with PHP or JSP to do web based website statistics. I need the application to be able to track all the virtual hosts I have. I need individual readout for page hits, unique visitors and bandwidth consumed. Is there anything anyone has used and liked?
Messages 1 - 4 of 4
Aaron Freimark
RE: Website statistics
(msg # 1.: Posted Dec 20, 02 10:53 am) reply *
Overall: None
Posts: 11
I use a Perl script called "runanalog" by Dan Pentcheff. It runs Analog for each virtual domain, and then compiles the results on a simple one-page summary.
You can see it in action on his web page . Links to the script and to its documentation are at the bottom of the page.
Like Analog, however, it does not do unique visitors...
Pavel Panteff
RE: Website statistics
(msg # 2.: Posted Dec 31, 02 12:28 pm) reply *
Overall: Helpful
Posts: 30
PM G4/450MP
Try this one !
http://awstats.sourceforge.net/
I use it to display stats for most of websites i have on my server !
here are some of them:
http://www.apple-bg.com/cgi-bin/awstats.pl?config=apple
http://www.apple-bg.com/cgi-bin/awstats.pl?config=hinso
http://www.apple-bg.com/cgi-bin/awstats.pl?config=model
I use it allso for stats for the squid:
http://www.apple-bg.com/cgi-bin/awstats.pl?config=squid
Kristoffer
RE: Website statistics
(msg # 3.: Posted Jan 2, 03 12:08 am) reply *
Overall: Helpful
Posts: 396
just installed awstats, it's very nice.
only problem was to change the log files into a log-friendly state.
found a little guide on it here:
http://www.afp548.com/Articles/web/apachelog.html
then to get crontab to work:
% sudo sh
% export EDITOR=/usr/bin/pico
% crontab -e
add something like:
1 5 * * * root /library/webserver/cgi-executables/awstats.pl -config=myvirtualhostname -update
save and exit pico.
the numbers are timers, this will update your logs every 24 hours, 1 minute past 5 am.
(if you change the 1 to 30, and the 5 to 13 it will update at 1.30 pm instead.)
Thomas Koons
(Helper) RE: Website statistics
(msg # 4.: Posted Jan 21, 03 4:28 am) reply *
Overall: None
Posts: 897
I use Summary from www.summary.net. It is used by a lot of the pros and it has almost every feature you can think of :)
Tom
Install a program called LittleDutchMoose! It stopped all attacks on my OSX server.
http://www.wundermoosen.com/wmMacXProducts.html#LDM
Give it a try. I bet you'll like it :)
Tom
Posts: 5
look at zend.com for an smtp sender, much nicer than trying to install and configure sendmail
Dan,
I'm not sure how to set up the system to run smtp to send your messages out, but you could use sendmail built-in your system to do this.
To find out how to configure sendmail on Jaguar, please go to: http://www.macdevcenter.com/lpt/a/2692.
RE: Allowing file Upload...safely
(msg # 1.: Posted Sep 30, 02 11:33 pm) reply *
Overall: None
Posts: 371
File uploads via php are fine. Default is a 2 meg max file size. This means for each upload, only 2 megs can be sent. To change the max upload size, you modify the php.ini file. If you can't find this file in either the /usr/lib or /usr/local/lib folders. you will need to get a generic copy from php.net.(download source code and in the files, there is a generic php.ini)
php treats the uploaded file like a variable. it places the file in a temp folder . With a simple function call you can move it where you want. At that same time, you change the name of the file for securtiy concerns. the "default locaiton" php plops the uploaded file is again set by php.ini
The is a simple php function that moves the file and renames it to a name you want to give it.......ie rename and move file to a new location.... the function is move_upload_file
see the description here
http://www.php.net/manual/en/function.move-uploaded-file.php
I would never execute an uploaded file.....nor would I allow it to ever be executable. Your concern about security would be diminished by changing the file name to something no one would know....... php supports the changing of privilieges quite easily as well......
Seb,
In case you didn't get anywhere with this...
I've found that, to use directives on user's folders, you need to use the user's home path as shown in either Workgroup Manager or NetInfo Manager, not what it appears to be from the disk structure.
Eg, If you created the user using Workgroup Manager so that their directories were created the first time they logged in, their Path to Home is something like
"/Network/Servers/server.domain.name.here/Users/username"
and the directive would start
HTH,
Nigel
got it working!
The solution?
I had to edit httpd.conf, NOT httpd_macosxserver.conf.
In other words, I had to IGNORE what the manual said, and add "Options Includes" to this part of httpd.conf file to enable SSI for all the "~user" directories:
#
# Each directory to which Apache has access, can be configured with respect
# to which services and features are allowed and/or disabled in that
# directory (and its subdirectories).
#
# First, we configure the "default" to be a very restrictive set of
# permissions.
#
Options FollowSymLinks Includes
AllowOverride None
So much for good documentation from Apple. Jeesh. Had me running in circles over and over...
Posts: 9
Hi,
I'm trying to enable SSI for my site. I followed the instructions exactly in the OSX Admin Guide. Namely:
"To enable SSI:
1 In the Terminal application, use the sudo command with a text editor to edit as the super
user (root):
/etc/httpd/httpd_macosxserver.conf
2 Add the following line to each virtual host for which you want SSI enabled:
Options Includes
To enable SSI for all virtual hosts, add the line outside any virtual host block.
3 In Server Settings, click Web and add ?index.shtml? to the set of default index files for each
virtual host.
By default, the mime_macosxserver.types file maintained by Server Settings contains the
following two lines:
AddHandler server-parsed shtml
AddType text/html shtml
If your SSI files use a file extension other than .shtml, you should add that type to the
mime_macosxserver.types file. You can add MIME types in Server Settings from the MIME
Types tab.
The changes take effect when you restart Web service."
Seems simple enough. I am not hosting any virtual hosts on my website. Just the main domain (zero.xa.net) and some individual user sites (such as http://zero.xa.net/~count0 ). Strangely, SSI is enabled for zero.xa.net (you can see it work at http://zero.xa.net/test.shtml ) but SSI is NOT enabled for any of the personal sites (see http://zero.xa.net/~count0/test.shtml ).
Anyone have any ideas/suggestions? I've searched these forums and the manual, but to no avail so far. Thank you.
The Webmin method works as i use it allot myself. However, it is always a good idea to "earn your stripes" the good old fashion way.
So....
This works ; )
AuthName "Organic Food Network"
AuthType Basic
AuthUserFile /path_to_your_password_file/.htpassword
AuthGroupFile /dev/null
require valid-user
Then, create your password file somewhere outside of your web root with this command:
touch /path/to/file/.htpassword
Finally, use the Apche password utlity to create your accounts, i.e. a user names admin with the password of starship would be...
htpasswd -b -d /path/to/file/.htpassword admin starship
Hope this helps.
Posts: 6
G4 2 x 1GHz
Mac OS X (10.2.x)
To reach a users "Sites" directory using a web browser a ~ (tilde) has to be included in the URL, before the users account name. This is some unix convention. The tilde is a bit tricky to find on swedish keyboards, and my users are irritated! Does anyone know a way to change the tilde for something else, like "users", the name of folder containing the users Home directories. Longer, but easier. /Bjorn
Andy Kvochick
RE: Don't want tilde in adress
(msg # 1.: Posted May 23, 03 1:27 pm) reply *
Overall: None
Posts: 9
You could check out "Mass Virtual Hosting" if you don't mind editing httpd.conf. Then you can do pretty much whatever you want to the URL. http://httpd.apache.org/docs/vhosts/mass.html
Posts: 1
You can view the man page for symbolic link by using the "man ln" command. The syntax for symbolic links is "ln -s "
James Robertson
Original Message
(Posted Feb 13, 03 3:00 pm) bookmark* mail* reply*
Posts: 3
Hi
We're trying to get Apache running as our new web server after using webstar for a good many years. Currently the server is up and running and handles requests internal to our network just fine.
The server sits in our DMZ, and on the outside is protected by our firewall. Port 16080, and port 80 are both available through the firewall. I can access the server from home using it's fully qualified domain name, using a full url ending in a file name, and using a folder name with a trailing slash for example www.apple.com/support/. If we try to access externally using a folder name without a slash as in www.apple.com/support it comes back with a 404.
Normally you would handle this through the conf file using, if I recall correctly, 'mod_dir' but this option is overridden by Apple's GUI. We need users who aren't web savvy to be able to access with or without the slash. We have set the various default page names up in the config utility. We also use multiple DNS names for various parts of the organization. Each of these has been registered using the config utility, and pointed to the specific folder that contains the pages for that division. With Webstar we had a cgi script that handled that part. Even though we could purchase webstar V for OS X we want to move away from that platform and into a more standard www server. IIS, may it die a shameful death, is not an option.
Any help would be appreciated.
Thanks
Messages 1 - 3 of 3
Celia Wessen
RE: Trailing slash problem with Apache
(msg # 1.: Posted Feb 14, 03 12:44 pm) reply *
Overall: None
Posts: 233
Extended Keyboard Server
Mac OS X (10.2.x)
celiamania.com Do you have the same problem with the top-most page (probably index.html)? i.e. If a user types "http://www.yourdomain.com", will the server return a 404 - therefore needing the user to type "http://www.yourdmain.com / ".
Jim Freese
RE: Trailing slash problem with Apache
(msg # 2.: Posted May 19, 03 3:06 pm) reply *
Overall: None
Posts: 1
Have you found a solution for this yet. I am having the same problem.
Camelot
RE: Trailing slash problem with Apache
(msg # 3.: Posted May 19, 03 3:28 pm) reply *
Overall: None
Posts: 1452
Check:
http://httpd.apache.org/docs/misc/FAQ.html#set-servername
It specifically covers this issue, relating it to the presence (or lack thereof) of the ServerName directive. Apache uses (needs?) this to determine the servername for your server so that it can generate the correct redirects if necessary.
Posts: 7
anyone any idea where php.ini or the php configuration file is? I've done a search and it reports 0 results.
thanks
Messages 1 - 5 of 5
Jim Mooney
RE: php.ini
(msg # 1.: Posted Oct 1, 02 9:29 am) reply *
Overall: Helpful
Posts: 371
Any install I have seen from Apple leaves out the php.ini file.
this is okay for the default settings are done at compile time and php uses the default settings to do it's thing.
So how do you get a working ini file. Download a complete source code from php.net and in the package is a generic php.ini file.
But wait you are not done. So where do you put it?????
In your default web root there should be a info.php file. Open that up in a web browser from the webserver. ie http://localhost/info.php
There is a line in there that tells you where you version of php expects the php.ini to be. << and that it where you put. then you're done.
Mat Griffin1
RE: php.ini
(msg # 2.: Posted Oct 2, 02 3:07 am) reply *
Overall: None
Posts: 7
Thanks Jim :D
Peter.
RE(1): RE: php.ini
(msg # 2.1: Posted Mar 24, 03 8:22 am) reply *
Overall: None
Posts: 85
did you found your php.ini file?
What have you done if you have a php.ini file mat?
I've got the same problem!!!!
I hope to hear from you soon.
Rutger.
speedycam.be
RE: php.ini
(msg # 3.: Posted Mar 27, 03 4:19 am) reply *
Overall: None
Posts: 114
You can get the latest php.ini from this location:
http://cvs.php.net/co.php/php4/php.ini-dist
It's very well documented, so you should be able to figure out what each option is for.
Joe.
cedric gentil
RE: php.ini
(msg # 4.: Posted May 14, 03 5:52 am) reply *
Overall: None
Posts: 7
I put a php.in file in /usr/lib and it works well. See the php manuals around the web too see what type of options you can write in.
Posts: 396
Why does accessing directories only work when I include the trailing "/" (e.g., http://foo.domain.com/~user/) but not when I omit it(e.g., http://foo.domain.com/~user)?
When you access a directory without a trailing "/", Apache needs to send what is called a redirect to the client to tell it to add the trailing slash. If it did not do so, relative URLs would not work properly. When it sends the redirect, it needs to know the name of the server so that it can include it in the redirect. There are two ways for Apache to find this out; either it can guess, or you can tell it. If your DNS is configured correctly, it can normally guess without any problems. If it is not, however, then you need to tell it.
Add a ServerName directive to the config file to tell it what the domain name of the server is.
The other thing that can occasionally cause this symptom is a misunderstanding of the Alias directive, resulting in an alias working with a trailing slash, and not without one. The Alias directive is very literal, and aliases what you tell it to. Consider the following example:
Alias /example/ /home/www/example/
The above directive creates an alias for URLs starting with /example/, but does not alias URLs starting with /example. That is to say, a URL such as http://servername.com/example/ will get the desired content, but a URL such as http://servername.com/example will result in a "file not found" error.
The following Alias, on the other hand, will work for both cases:
Alias /example /home/www/example
Joy Miller
RE(1): RE: Why is "/" necessary at end of url for pr
(msg # 1.1: Posted Apr 28, 03 1:48 pm) reply *
Overall: None
Posts: 5
Thank you SO MUCH! Your answer solved my problem. Adding the server name directive did the trick.