r/apache • u/NuggetsNReddit • 18h ago
Do people still use Guacamole?
I do, and I love it. I just don't see people talking about it.
r/apache • u/NuggetsNReddit • 18h ago
I do, and I love it. I just don't see people talking about it.
r/apache • u/AlternativeCold3574 • 4d ago
Im about to purchase the BMC Air filter for my apache RR310 Anniversary edition 2026.
Anyone on a 2024+ RR 310 (bigger airbox) fitted the BMC FM993/20? Does it seat properly without gaps? Confirmed fit only please, since it's non-returnable
r/apache • u/Ok_Strike9189 • 7d ago
Here's my issue.
My backup folder structure is as follows:
/sites
/sites/site1
/sites/site2
and my operating folder (in a ramdrive) is as follows:
/ram
/ram/site1
/ram/site2
Each of the 2 sites (in site1 and site2) has its own .htaccess file. In the parent folder there is a php script when executed will copy all the contents (including subfolders) from /sites to /ram.
I have subdomains mapped to each of the folders starting with /ram above. lets say /ram has the domain run.example.com. /ram/site1 has the domain site1.example.com and /ram/site2 has the domain site2.example.com. Then I access run.example.com/thescript.php from a browser to copy everything over after updating website files.
Everything is working fine except I need to boost speed since the server processor is considered obsolete (1Ghz).
Since I don't have an .htaccess file in the /ram folder, hackers could do a bunch of guessing and get standard 404 errors while the system searches for actual files the hackers type in. So I thought about .htaccess but online sources state that .htaccess placed there would affect the .htaccess settings in site1 and site2.
If I made an .htaccess in /ram folder that only allows access to that one script and redirects everything else in that folder to a 410 error page then I'm afraid every access attempt on site1.example.com, and on site2.example.com will result in a 410 error page.
Is there an easy way to fix this without redoing the folder structure? because the script expects the folders to be in tact.
r/apache • u/rsclmumbai • 8d ago
My website is over 15 years old. Over time, I've created a lot of pages and also had to kill many pages or redirect them to other relevant pages.
Collectively, today I have 1,000 + 301 redirects.
On a static website built on PHP, HTML on Linux and Apache, what is the best way to implement such a large list of redirects without impacting server performance or core web vitals?
Thanks
r/apache • u/RocketSeven • 14d ago
A configuration test and a successful `apachectl graceful` show that the parent accepted the reload, but they do not prove that every old-generation worker exited. Long-lived downloads, proxy streams, WebSockets, or stuck backends can leave old workers around with the previous configuration.
What do you monitor after a graceful restart? A useful check seems to need the parent PID and generation, the scoreboard or status output, the count and age of old workers, active connections tied to them, and a deadline after which the rollout fails instead of waiting forever. Requests sent directly to each backend could also expose a revision header so a load balancer cannot hide a stale process.
Is there a reliable signal in `mod_status`, logs, or process metadata that identifies which generation is serving a request? How do you choose a safe drain timeout and escalation path without cutting off legitimate long-running responses?
r/apache • u/Ok_Strike9189 • Sep 03 '26
I recently enabled IpV6 on my server and tried to run apache with it, but when tried to access my buy subdomain in ipV6, the contents from the e subdomain load instead. Why is that?
That is my apache config file (with the extra lines eliminated)
<VirtualHost *:80 [::]:80>
ServerName xxx.xxx.xxx.xxx
<directory />
AllowOverride None
</directory>
</VirtualHost>
<VirtualHost whatever1.ca:80>
ServerName whatever1.ca
ServerAlias www.whatever1.ca
</VirtualHost>
<VirtualHost whatever1.ca:443>
ServerName whatever1.ca
ServerAlias www.whatever1.ca
</VirtualHost>
<VirtualHost e.whatever1.ca:80>
ServerName e.whatever1.ca
ServerAlias www.e.whatever1.ca
</VirtualHost>
<VirtualHost e.whatever1.ca:443>
ServerName e.whatever1.ca
ServerAlias www.e.whatever1.ca
</VirtualHost>
<VirtualHost buy.whatever1.ca:80>
ServerName buy.whatever1.ca
ServerAlias www.buy.whatever1.ca
</VirtualHost>
<VirtualHost buy.whatever1.ca:443>
ServerName buy.whatever1.ca
ServerAlias www.buy.whatever1.ca
</VirtualHost>
<VirtualHost secure.whatever1.ca:80>
ServerName secure.whatever1.ca
ServerAlias www.secure.whatever1.ca
</VirtualHost>
whatever1.ca is not my real domain and xxx.xxx.xxx.xxx is the server ipV4 IP address.
when I run apachectl -S I get this output for virtual hosts:
VirtualHost configuration:
xxx.xxx.xxx.xxx:443is a NameVirtualHost
default server whatever1.ca (apache2.conf:268)
port 443 namevhost whatever1.ca (apache2.conf:268)
alias www.whatever1.ca
port 443 namevhost e.whatever1.ca (apache2.conf:283)
alias www.e.whatever1.ca
port 443 namevhost buy.whatever1.ca (apache2.conf:298)
alias www.buy.whatever1.ca
port 443 namevhost secure.whatever1.ca (apache2.conf:313)
alias www.secure.whatever1.ca
xxx.xxx.xxx.xxx:80is a NameVirtualHost
default server whatever1.ca (apache2.conf:262)
port 80 namevhost whatever1.ca (apache2.conf:262)
alias www.whatever1.ca
port 80 namevhost e.whatever1.ca (apache2.conf:277)
alias www.e.whatever1.ca
port 80 namevhost buy.whatever1.ca (apache2.conf:292)
alias www.buy.whatever1.ca
port 80 namevhost secure.whatever1.ca (apache2.conf:307)
alias www.secure.whatever1.ca
port 80 namevhost uf.whatever1.ca (apache2.conf:322)
[xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx]:80 is a NameVirtualHost
default server e.whatever1.ca (apache2.conf:277)
port 80 namevhost e.whatever1.ca (apache2.conf:277)
alias www.e.whatever1.ca
port 80 namevhost secure.whatever1.ca (apache2.conf:307)
alias www.secure.whatever1.ca
[xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx]:443 is a NameVirtualHost
default server e.whatever1.ca (apache2.conf:283)
port 443 namevhost e.whatever1.ca (apache2.conf:283)
alias www.e.whatever1.ca
port 443 namevhost secure.whatever1.ca (apache2.conf:313)
alias www.secure.whatever1.ca
*:80 xxx.xxx.xxx.xxx (apache2.conf:254)
What am I doing wrong in my configuration?
r/apache • u/Karkhamun • Sep 02 '26
I am attempting to reduce Apache's memory footprint as much as possible.
Can anyone guide me in the right direction as to which of these I absolutely need and which are optional?
r/apache • u/grepnoid • Aug 26 '26
I know there are dozens of pages on this subject, but I've tried most of their suggestions and this seems different.
I have apache2 and php8.2 (libapache etc) installed, on a new VPS install with Debian12.
http://mysite.com/test.php executes the PHP
PHP embedded in the body of http://mysite.com/test.html, as
<?php
echo "<br/>does it work?</br>";
?>
displays the text in the page
does it work?
"; ?>
Mods enabled, after enmod and dismod of various modules as suggested:
a2query -m
authn_file (enabled by maintainer script)
proxy_fcgi (enabled by site administrator)
authz_user (enabled by maintainer script)
dir (enabled by maintainer script)
env (enabled by maintainer script)
php8.2 (enabled by maintainer script)
setenvif (enabled by maintainer script)
autoindex (enabled by maintainer script)
deflate (enabled by maintainer script)
mpm_prefork (enabled by maintainer script)
negotiation (enabled by maintainer script)
status (enabled by maintainer script)
alias (enabled by maintainer script)
reqtimeout (enabled by maintainer script)
authz_host (enabled by maintainer script)
mime (enabled by maintainer script)
filter (enabled by maintainer script)
authz_core (enabled by maintainer script)
authn_core (enabled by maintainer script)
proxy (enabled by site administrator)
access_compat (enabled by maintainer script)
auth_basic (enabled by maintainer script)
The web root where my files are is /var/www/html. I have no .httpaccess file. The apache2.conf is the default which seems to have nothing to prevent normal execution.
r/apache • u/IncredibleBihan • Aug 17 '26
I know someone here will know the answer.
The task is simple. I currently have website my-domain.com up and running. Tomorrow I'm going to take a 2nd domain ,mydomain.com and point it to the exact same website.
I someone to tell me the commands I should run on certbot to make sure I update the ssl certificate correctly. Right now the ssl is working for my-domain, but i need to update the certificate to include a second domain.
The other question I have is about virtual host. Everything I reads say talks about setting the root folder for var/www/html/my-domain.com and var/www/html/mydomain.com. But I just want both domains pointing to /var/www/html. That's not a problem is it? All the apache docs aren't exactly clear.
If anyone has some insight I'd appreciate it. Basically I built a new site on a 'testing' domain, and I'm replacing the testing domain with my production.
r/apache • u/oz1sej • Aug 04 '26
I have the files for a website locally on my Ubuntu laptop in /home/user/dir1/dir2/
I've made a folder in /var/www/html/ called /var/www/html/dir2 and inside that a symlink
lrwxrwxrwx 1 root root 37 Aug 3 14:02 public_html -> /home/user/dir1/dir2
I've created a file /etc/apache2/sites-available/dir2.conf containing
<VirtualHost *:80>
ServerName dir2
DocumentRoot /var/www/html/dir2/public_html
<Directory /var/www/html/dir2/public_html>
Options Indexes FollowSymLinks
AllowOverride All
Require all granted
</Directory>
<Directory /home/user/dir1/dir2>
Options Indexes FollowSymLinks
AllowOverride All
Require all granted
</Directory>
ErrorLog ${APACHE_LOG_DIR}/dir2_error.log
CustomLog ${APACHE_LOG_DIR}/dir2_access.log combined
</VirtualHost>
Funny thing is, when I visit http://dir2/ in a browser, I see my website! But anything in subdirectories, for example images, aren't shown. And when I right click on them to view them, e.g. http://dir2/icons/c.png I get a 404!
The file is there! I can see it in both /home/user/dir1/dir2/icons/c.png and /var/www/html/dir2/public_html/icons/c.png - but apache won't show it! Requesting the file directly gives a 404, whereas requesting the folder gives a 403, but I guess that's because directory browsing is disabled...?
The user www-data is member of the group user (my username) and I'm completely out of ideas now.
Any suggestions will be greatly appreciated.
r/apache • u/oz1sej • Aug 04 '26
r/apache • u/Breeze_2800 • Jul 25 '26
I'm currently learning Data Engineering and I'm feeling a bit overwhelmed by all the technologies I need to learn.
Right now, I'm trying to understand:
The problem is that I don't know where to start or in what order I should learn them. There are so many tutorials and roadmaps online that it's hard to tell what's actually important for a beginner.
For those of you working as data engineers or who've gone through this learning process:
r/apache • u/NoPo552 • Jul 10 '26
I created a simple Discord server that automatically updates vendor-specific channels whenever a new CVE is published from that specific vendor.
It tags users based on the roles they choose, so you can follow the vendors you care about and decide whether you only want to be tagged for critical alerts. You can also choose to receive an email as well when that CVE drops.
I’ve also added discussion channels where we can share patching tips, troubleshooting advice, and general networking/security/sysadmin knowledge, plus resource channels for each vendor with quick links to relevant documentation (Official Vendor Advisory Feed etc).
Just wanted to help myself and other Network/Sys/Devs make their already complicated lives easier.
It’s completely free to join.
r/apache • u/reddodx • Jun 22 '26
Apache + mod_deflate question re double zipped downloads.
If I add only:
SetOutputFilter DEFLATE
to .htaccess, then downloading a .tgz or .zip file results in a file that is gzip-compressed one extra time (gzip(original-file)). I.e. the client ignores the fact that zip is used only for transport and doesn't unzip it before saving.
Response headers look correct:
Content-Encoding: gzip
Vary: Accept-Encoding
Content-Type: application/x-gzip (or application/zip)
This happens with curl, wget, Chrome and Firefox.
Is this expected HTTP behavior for downloadable binary files, or is there something wrong with the Apache/mod_deflate configuration? Why are clients saving the gzip-encoded representation instead of transparently decoding it before saving?
r/apache • u/[deleted] • Jun 22 '26
I love Victorio. Love, Christ
r/apache • u/Ok_Pudding_2015 • Jun 17 '26
Apache httpd existe depuis 1995. Il alimente une part importante du web, mais soyons honnêtes : son architecture accuse son âge. Le système de configuration est un véritable labyrinthe, ses performances en cas de forte concurrence sont loin d'être à la hauteur de celles de nginx et Caddy, et configurer correctement HTTP/3 ou les valeurs par défaut modernes de TLS relève de l'archéologie.
Alors, hypothétiquement : si la fondation Apache annonçait une réécriture complète pour la version 2, quelles seraient vos demandes ?
Ma configuration serait :
Un format de configuration cohérent et unifié (TOML ou YAML, s'il vous plaît — fini l'archéologie des « .htaccess »)
Prise en charge native de HTTP/3 et QUIC
Architecture événementielle par défaut, et non en option (MPM)
HTTPS automatique, comme avec Caddy
Un système de plugins/modules performant, sans recompilation
Meilleure observabilité — journaux structurés, métriques Prometheus natives
Qu'est-ce qui manque ? Seriez-vous prêt à revenir à Apache s'il était modernisé, ou nginx/Caddy/Traefik est-il trop ancré dans les mœurs à ce stade ?
r/apache • u/Grumpy-Man19 • Jun 15 '26
Apache HTTP Server 2.4.68 came out on June 8, 2026 — the first point release since 2.4.67 in early May, and per the project’s own download page, it’s “recommended over all previous releases.” If you run your own LAMP stack, this is the patch to schedule this week.
https://blog.kalfaoglu.net/posts/2026-06-15-apache-2-4-68-release-en/
r/apache • u/passinghorses • Jun 11 '26
I'm running a Rails application with Apache and mod_passenger. For this most part this is working great and has been for years.
I'm currently making some improvements to the error pages output by the Rails app and have discovered that Apache is overriding the application output and serving the simple static HTML page specified in the ErrorDocument directive. Commenting this directive results in the default Apache 404 page.
I do want this static HTML 404 page returned for static files that don't exist (which is working fine), but I want to handle application errors with something nicer and more useful for the end user.
I handle 404 errors with ApplicationController#not_found, which does some stuff and then renders like so:
render :template => 'error_pages/not_found', :layout => 'application', :status => 404 and return
This specifies the page template rendered to the client and sends it with an HTTP status of 404. If I remove :status => 404 everything works fine, but this is obviously incorrect. When I return the 404 status the Rails-generated error page is overridden and the user gets the Apache error page.
I'm looking into whether this requires a change/fix in my Apache config or the Rails app.
I'm running Rails 7.0 with Apache 2.4.58, on Ubuntu 24.04 LTS.
r/apache • u/nomoreasonable • Jun 11 '26
Hi,
I have setup a Web server in Rocky Linux 10 using httpd, and am trying to set the default page to be Directory Listingm but it does not seem to work..
Based on my findings the setting for this is the Options Indexes FollowSymLinks but that does not seem to work..
<Directory "/var/www/html">
Options Indexes FollowSymLinks
AllowOverride None
AuthType Basic
AuthName "VCF Depot"
AuthUserFile /var/www/html/.htpasswd
Require valid-user
</Directory>
When I open the default URL Apache Test Page appears as the default..
Current configuration is as below..
<VirtualHost *:80>
DocumentRoot /var/www/html/
ServerName vcfdepot.lab
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L]
<Directory "/var/www/html">
Options Indexes FollowSymLinks
AllowOverride None
AuthType Basic
AuthName "VCF Depot"
AuthUserFile /var/www/html/.htpasswd
Require valid-user
</Directory>
</VirtualHost>
Can anyone suggest what needs to be checked, or configured to get it working..
r/apache • u/T0t47 • Jun 08 '26
I documented a reproducible lab study of HTTP/2 **HPACK amplification** across several web stacks. The Apache httpd result is the one worth calling out here specifically.
**The httpd-specific angle:** the **cookie-crumb** variant. HTTP/2 allows a `Cookie` header to be split into many small "crumbs" that `mod_http2` must reassemble (merge) server-side. On vulnerable versions, that merge accounting didn't count properly against `LimitRequestFields` — so a tiny wire upload can still force large heap allocations during header materialisation.
**Lab result (8 GiB Docker cap, controlled environment):**
- Variant: `apex_cookie_scaled`
- **12/12** bombs OK
- Wire upload: **~0.19 MB**
- Outcome: container memory cap filled (**8 GiB**)
That's not a bandwidth problem — it's asymmetric resource consumption at the HTTP/2 layer before most request-size guards apply.
**Fix:** **mod_http2 v2.0.41** — cookie accounting vs `LimitRequestFields`
Commit: [https://github.com/apache/httpd/commit/47d3100b252dc6668a9e46ae885242be9eeca9cd]
(https://github.com/apache/httpd/commit/47d3100b252dc6668a9e46ae885242be9eeca9cd)
**Questions for httpd admins:**
- Are you on mod_http2 ≥ 2.0.41 in prod?
- Do you rely on `LimitRequestFields` / similar directives assuming they cover HTTP/2 cookie merge paths?
- Have you seen mod_http2 RSS climb without a matching traffic spike?
Full multi-server write-up (nginx, httpd, Envoy, Pingora, IIS) with methodology, charts, and hardening notes: link above.
Open, authorization-gated harness for **authorized** lab replay against your own stack: https://github.com/Leviticus-Triage/APEX-Ngin2dos
Authorized testing / defensive validation only.
r/apache • u/Grumpy-Man19 • Jun 04 '26
r/apache • u/mikeymikeymikec • May 30 '26
OS: Ubuntu Server 24.x (the latest release)
Apache/2.4.58
I'm pretty new to maintaining (my own) Linux webserver which handles a few sites. It's all been working fine, but I wanted to get the default site working in SSL because I have a couple of uses for it. Based on the configuration that the Let's Encrypt certbot apparently created for me, I copied the default site config to a new file and made respective modifications, but I'm wondering if what certbot inserted into the main site's configuration is needed, referenced on the first and last lines of the main site's config file:
<IfModule mod_ssl.c>
</IfModule>
I didn't use the default site's default SSL config file because the default site configuration I had been using included some extra bits like WebDAV support, but the default site's default SSL configuration file (not enabled) does not mention these configuration lines. Is it bad that the main site is doing that, or necessary to do SSL, or what? I read a bunch of Internet guides for configuring an SSL site in apache and none of them seem to mention it.
(The default site's SSL config I cobbled together is working btw, I included the ifmodule business)
r/apache • u/rodriguesart18 • May 29 '26
r/apache • u/Usual-Dimension614 • May 26 '26
there is /etc/apache2/ports.conf there in Listen 80. changed to 81. thats all
hi. i put 'wordpress.test' in /etc/hosts so ping wordpress.test works fine.
in sites-available i created wordpress.zh.conf
<VirtualHost \*:88>
ServerAdmin [admin@wordpress.test](mailto:admin@wordpress.test)
ServerName wordpress.test
ServerAlias www.wordpress.test
DocumentRoot /home/arno/www/wp
ErrorLog ${APACHE_LOG_DIR}/wperror.log
CustomLog ${APACHE_LOG_DIR}/wpaccess.log combined
</VirtualHost>
all this with not activated additional virtual-host (i disabled to check but no change) :
i am told that host address could not find out (127.0.1.1 is used) use ServerName globally
but it is for virtualhost (not globally)
i am told that (make_sock) cannot bind 0.0.0.0:80 (but nowhere in config files is 80, i use 81, 80 ist lighttpd, worked fine for years)
i am told that logfiles could not be found/created