aboutsummaryrefslogtreecommitdiff
path: root/usr/pkg/etc/httpd/httpd.conf
blob: 5bbb3144eb386dbfbe269f3636eee0e978a90c33 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
ServerRoot "/usr/pkg"
Listen 0.0.0.0:80

#LoadModule mpm_event_module lib/httpd/mod_mpm_event.so
LoadModule mpm_prefork_module lib/httpd/mod_mpm_prefork.so
#LoadModule mpm_worker_module lib/httpd/mod_mpm_worker.so
LoadModule authn_file_module lib/httpd/mod_authn_file.so
#LoadModule authn_dbm_module lib/httpd/mod_authn_dbm.so
#LoadModule authn_anon_module lib/httpd/mod_authn_anon.so
#LoadModule authn_dbd_module lib/httpd/mod_authn_dbd.so
#LoadModule authn_socache_module lib/httpd/mod_authn_socache.so
LoadModule authn_core_module lib/httpd/mod_authn_core.so
LoadModule authz_host_module lib/httpd/mod_authz_host.so
LoadModule authz_groupfile_module lib/httpd/mod_authz_groupfile.so
LoadModule authz_user_module lib/httpd/mod_authz_user.so
#LoadModule authz_dbm_module lib/httpd/mod_authz_dbm.so
#LoadModule authz_owner_module lib/httpd/mod_authz_owner.so
#LoadModule authz_dbd_module lib/httpd/mod_authz_dbd.so
LoadModule authz_core_module lib/httpd/mod_authz_core.so
LoadModule access_compat_module lib/httpd/mod_access_compat.so
LoadModule auth_basic_module lib/httpd/mod_auth_basic.so
#LoadModule auth_form_module lib/httpd/mod_auth_form.so
#LoadModule auth_digest_module lib/httpd/mod_auth_digest.so
#LoadModule allowmethods_module lib/httpd/mod_allowmethods.so
#LoadModule file_cache_module lib/httpd/mod_file_cache.so
#LoadModule cache_module lib/httpd/mod_cache.so
#LoadModule cache_disk_module lib/httpd/mod_cache_disk.so
#LoadModule cache_socache_module lib/httpd/mod_cache_socache.so
#LoadModule socache_shmcb_module lib/httpd/mod_socache_shmcb.so
#LoadModule socache_dbm_module lib/httpd/mod_socache_dbm.so
#LoadModule socache_memcache_module lib/httpd/mod_socache_memcache.so
#LoadModule socache_redis_module lib/httpd/mod_socache_redis.so
#LoadModule watchdog_module lib/httpd/mod_watchdog.so
#LoadModule macro_module lib/httpd/mod_macro.so
#LoadModule dbd_module lib/httpd/mod_dbd.so
#LoadModule dumpio_module lib/httpd/mod_dumpio.so
#LoadModule echo_module lib/httpd/mod_echo.so
#LoadModule buffer_module lib/httpd/mod_buffer.so
#LoadModule data_module lib/httpd/mod_data.so
#LoadModule ratelimit_module lib/httpd/mod_ratelimit.so
LoadModule reqtimeout_module lib/httpd/mod_reqtimeout.so
#LoadModule ext_filter_module lib/httpd/mod_ext_filter.so
#LoadModule request_module lib/httpd/mod_request.so
#LoadModule include_module lib/httpd/mod_include.so
LoadModule filter_module lib/httpd/mod_filter.so
#LoadModule reflector_module lib/httpd/mod_reflector.so
#LoadModule substitute_module lib/httpd/mod_substitute.so
#LoadModule sed_module lib/httpd/mod_sed.so
#LoadModule charset_lite_module lib/httpd/mod_charset_lite.so
#LoadModule deflate_module lib/httpd/mod_deflate.so
#LoadModule xml2enc_module lib/httpd/mod_xml2enc.so
#LoadModule proxy_html_module lib/httpd/mod_proxy_html.so
#LoadModule brotli_module lib/httpd/mod_brotli.so
LoadModule mime_module lib/httpd/mod_mime.so
LoadModule log_config_module lib/httpd/mod_log_config.so
#LoadModule log_debug_module lib/httpd/mod_log_debug.so
#LoadModule log_forensic_module lib/httpd/mod_log_forensic.so
#LoadModule logio_module lib/httpd/mod_logio.so
LoadModule env_module lib/httpd/mod_env.so
#LoadModule mime_magic_module lib/httpd/mod_mime_magic.so
#LoadModule expires_module lib/httpd/mod_expires.so
LoadModule headers_module lib/httpd/mod_headers.so
#LoadModule usertrack_module lib/httpd/mod_usertrack.so
#LoadModule unique_id_module lib/httpd/mod_unique_id.so
LoadModule setenvif_module lib/httpd/mod_setenvif.so
LoadModule version_module lib/httpd/mod_version.so
#LoadModule remoteip_module lib/httpd/mod_remoteip.so
#LoadModule proxy_module lib/httpd/mod_proxy.so
#LoadModule proxy_connect_module lib/httpd/mod_proxy_connect.so
#LoadModule proxy_ftp_module lib/httpd/mod_proxy_ftp.so
#LoadModule proxy_http_module lib/httpd/mod_proxy_http.so
#LoadModule proxy_fcgi_module lib/httpd/mod_proxy_fcgi.so
#LoadModule proxy_scgi_module lib/httpd/mod_proxy_scgi.so
#LoadModule proxy_uwsgi_module lib/httpd/mod_proxy_uwsgi.so
#LoadModule proxy_fdpass_module lib/httpd/mod_proxy_fdpass.so
#LoadModule proxy_wstunnel_module lib/httpd/mod_proxy_wstunnel.so
#LoadModule proxy_ajp_module lib/httpd/mod_proxy_ajp.so
#LoadModule proxy_balancer_module lib/httpd/mod_proxy_balancer.so
#LoadModule proxy_express_module lib/httpd/mod_proxy_express.so
#LoadModule proxy_hcheck_module lib/httpd/mod_proxy_hcheck.so
#LoadModule session_module lib/httpd/mod_session.so
#LoadModule session_cookie_module lib/httpd/mod_session_cookie.so
#LoadModule session_dbd_module lib/httpd/mod_session_dbd.so
#LoadModule slotmem_shm_module lib/httpd/mod_slotmem_shm.so
#LoadModule slotmem_plain_module lib/httpd/mod_slotmem_plain.so
#LoadModule ssl_module lib/httpd/mod_ssl.so
#LoadModule dialup_module lib/httpd/mod_dialup.so
#LoadModule http2_module lib/httpd/mod_http2.so
#LoadModule lbmethod_byrequests_module lib/httpd/mod_lbmethod_byrequests.so
#LoadModule lbmethod_bytraffic_module lib/httpd/mod_lbmethod_bytraffic.so
#LoadModule lbmethod_bybusyness_module lib/httpd/mod_lbmethod_bybusyness.so
#LoadModule lbmethod_heartbeat_module lib/httpd/mod_lbmethod_heartbeat.so
LoadModule unixd_module lib/httpd/mod_unixd.so
#LoadModule heartbeat_module lib/httpd/mod_heartbeat.so
#LoadModule heartmonitor_module lib/httpd/mod_heartmonitor.so
#LoadModule dav_module lib/httpd/mod_dav.so
LoadModule status_module lib/httpd/mod_status.so
LoadModule autoindex_module lib/httpd/mod_autoindex.so
#LoadModule asis_module lib/httpd/mod_asis.so
#LoadModule info_module lib/httpd/mod_info.so
#LoadModule cgid_module lib/httpd/mod_cgid.so
#LoadModule dav_fs_module lib/httpd/mod_dav_fs.so
#LoadModule dav_lock_module lib/httpd/mod_dav_lock.so
#LoadModule vhost_alias_module lib/httpd/mod_vhost_alias.so
#LoadModule negotiation_module lib/httpd/mod_negotiation.so
LoadModule dir_module lib/httpd/mod_dir.so
#LoadModule actions_module lib/httpd/mod_actions.so
#LoadModule speling_module lib/httpd/mod_speling.so
LoadModule userdir_module lib/httpd/mod_userdir.so
LoadModule alias_module lib/httpd/mod_alias.so
LoadModule rewrite_module lib/httpd/mod_rewrite.so
LoadModule perl_module lib/httpd/mod_perl.so
LoadModule php7_module lib/httpd/mod_php7.so

<IfModule unixd_module>
	User www
	Group www
</IfModule>

#
# rbsd.ankarstrom.se
#
ServerName rbsd.ankarstrom.se:80
ServerAdmin john@ankarstrom.se
DocumentRoot "/var/www/rbsd/htdocs"

# Secure root filesystem
<Directory />
	AllowOverride none
	Require all denied
</Directory>

<Directory "/var/www/rbsd/htdocs">
	Options Indexes FollowSymLinks
	AllowOverride All
	Require all granted
</Directory>

<IfModule dir_module>
	DirectoryIndex index.php index.html
</IfModule>

<Files ".ht*">
	Require all denied
</Files>

ErrorLog "/var/log/httpd/error_log"
LogLevel warn

<IfModule log_config_module>
	LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
	LogFormat "%h %l %u %t \"%r\" %>s %b" common
	CustomLog "/var/log/httpd/access_log" combined
</IfModule>

<IfModule alias_module>
	# Put Redirect, Alias and ScriptAlias directives here
	ScriptAlias /cgi-bin/ "/usr/pkg/libexec/cgi-bin/"
</IfModule>

<Directory "/usr/pkg/libexec/cgi-bin">
	AllowOverride None
	Options None
	Require all granted
</Directory>

<IfModule headers_module>
	#
	# Avoid passing HTTP_PROXY environment to CGI's on this or any proxied
	# backend servers which have lingering "httpoxy" defects.
	# 'Proxy' request header is undefined by the IETF, not listed by IANA
	#
	RequestHeader unset Proxy early
</IfModule>

<IfModule mime_module>
	TypesConfig etc/httpd/mime.types
	AddType application/x-compress .Z
	AddType application/x-gzip .gz .tgz

	#AddType application/x-gzip .tgz
	#AddEncoding x-compress .Z
	#AddEncoding x-gzip .gz .tgz
	#AddHandler cgi-script .cgi
	#AddType text/html .shtml
	#AddOutputFilter INCLUDES .shtml
</IfModule>

<FilesMatch \.php$>
	SetHandler application/x-httpd-php
</FilesMatch>

#MIMEMagicFile etc/httpd/magic

# Server-pool management (MPM specific)
#Include etc/httpd/httpd-mpm.conf

# Multi-language error messages
#Include etc/httpd/httpd-multilang-errordoc.conf

# Fancy directory listings
#Include etc/httpd/httpd-autoindex.conf

# Language settings
#Include etc/httpd/httpd-languages.conf

# User home directories
Include etc/httpd/httpd-userdir.conf

# Real-time info on requests and configuration
#Include etc/httpd/httpd-info.conf

# Virtual hosts
#Include etc/httpd/httpd-vhosts.conf

# Local access to the Apache HTTP Server Manual
#Include etc/httpd/httpd-manual.conf

# Distributed authoring and versioning (WebDAV)
#Include etc/httpd/httpd-dav.conf

# Various default settings
#Include etc/httpd/httpd-default.conf

# Configure mod_proxy_html to understand HTML4/XHTML1
<IfModule proxy_html_module>
Include etc/httpd/proxy-html.conf
</IfModule>

# Secure (SSL/TLS) connections
#Include etc/httpd/httpd-ssl.conf

#
# Note: The following must must be present to support
#       starting without SSL on platforms with no /dev/random equivalent
#       but a statically compiled-in mod_ssl.
#
<IfModule ssl_module>
SSLRandomSeed startup builtin
SSLRandomSeed connect builtin
</IfModule>

<Perl>
use warnings;
use subs qw/vhost idn with_idn block/;
use Tie::DxHash;

# Long-term redirections

my %redir = (
	'git.ankarstrom.se' => block(
		RewriteRule => '^Apache-Inject\.git/?$ /cpan/Apache-Inject/ [L,R,END]',
		RewriteRule => '^([^/]*)\.git(/.*)?$ /$1$2 [L,R,END]',
	),
	'john.ankarstrom.se' => block(
		Redirect => '301 /feed.rss /articles.xml',
		Redirect => '301 /feed.php /articles.xml',
		Redirect => '301 /english/texts/replacing-javascript /replacing-javascript',
		Redirect => '301 /web/separation-of-concerns.html /separation-of-concerns',
		Redirect => '301 /unix/learning-c.html /learning-c',
		Redirect => '301 /scripts http://git.ankarstrom.se/',
		Redirect => '301 /software http://git.ankarstrom.se',
		Redirect => '301 /ansi-sv-layout /sv-ansi',
	),
	'software.ankarstrom.se' => block(
		RewriteRule => '^(win32/)?ahk(/.*)? http://git.ankarstrom.se/ahk/about/ [L,R]',
		RewriteRule => '^(win32/)?drm(/.*)? http://git.ankarstrom.se/drm/about/ [L,R]',
		RewriteRule => '^(win32/)?run(/.*)? http://git.ankarstrom.se/run/about/ [L,R]',
		RewriteRule => '^(win32/)?tt(/.*)? http://git.ankarstrom.se/tt/about/ [L,R]',
		RewriteRule => '^(win32/)?watch(/.*)? http://git.ankarstrom.se/watch/about/ [L,R]',
		RewriteRule => '^.* http://git.ankarstrom.se/ [L,R]',
	),
);

# Virtual host configuration

vhost block(ServerName => 'ankarstrom.se',
	ServerAlias => [with_idn 'www.ankarstrom.se'],
	DocumentRoot => '/var/www/rbsd/htdocs',
);

vhost block(ServerName => 'lamnafacebook.nu',
	DocumentRoot => '/var/www/facebook/htdocs',
	ServerAlias => [with_idn 'www.lamnafacebook.nu'],
);

vhost block(ServerName => 'git.ankarstrom.se',
	Directory => block('/var/www/git/htdocs' => block(
		DirectoryIndex => 'cgit.cgi',
		Options => '+ExecCGI',
		RewriteEngine => 'On',
		RewriteCond => '%{REQUEST_FILENAME} !-f',
		RewriteCond => '%{REQUEST_FILENAME} !-d',
		RewriteRule => '(.*) cgit.cgi/$1 [END,QSA]',
	)),
);

vhost block(ServerName => 'dev.ankarstrom.se');
vhost block(ServerName => 'img.ankarstrom.se');
vhost block(ServerName => 'john.ankarstrom.se');
vhost block(ServerName => 'mail.ankarstrom.se');
vhost block(ServerName => 'software.ankarstrom.se');
vhost block(ServerName => 'perlisdead.org',
	DocumentRoot => '/var/www/perlisdead/out');

# Default virtual host configuration

sub vhost {
	my $vhost = $_[0]; # this should be a hash ref tied to Tie::DxHash

	if (!$vhost->{ServerName}) {
		warn 'Call to vhost missing ServerName, skipping virtual host';
		return;
	}

	# Merge directives of which only one instance is allowed
	if (!$vhost->{DocumentRoot}) {
		(my $subdomain = $vhost->{ServerName}) =~ s/\..*//;
		$vhost->{DocumentRoot} = "/var/www/$subdomain/htdocs";
	}

	# Merge directives of which multiple instances are allowed
	my $default = block(
		ServerAlias => idn($vhost->{ServerName}),
		Directory => block(
			$vhost->{DocumentRoot} => block(
				Options => 'Indexes FollowSymLinks',
				AllowOverride => 'All',
				Require => 'all granted',
				exists $redir{$vhost->{ServerName}} ? (RewriteEngine => 'On') : (),
				%{$redir{$vhost->{ServerName}}},
			),
		),
	);

	my @keys = keys %$vhost;
	my @values = values %$vhost;
	for (my $i = 0; $i < @keys; $i++) {
		$default->{$keys[$i]} = $values[$i];
	}
	$vhost = $default;

	$VirtualHost{'*:80'} = [@{$VirtualHost{'*:80'}||[]}, $vhost];
}

sub idn {
	my ($domain) = @_;
	$domain =~ s/ankarstrom\.se$/xn--ankarstrm-77a.se/;
	$domain =~ s/lamnafacebook\.nu$/xn--lmnafacebook-gcb.nu/;
	return $domain;
}

sub with_idn {
	return $_[0], idn $_[0];
}

sub block {
	my %hash;
	tie %hash, 'Tie::DxHash';
	%hash = @_;
	return \%hash;
}
</Perl>