Advertising
- Mine
- Friday, March 16th, 2007 at 12:12:58pm UTC
- ------------------------------------------------------------------------
- | APACHE2.CONF |
- ------------------------------------------------------------------------
- # Based upon the NCSA server configuration files originally by Rob McCool.
- # Changed extensively for the Debian package by Daniel Stone <[email protected]>
- # and also by Thom May <[email protected]>.
- # ServerRoot: The top of the directory tree under which the server's
- # configuration, error, and log files are kept.
- #
- # NOTE! If you intend to place this on an NFS (or otherwise network)
- # mounted filesystem then please read the LockFile documentation
- # (available at <URL:http://www.apache.org/docs/mod/core.html#lockfile>);
- # you will save yourself a lot of trouble.
- ServerRoot "/etc/apache2"
- # The LockFile directive sets the path to the lockfile used when Apache
- # is compiled with either USE_FCNTL_SERIALIZED_ACCEPT or
- # USE_FLOCK_SERIALIZED_ACCEPT. This directive should normally be left at
- # its default value. The main reason for changing it is if the logs
- # directory is NFS mounted, since the lockfile MUST BE STORED ON A LOCAL
- # DISK. The PID of the main server process is automatically appended to
- # the filename.
- LockFile /var/lock/apache2/accept.lock
- # PidFile: The file in which the server should record its process
- # identification number when it starts.
- PidFile /var/run/apache2.pid
- # Timeout: The number of seconds before receives and sends time out.
- Timeout 300
- # KeepAlive: Whether or not to allow persistent connections (more than
- # one request per connection). Set to "Off" to deactivate.
- KeepAlive On
- # MaxKeepAliveRequests: The maximum number of requests to allow
- # during a persistent connection. Set to 0 to allow an unlimited amount.
- # We recommend you leave this number high, for maximum performance.
- MaxKeepAliveRequests 100
- # KeepAliveTimeout: Number of seconds to wait for the next request from the
- # same client on the same connection.
- KeepAliveTimeout 15
- ##
- ## Server-Pool Size Regulation (MPM specific)
- ##
- # prefork MPM
- # StartServers ......... number of server processes to start
- # MinSpareServers ...... minimum number of server processes which are kept spare
- # MaxSpareServers ...... maximum number of server processes which are kept spare
- # MaxClients ........... maximum number of server processes allowed to start
- # MaxRequestsPerChild .. maximum number of requests a server process serves
- <IfModule prefork.c>
- StartServers 5
- MinSpareServers 5
- MaxSpareServers 10
- MaxClients 20
- MaxRequestsPerChild 0
- </IfModule>
- # pthread MPM
- # StartServers ......... initial number of server processes to start
- # MaxClients ........... maximum number of server processes allowed to start
- # MinSpareThreads ...... minimum number of worker threads which are kept spare
- # MaxSpareThreads ...... maximum number of worker threads which are kept spare
- # ThreadsPerChild ...... constant number of worker threads in each server process
- # MaxRequestsPerChild .. maximum number of requests a server process serves
- <IfModule worker.c>
- StartServers 2
- MaxClients 150
- MinSpareThreads 25
- MaxSpareThreads 75
- ThreadsPerChild 25
- MaxRequestsPerChild 0
- </IfModule>
- # perchild MPM
- # NumServers ........... constant number of server processes
- # StartThreads ......... initial number of worker threads in each server process
- # MinSpareThreads ...... minimum number of worker threads which are kept spare
- # MaxSpareThreads ...... maximum number of worker threads which are kept spare
- # MaxThreadsPerChild ... maximum number of worker threads in each server process
- # MaxRequestsPerChild .. maximum number of connections per server process (then it dies)
- <IfModule perchild.c>
- NumServers 5
- StartThreads 5
- MinSpareThreads 5
- MaxSpareThreads 10
- MaxThreadsPerChild 20
- MaxRequestsPerChild 0
- AcceptMutex fcntl
- </IfModule>
- User www-data
- Group www-data
- # The following directives define some format nicknames for use with
- # a CustomLog directive (see below).
- LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
- LogFormat "%h %l %u %t \"%r\" %>s %b" common
- LogFormat "%{Referer}i -> %U" referer
- LogFormat "%{User-agent}i" agent
- # Global error log.
- ErrorLog /var/log/apache2/error.log
- # Include module configuration:
- Include /etc/apache2/mods-enabled/*.load
- Include /etc/apache2/mods-enabled/*.conf
- # Include all the user configurations:
- Include /etc/apache2/httpd.conf
- # Include ports listing
- Include /etc/apache2/ports.conf
- # Include generic snippets of statements
- Include /etc/apache2/conf.d/[^.#]*
- #Let's have some Icons, shall we?
- Alias /icons/ "/usr/share/apache2/icons/"
- <Directory "/usr/share/apache2/icons">
- Options Indexes MultiViews
- AllowOverride None
- Order allow,deny
- Allow from all
- </Directory>
- # Set up the default error docs.
- #
- # Customizable error responses come in three flavors:
- # 1) plain text 2) local redirects 3) external redirects
- #
- # Some examples:
- #ErrorDocument 500 "The server made a boo boo."
- #ErrorDocument 404 /missing.html
- #ErrorDocument 404 "/cgi-bin/missing_handler.pl"
- #ErrorDocument 402 http://www.example.com/subscription_info.html
- #
- #
- # Putting this all together, we can Internationalize error responses.
- #
- # We use Alias to redirect any /error/HTTP_<error>.html.var response to
- # our collection of by-error message multi-language collections. We use
- # includes to substitute the appropriate text.
- #
- # You can modify the messages' appearance without changing any of the
- # default HTTP_<error>.html.var files by adding the line;
- #
- # Alias /error/include/ "/your/include/path/"
- #
- # which allows you to create your own set of files by starting with the
- # /usr/local/apache2/error/include/ files and
- # copying them to /your/include/path/, even on a per-VirtualHost basis.
- #
- <IfModule mod_negotiation.c>
- <IfModule mod_include.c>
- Alias /error/ "/usr/share/apache2/error/"
- <Directory "/usr/share/apache2/error">
- AllowOverride None
- Options IncludesNoExec
- AddOutputFilter Includes html
- AddHandler type-map var
- Order allow,deny
- Allow from all
- LanguagePriority en es de fr
- ForceLanguagePriority Prefer Fallback
- </Directory>
- ErrorDocument 400 /error/HTTP_BAD_REQUEST.html.var
- ErrorDocument 401 /error/HTTP_UNAUTHORIZED.html.var
- ErrorDocument 403 /error/HTTP_FORBIDDEN.html.var
- ErrorDocument 404 /error/HTTP_NOT_FOUND.html.var
- ErrorDocument 405 /error/HTTP_METHOD_NOT_ALLOWED.html.var
- ErrorDocument 408 /error/HTTP_REQUEST_TIME_OUT.html.var
- ErrorDocument 410 /error/HTTP_GONE.html.var
- ErrorDocument 411 /error/HTTP_LENGTH_REQUIRED.html.var
- ErrorDocument 412 /error/HTTP_PRECONDITION_FAILED.html.var
- ErrorDocument 413 /error/HTTP_REQUEST_ENTITY_TOO_LARGE.html.var
- ErrorDocument 414 /error/HTTP_REQUEST_URI_TOO_LARGE.html.var
- ErrorDocument 415 /error/HTTP_SERVICE_UNAVAILABLE.html.var
- ErrorDocument 500 /error/HTTP_INTERNAL_SERVER_ERROR.html.var
- ErrorDocument 501 /error/HTTP_NOT_IMPLEMENTED.html.var
- ErrorDocument 502 /error/HTTP_BAD_GATEWAY.html.var
- ErrorDocument 503 /error/HTTP_SERVICE_UNAVAILABLE.html.var
- ErrorDocument 506 /error/HTTP_VARIANT_ALSO_VARIES.html.var
- </IfModule>
- </IfModule>
- DirectoryIndex index.html index.htm index.shtml index.cgi index.php index.php3 index.pl index.xhtml
- # UserDir is now a module
- #UserDir public_html
- #UserDir disabled root
- #<Directory /home/*/public_html>
- # AllowOverride FileInfo AuthConfig Limit
- # Options Indexes SymLinksIfOwnerMatch IncludesNoExec
- #</Directory>
- AccessFileName .htaccess
- <Files ~ "^\.ht">
- Order allow,deny
- Deny from all
- </Files>
- UseCanonicalName Off
- TypesConfig /etc/mime.types
- DefaultType text/plain
- HostnameLookups Off
- IndexOptions FancyIndexing VersionSort
- AddIconByEncoding (CMP,/icons/compressed.gif) x-compress x-gzip
- AddIconByType (TXT,/icons/text.gif) text/*
- AddIconByType (IMG,/icons/image2.gif) image/*
- AddIconByType (SND,/icons/sound2.gif) audio/*
- AddIconByType (VID,/icons/movie.gif) video/*
- # This really should be .jpg.
- AddIcon /icons/binary.gif .bin .exe
- AddIcon /icons/binhex.gif .hqx
- AddIcon /icons/tar.gif .tar
- AddIcon /icons/world2.gif .wrl .wrl.gz .vrml .vrm .iv
- AddIcon /icons/compressed.gif .Z .z .tgz .gz .zip
- AddIcon /icons/a.gif .ps .ai .eps
- AddIcon /icons/layout.gif .html .shtml .htm .pdf
- AddIcon /icons/text.gif .txt
- AddIcon /icons/c.gif .c
- AddIcon /icons/p.gif .pl .py
- AddIcon /icons/f.gif .for
- AddIcon /icons/dvi.gif .dvi
- AddIcon /icons/uuencoded.gif .uu
- AddIcon /icons/script.gif .conf .sh .shar .csh .ksh .tcl
- AddIcon /icons/tex.gif .tex
- AddIcon /icons/bomb.gif core
- AddIcon /icons/back.gif ..
- AddIcon /icons/hand.right.gif README
- AddIcon /icons/folder.gif ^^DIRECTORY^^
- AddIcon /icons/blank.gif ^^BLANKICON^^
- # This is from Matty J's patch. Anyone want to make the icons?
- #AddIcon /icons/dirsymlink.jpg ^^SYMDIR^^
- #AddIcon /icons/symlink.jpg ^^SYMLINK^^
- DefaultIcon /icons/unknown.gif
- ReadmeName README.html
- HeaderName HEADER.html
- IndexIgnore .??* *~ *# HEADER* RCS CVS *,t
- AddEncoding x-compress Z
- AddEncoding x-gzip gz tgz
- AddLanguage da .dk
- AddLanguage nl .nl
- AddLanguage en .en
- AddLanguage et .et
- AddLanguage fr .fr
- AddLanguage de .de
- AddLanguage el .el
- AddLanguage it .it
- AddLanguage ja .ja
- AddLanguage pl .po
- AddLanguage ko .ko
- AddLanguage pt .pt
- AddLanguage no .no
- AddLanguage pt-br .pt-br
- AddLanguage ltz .ltz
- AddLanguage ca .ca
- AddLanguage es .es
- AddLanguage sv .se
- AddLanguage cz .cz
- AddLanguage ru .ru
- AddLanguage tw .tw
- AddLanguage zh-tw .tw
- LanguagePriority en da nl et fr de el it ja ko no pl pt pt-br ltz ca es sv tw
- #AddDefaultCharset ISO-8859-1
- AddCharset ISO-8859-1 .iso8859-1 .latin1
- AddCharset ISO-8859-2 .iso8859-2 .latin2 .cen
- AddCharset ISO-8859-3 .iso8859-3 .latin3
- AddCharset ISO-8859-4 .iso8859-4 .latin4
- AddCharset ISO-8859-5 .iso8859-5 .latin5 .cyr .iso-ru
- AddCharset ISO-8859-6 .iso8859-6 .latin6 .arb
- AddCharset ISO-8859-7 .iso8859-7 .latin7 .grk
- AddCharset ISO-8859-8 .iso8859-8 .latin8 .heb
- AddCharset ISO-8859-9 .iso8859-9 .latin9 .trk
- AddCharset ISO-2022-JP .iso2022-jp .jis
- AddCharset ISO-2022-KR .iso2022-kr .kis
- AddCharset ISO-2022-CN .iso2022-cn .cis
- AddCharset Big5 .Big5 .big5
- # For russian, more than one charset is used (depends on client, mostly):
- AddCharset WINDOWS-1251 .cp-1251 .win-1251
- AddCharset CP866 .cp866
- AddCharset KOI8-r .koi8-r .koi8-ru
- AddCharset KOI8-ru .koi8-uk .ua
- AddCharset ISO-10646-UCS-2 .ucs2
- AddCharset ISO-10646-UCS-4 .ucs4
- AddCharset UTF-8 .utf8
- AddCharset GB2312 .gb2312 .gb
- AddCharset utf-7 .utf7
- AddCharset utf-8 .utf8
- AddCharset big5 .big5 .b5
- AddCharset EUC-TW .euc-tw
- AddCharset EUC-JP .euc-jp
- AddCharset EUC-KR .euc-kr
- AddCharset shift_jis .sjis
- #AddType application/x-httpd-php .php
- #AddType application/x-httpd-php-source .phps
- AddType application/x-tar .tgz
- # To use CGI scripts outside /cgi-bin/:
- #
- #AddHandler cgi-script .cgi
- # To use server-parsed HTML files
- #
- <FilesMatch "\.shtml(\..+)?$">
- SetOutputFilter INCLUDES
- </FilesMatch>
- # If you wish to use server-parsed imagemap files, use
- #
- #AddHandler imap-file map
- BrowserMatch "Mozilla/2" nokeepalive
- BrowserMatch "MSIE 4\.0b2;" nokeepalive downgrade-1.0 force-response-1.0
- BrowserMatch "RealPlayer 4\.0" force-response-1.0
- BrowserMatch "Java/1\.0" force-response-1.0
- BrowserMatch "JDK/1\.0" force-response-1.0
- #
- # The following directive disables redirects on non-GET requests for
- # a directory that does not include the trailing slash. This fixes a
- # problem with Microsoft WebFolders which does not appropriately handle
- # redirects for folders with DAV methods.
- #
- BrowserMatch "Microsoft Data Access Internet Publishing Provider" redirect-carefully
- BrowserMatch "^WebDrive" redirect-carefully
- BrowserMatch "^gnome-vfs" redirect-carefully
- BrowserMatch "^WebDAVFS/1.[012]" redirect-carefully
- # Allow server status reports, with the URL of http://servername/server-status
- # Change the ".your_domain.com" to match your domain to enable.
- #
- #<Location /server-status>
- # SetHandler server-status
- # Order deny,allow
- # Deny from all
- # Allow from .your_domain.com
- #</Location>
- # Allow remote server configuration reports, with the URL of
- # http://servername/server-info (requires that mod_info.c be loaded).
- # Change the ".your_domain.com" to match your domain to enable.
- #
- #<Location /server-info>
- # SetHandler server-info
- # Order deny,allow
- # Deny from all
- # Allow from .your_domain.com
- #</Location>
- # Include the virtual host configurations:
- Include /etc/apache2/sites-enabled/default
- ------------------------------------------------------------------------
- | sites-enabled(available)/DEFAULT.CONF |
- ------------------------------------------------------------------------
- NameVirtualHost *:80
- <VirtualHost *:80>
- ServerName rsadesign.nl.
- ServerAlias www.rsadesign.nl
- DocumentRoot /home/harm/site01
- ErrorLog /home/harm/site01/log/error.log
- </VirtualHost>
- <VirtualHost *:80>
- ServerName site02.homelinux.org
- #ServerAlias
- DocumentRoot /home/harm/site02
- ErrorLog /home/harm/site02/log/error.log
- </VirtualHost>
- <VirtualHost *:80>
- ServerName site03.homelinux.org
- #ServerAlias
- DocumentRoot /home/harm/site03
- ErrorLog /home/harm/site03/log/error.log
- </VirtualHost>
- <VirtualHost *:80>
- ServerName tre-amici.nl
- ServerAlias www.tre-amici.nl www.treamici.nl treamici.nl site04.homelinux.org
- DocumentRoot /home/harm/site04
- ErrorLog /home/harm/site04/log/error.log
- </VirtualHost>
- <VirtualHost *:80>
- ServerName site05.homelinux.org
- #ServerAlias
- DocumentRoot /home/harm/site05
- ErrorLog /home/harm/site05/log/error.log
- </VirtualHost>
- <VirtualHost *:80>
- ServerName site06.homelinux.org
- #ServerAlias
- DocumentRoot /home/harm/site06
- ErrorLog /home/harm/site06/log/error.log
- </VirtualHost>
- <VirtualHost *:80>
- ServerName site07.homelinux.org
- #ServerAlias
- DocumentRoot /home/harm/site07
- ErrorLog /home/harm/site07/log/error.log
- </VirtualHost>
- ------------------------------------------------------------------------
- | /etc/hosts |
- ------------------------------------------------------------------------
- 127.0.0.1 localhost.localdomain localhost
- 192.168.1.39 server1 server1.rsadesign.nl
- # The following lines are desirable for IPv6 capable hosts
- ::1 ip6-localhost ip6-loopback
- fe00::0 ip6-localnet
- ff00::0 ip6-mcastprefix
- ff02::1 ip6-allnodes
- ff02::2 ip6-allrouters
- ff02::3 ip6-allhosts
- ------------------------------------------------------------------------
- | VSFTPD.CONF |
- ------------------------------------------------------------------------
- # Example config file /etc/vsftpd.conf
- #
- # The default compiled in settings are fairly paranoid. This sample file
- # loosens things up a bit, to make the ftp daemon more usable.
- # Please see vsftpd.conf.5 for all compiled in defaults.
- #
- # READ THIS: This example file is NOT an exhaustive list of vsftpd options.
- # Please read the vsftpd.conf.5 manual page to get a full idea of vsftpd's
- # capabilities.
- #
- #
- # Run standalone? vsftpd can run either from an inetd or as a standalone
- # daemon started from an initscript.
- listen=YES
- #
- # Run standalone with IPv6?
- # Like the listen parameter, except vsftpd will listen on an IPv6 socket
- # instead of an IPv4 one. This parameter and the listen parameter are mutually
- # exclusive.
- #listen_ipv6=YES
- #
- # Allow anonymous FTP? (Beware - allowed by default if you comment this out).
- anonymous_enable=NO
- #
- # Uncomment this to allow local users to log in.
- local_enable=YES
- #
- # Uncomment this to enable any form of FTP write command.
- write_enable=YES
- #
- # Default umask for local users is 077. You may wish to change this to 022,
- # if your users expect that (022 is used by most other ftpd's)
- #local_umask=022
- #
- # Uncomment this to allow the anonymous FTP user to upload files. This only
- # has an effect if the above global write enable is activated. Also, you will
- # obviously need to create a directory writable by the FTP user.
- #anon_upload_enable=YES
- #
- # Uncomment this if you want the anonymous FTP user to be able to create
- # new directories.
- #anon_mkdir_write_enable=YES
- #
- # Activate directory messages - messages given to remote users when they
- # go into a certain directory.
- dirmessage_enable=YES
- #
- # Activate logging of uploads/downloads.
- xferlog_enable=YES
- #
- # Make sure PORT transfer connections originate from port 20 (ftp-data).
- connect_from_port_20=YES
- #
- # If you want, you can arrange for uploaded anonymous files to be owned by
- # a different user. Note! Using "root" for uploaded files is not
- # recommended!
- #chown_uploads=YES
- #chown_username=whoever
- #
- # You may override where the log file goes if you like. The default is shown
- # below.
- #xferlog_file=/var/log/vsftpd.log
- #
- # If you want, you can have your log file in standard ftpd xferlog format
- #xferlog_std_format=YES
- #
- # You may change the default value for timing out an idle session.
- #idle_session_timeout=600
- #
- # You may change the default value for timing out a data connection.
- #data_connection_timeout=120
- #
- # It is recommended that you define on your system a unique user which the
- # ftp server can use as a totally isolated and unprivileged user.
- #nopriv_user=ftpsecure
- #
- # Enable this and the server will recognise asynchronous ABOR requests. Not
- # recommended for security (the code is non-trivial). Not enabling it,
- # however, may confuse older FTP clients.
- #async_abor_enable=YES
- #
- # By default the server will pretend to allow ASCII mode but in fact ignore
- # the request. Turn on the below options to have the server actually do ASCII
- # mangling on files when in ASCII mode.
- # Beware that on some FTP servers, ASCII support allows a denial of service
- # attack (DoS) via the command "SIZE /big/file" in ASCII mode. vsftpd
- # predicted this attack and has always been safe, reporting the size of the
- # raw file.
- # ASCII mangling is a horrible feature of the protocol.
- #ascii_upload_enable=YES
- #ascii_download_enable=YES
- #
- # You may fully customise the login banner string:
- ftpd_banner=Welcome to RsaDesign.Nl
- #
- # You may specify a file of disallowed anonymous e-mail addresses. Apparently
- # useful for combatting certain DoS attacks.
- #deny_email_enable=YES
- # (default follows)
- #banned_email_file=/etc/vsftpd.banned_emails
- #
- # You may restrict local users to their home directories. See the FAQ for
- # the possible risks in this before using chroot_local_user or
- # chroot_list_enable below.
- #chroot_local_user=YES
- #
- # You may specify an explicit list of local users to chroot() to their home
- # directory. If chroot_local_user is YES, then this list becomes a list of
- # users to NOT chroot().
- #chroot_list_enable=YES
- # (default follows)
- #chroot_list_file=/etc/vsftpd.chroot_list
- #
- # You may activate the "-R" option to the builtin ls. This is disabled by
- # default to avoid remote users being able to cause excessive I/O on large
- # sites. However, some broken FTP clients such as "ncftp" and "mirror" assume
- # the presence of the "-R" option, so there is a strong case for enabling it.
- #ls_recurse_enable=YES
- #
- #
- # Debian customization
- #
- # Some of vsftpd's settings don't fit the Debian filesystem layout by
- # default. These settings are more Debian-friendly.
- #
- # This option should be the name of a directory which is empty. Also, the
- # directory should not be writable by the ftp user. This directory is used
- # as a secure chroot() jail at times vsftpd does not require filesystem
- # access.
- secure_chroot_dir=/var/run/vsftpd
- #
- # This string is the name of the PAM service vsftpd will use.
- pam_service_name=vsftpd
- #
- # This option specifies the location of the RSA certificate to use for SSL
- # encrypted connections.
- rsa_cert_file=/etc/ssl/certs/ssl-cert-snakeoil.pem
- #
- # This option specifies the location of the RSA key to use for SSL
- # encrypted connections.
- rsa_private_key_file=/etc/ssl/private/ssl-cert-snakeoil.key
advertising
Update the Post
Either update this post and resubmit it with changes, or make a new post.
You may also comment on this post.
Please note that information posted here will not expire by default. If you do not want it to expire, please set the expiry time above. If it is set to expire, web search engines will not be allowed to index it prior to it expiring. Items that are not marked to expire will be indexable by search engines. Be careful with your passwords. All illegal activities will be reported and any information will be handed over to the authorities, so be good.