Apache2でHTTP・HTTPSと認証を構成する
Debian 系の Apache HTTP Server で、HTTP / HTTPS、PAM 認証、LDAP 認証、HTTP から HTTPS へのリダイレクトを構成する。
client -> Apache HTTP Server ├─ VirtualHost *:80 │ ├─ HTTP content │ └─ mod_rewrite -> HTTPS redirect └─ VirtualHost *:443 ├─ mod_ssl -> HTTPS content └─ HTTP Basic authentication ├─ mod_authnz_pam -> PAM service └─ mod_authnz_ldap -> LDAP search / BindApache は、待ち受ける IP アドレスとポート、リクエストのホスト名に基づいて VirtualHost を選ぶ。その後、URL とファイルシステム上のパスに対応する設定を統合し、認証、認可、コンテンツの返却などを処理する。
HTTPS 証明書の作成は Server Certificateの作成 を参照する。LDAP の Bind と TLS は BindとSASL認証 と TLS・ACL・運用上の注意 を参照する。
主なモジュール
Section titled “主なモジュール”| モジュール | 役割 |
|---|---|
mod_ssl |
TLS 接続を受け、HTTPS を提供する |
mod_auth_basic |
HTTP Basic 認証の入口を提供する |
mod_authnz_pam |
Basic 認証で受け取った資格情報を PAM サービスへ渡す |
mod_authnz_ldap |
LDAP でユーザーを検索し、ユーザー DN で Bind して認証する |
mod_ldap |
LDAP 接続、TLS、接続プール、キャッシュを提供する |
mod_rewrite |
URL を規則に基づいて書き換え、またはリダイレクトする |
Apache HTTP Server公式ドキュメント
Section titled “Apache HTTP Server公式ドキュメント”-
Apache HTTP Server Version 2.4 Documentation Apache HTTP Server 2.4 の公式ドキュメント。
-
Configuration Sections
VirtualHost、Directory、Locationなどの設定セクション。 -
Authentication and Authorization 認証プロバイダーと
Requireによる認可。 -
mod_ssl HTTPS と TLS の設定。
-
mod_authnz_ldap LDAP を使った認証と認可。
-
mod_ldap LDAP 接続、TLS、キャッシュの設定。
-
mod_rewrite URL 書き換えとリダイレクトの設定。
Debianパッケージ
Section titled “Debianパッケージ”-
apache2 Debian 13 の Apache HTTP Server パッケージ。
-
libapache2-mod-authnz-pam Apache から PAM を利用するためのモジュール。