AlmaLinux+Plesk环境下GLPI安全目录配置问题求助
解决GLPI 10.0.17在Plesk+AlmaLinux 9.5+NGINX下的安全目录检查报错
一、修正目录结构与配置文件定义
1. 目录权限与归属校准
- 将
/var/www/vhosts/yourdomain.com/internal/及其子目录的所有者设为Plesk对应站点的web用户(通常是nginx或站点专属系统用户),目录权限设为750,文件权限设为640。 - 将
/var/www/vhosts/yourdomain.com/subdomain/(GLPI主体目录)的所有者设为同一用户,权限设为755。
2. 修正inc/downstream.php内容
确保该文件准确指向配置目录并引入自定义配置:
<?php define('GLPI_CONFIG_DIR', '/var/www/vhosts/yourdomain.com/internal/config/'); if (file_exists(GLPI_CONFIG_DIR . '/local_define.php')) { require_once GLPI_CONFIG_DIR . '/local_define.php'; }
3. 完善config/local_define.php内容
补充所有非公共目录的定义,确保路径与实际目录一致:
<?php define('GLPI_VAR_DIR', '/var/www/vhosts/yourdomain.com/internal/files/'); define('GLPI_LOG_DIR', GLPI_VAR_DIR . 'logs/'); define('GLPI_MARKETPLACE_DIR', '/var/www/vhosts/yourdomain.com/internal/marketplace/'); // 自动创建日志目录(仅首次执行生效) if (!is_dir(GLPI_LOG_DIR)) { mkdir(GLPI_LOG_DIR, 0750, true); }
二、配置NGINX站点规则(核心修复)
在Plesk后台进入子域名设置 > Apache & NGINX Settings > Additional NGINX directives,替换原有指令为以下内容:
# 关键:将网站根目录指向GLPI的public子目录(GLPI 10.x标准公共入口) root /var/www/vhosts/yourdomain.com/subdomain/public; # 禁止访问所有隐藏文件 location ~ /\. { deny all; } # 双重防护:禁止直接访问GLPI非公共目录 location ~ ^/(inc|config|install|vendor|locales) { deny all; } # 适配GLPI的URL重写规则 location / { try_files $uri $uri/ /index.php$is_args$args; } # PHP-FPM配置(根据Plesk实际套接字路径调整,若不确定可查看Plesk PHP设置) location ~ \.php$ { include snippets/fastcgi-php.conf; fastcgi_pass unix:/var/www/vhosts/system/yourdomain.com/php-fpm.sock; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; }
注:如果之前将NGINX根目录指向
/var/www/vhosts/yourdomain.com/subdomain/,必须替换为public子目录——这是GLPI安全检查通过的核心前提,因为非公共文件均位于public之外,web server无法直接访问。
三、验证open_basedir配置
在Plesk子域名设置 > PHP Settings > open_basedir中确保包含以下目录:
/var/www/vhosts/yourdomain.com/subdomain/:/var/www/vhosts/yourdomain.com/internal/:/tmp/:/var/tmp/
四、生效配置并验证
- 重启NGINX与PHP-FPM服务:
systemctl restart nginx systemctl restart php-fpm
- 访问
https://subdomain.yourdomain.com,检查安全错误是否消失。 - 若问题依旧,查看GLPI日志文件
/var/www/vhosts/yourdomain.com/internal/files/logs/php-errors.log,排查路径定义或权限问题。
内容的提问来源于stack exchange,提问作者mainmind83
相关产品推荐
相关产品推荐

