Ubuntu Apache服务器/www目录权限配置及POST交互密钥安全问询
Alright, let's tackle your questions step by step—you're working with an Ubuntu Apache setup focused on secure POST-only communication with a desktop app, so we'll prioritize security and proper permissions here:
1. /var/www Directory Permissions & POST-Only Access Setup
First, let's nail down the base permissions:
- For
/var/wwwitself: Keep ownership asroot:rootwith755permissions. This ensures only root can modify the top-level directory, while Apache'swww-datauser can read and navigate into it (critical for serving content). - For
/var/www/html(and any subdirs holding your PHP files): Set ownership toroot:www-datawith750permissions. This locks down write access to root only, but letswww-dataread and access the files it needs to serve.
To restrict your PHP files to only accept POST requests (blocking GET, PUT, etc.), you have two secure options:
Option 1: Apache Site Configuration (Recommended)
Edit your site's config file (usually in /etc/apache2/sites-available/your-site.conf) and add this rule inside the <Directory /var/www/html> block:
<FilesMatch "\.php$"> Require all granted <LimitExcept POST> Require all denied </LimitExcept> </FilesMatch>
Then reload Apache with sudo systemctl reload apache2. This avoids relying on .htaccess (which can be tampered with if permissions are misconfigured).
Option 2: .htaccess (If You Allow Overrides)
If you have AllowOverride All enabled for your directory, create a .htaccess file in /var/www/html with the same rule above.
2. Secure Key Storage & Directory Structure Optimization
Storing encryption keys directly in PHP files is risky—if PHP ever fails to parse (e.g., a syntax error), the raw key could be exposed to visitors. Here's a better setup:
- Create a non-web-accessible directory: Make a folder outside your
DocumentRoot(Apache won't serve content from here), like/var/www/secure/. - Store your key here: Save the key in a file like
/var/www/secure/encryption_key.txt, set permissions to600, and ownership toroot:www-data. This ensures only root andwww-datacan read the key—no other users get access. - Read the key in PHP: Use an absolute path to pull the key into your scripts:
$encryption_key = file_get_contents('/var/www/secure/encryption_key.txt');
Your final directory structure should look like this:
/var/www/ ├── html/ # Web root: only your POST-handling PHP files live here │ ├── auth_validate.php │ └── query_processor.php └── secure/ # Off-limits to web visitors: stores keys, configs, etc. └── encryption_key.txt
3. File Ownership: Root or www-data?
Always prefer root:www-data ownership for your PHP files, with 640 permissions:
- Root retains full control to edit or update the files.
www-dataonly gets read access (which is all it needs, since your scripts don't perform write operations).- Never set ownership to
www-dataalone—if an attacker compromises your PHP script, they could modify or delete your files. Pureroot:rootownership works too, but you need to ensurewww-datahas read access (which644would provide, but640is tighter since it restricts other users entirely).
4. Why Do PHP Files With 0000 Permissions Still Work?
This is a confusing edge case, and it's almost certainly due to one of these scenarios:
- Apache/PHP-FPM is running as root: This is a huge security no-no, but if your Apache process is running as root (check with
ps aux | grep apache2), it can read any file regardless of permissions. Fix this immediately—Apache should always run aswww-data. - SELinux/AppArmor is in permissive mode: These security modules enforce additional access controls. If they're set to permissive (run
sestatusto check), they'll ignore file permission restrictions and let Apache read the file. - Cached PHP opcode: If your server uses opcode caching (like OPcache), the script might have been cached when permissions were valid, so Apache is serving the cached version instead of reading the 0000 file.
Don't rely on this behavior—0000 permissions are not secure (they're ambiguous and can lead to unexpected issues). Stick to 640 for your PHP files to keep things predictable and safe.
内容的提问来源于stack exchange,提问作者hawkesbury

