Tuesday, January 1, 2019

Apache 2.4 /PHP7.3 /PHP-FPM /freeBSD 12 (part 2): Mysql Server57/PHP Extensions

Install Mysql server 57: 
MySQL server 5.7 installations of FreeBSD 12

Install PHP Extensions:
When you install any DB support PHP extension it will automatically install this particular DB client libraries. Chances are that these client libs will be of an old version. To avoid version mismatch simply install the database server of version you want before installing the PHP extension.
# cd /usr/ports/lang/php73-extensions && make install clean

This is a meta-port listing main PHP extension. You check the option and it will install the port of this extension. But the list is not complete, for example, pecl-* extensions you will have to install by hand:
# cd /usr/ports/devel/pecl-intl
# make install clean

Complete!


Block website with mikrotik

First, create a rule in IP>Firewall.Layer7

Add this Regix expression:
^.+(freelancer.com|upwork.com).*$


Secondly, create a firewal rule

In. interface: Lan
Action: Drop
rule: Forward
Layer 7: point the the layer 7 records,

Sunday, December 30, 2018

Apache 2.4 /PHP7.3 /PHP-FPM /freeBSD 12 (part 1)

Install Apache 2.4:
# cd /usr/ports/www/apache24/ && make install clean BATCH=yes
Just append BATCH=yes at the end of the command and they will go straight away as they are without asking anymore.

httpd.conf:
# cp /usr/local/etc/apache24/httpd.conf /usr/local/etc/apache24/httpd.conf.original
# ee /usr/local/etc/apache24/httpd.conf

Virtual host configuration:
# Ensure that Apache listens on port 80
Listen 80
<VirtualHost *:80>
    ServerName 13.211.209.48
    ServerAlias example
    DocumentRoot "/usr/local/www/apache24/life110volts.com"
    DirectoryIndex index.php index.html

    <Directory /usr/local/www/apache24/life110volts.com>
        Options -Indexes +FollowSymLinks +MultiViews
        AllowOverride All
        Require all granted
    </Directory>

    <FilesMatch \.php$>
         SetHandler "proxy:unix:/var/run/php5-fpm.sock|fcgi://localhost/"
    </FilesMatch>

    ErrorLog /var/log/life110volts.com-error.log

    # Possible values include: debug, info, notice, warn, error, crit,
    # alert, emerg.
    LogLevel warn

    CustomLog /var/log/life110volts.com-access.log combined

</VirtualHost>

VirtualHost Examples: https://httpd.apache.org/docs/2.4/vhosts/examples.html


Website:
# mkdir /usr/local/www/apache24/life110volts.com
# ls -l /usr/local/www/apache24/life110volts.com
# chown -R www:www /usr/local/www/apache24/life110volts.com
# chown -R 755 /usr/local/www/apache24/life110volts.com
# ee /usr/local/www/apache24/life110volts.com/index.html
# ee /usr/local/www/apache24/life110volts.com/index.php
# ee /usr/local/www/apache24/life110volts.com/info.php

Start/Stop:
# sysrc apache24_enable=yes
# apachectl configtest
# service apache24 onestart
# service apache24 restart && service nginx reload

Curl the web page on Localhost.
# cd /usr/ports/ftp/curl && make install clean
# curl -i 127.0.0.1:8080/info.php
# curl -i 127.0.0.1:8080

Install PHP 7.3
To get a list of all available PHP version packages provided by FreeBSD Ports repositories
# ls /usr/ports/lang/ | grep php
# whereis mod_php73
# cd /usr/ports/lang/php73 && make install clean
(choose the php-FPM box)
(# make config)
# rehash
# php -v
# cp /usr/local/etc/php.ini-production /usr/local/etc/php.ini

Install PHP-FPM
FastCGI Process Manager - alternative FastCGI implementation
In addition to Apache and PHP-FPM, we will also install the PHP FastCGI Apache module, libapache2-mod-fastcgi, to support FastCGI web applications. In order to get the ability of handling the FastCGI protocol, mod_proxy and mod_proxy_fcgi have to be present in the server.
#LoadModule proxy_module libexec/apache24/mod_proxy.so
#LoadModule proxy_fcgi_module libexec/apache24/mod_proxy_fcgi.so

Normally PHP-FPM configuration files are located on /usr/local/etc/php-fpm.conf file and /usr/local/etc/php-fpm.d path. This is normally excellent start and all pool configs goes to /usr/local/etc/php-fpm.d directory. You need to add following include line on your php-fpm.conf file:
include=/etc/php-fpm.d/*.conf

Configure PHP-FPM
# ee /usr/local/etc/php-fpm.d/www.conf
listen = 127.0.0.1:9000 //
listen = /var/run/php-fpm.sock
listen = /var/run/php72-fpm.sock //
listen.owner = www
listen.group = www
listen.mode = 0660

# sysrc php_fpm_enable=YES

Start/Stop:
# service php-fpm stop
# service php-fpm start
# service php-fpm restart
# service php-fpm status

Nginx:Installing 
# cd /usr/ports/www/nginx && make config-recursive
- Accept the defaults.
# make install clean

Edit Nginx.conf
# nano /usr/local/etc/nginx/nginx.conf

# sysrc nginx_enable="YES"
# sudo nginx -t
# sudo service nginx reload

Location of importants files:
Nginx:
# ee /usr/local/etc/nginx/nginx.conf
Document Dir:
# ls /usr/local/www/
Modules dir:
Logs:
/var/log/nginx/example.com.access.log;

Apache:
# ee /usr/local/etc/apache24/httpd.conf
Web dir or DocumentRoot/ Directory:
# ls -l /usr/local/www/apache24/data
Modules.d directory:
# ee /usr/local/etc/apache24/modules.d/030_php-fpm.conf
Logs:
tail -f /var/log/httpd-access.log
tail -f /var/log/httpd-error.log
Includes:
# ee /usr/local/etc/apache24/Includes/php.conf

PHP:
# ee /usr/local/etc/php-fpm.d/www.conf
# ee /usr/local/etc/php-fpm.conf
# ee /usr/local/etc/php.ini

freeBSD:
# ee /etc/rc.conf

Courtesy:
1. How to install NGINX in CentOS 7 or FreeBSD and configure it to act as a Reverse Caching Proxy for Apache: 

Saturday, December 29, 2018

IPFW stateful firewall written for FreeBSD

IPFW is a stateful firewall written for FreeBSD.

# ee /etc/rc.conf
/etc/rc.conf
. . .
nginx_enable="YES"
firewall_enable="YES"
firewall_type="workstation"
firewall_myservices="22/tcp 80/tcp"
firewall_allowservices="any"
For the first time to run the server (in csh or tcsh shells, freeBSD)
# nohup service ipfw start >&/tmp/ipfw.log

Stop, start and restart the ipfw service.
# sudo service ipfw stop
# sudo service ipfw start
# sudo service ipfw restart

Friday, December 28, 2018

freeBSD Pkg operations

Link: Using pkg for Binary Package Management

Package Information with Pkg:
# pkg info package_name

Search for packages name:
# pkg search package_name
# pkg search -o php
Detailed package information:
# pkg search -f package_name
For a specific version of PHP:
# pkg search php5 | less
# pkg search php7
# pkg search nginx

Search the descriptions:
# pkg search -D pattern
# pkg search -D java
# pkg help search

Package install with Pkg:
# pkg install package_name
# pkg install package1 package2 ...
# pkg install nginx

If you are using the default shell, tcsh, or csh, you should rebuild the list of binaries in your PATH with this command:
# rehash

Run Services:
Runs as a service:
# ee /etc/rc.conf
# sysrc nginx_enable=yes
# service nginx start

Upgrade Installed Packages with Pkg:
# pkg upgrade

Delete Packages with Pkg:
# pkg delete package_name
# pkg delete package1 package2 ...
# pkg delete nginx

Remove Unused Dependencies
# pkg autoremove


Furthue reading: Install with ports.
OS: freeBSD 12

Thursday, December 27, 2018

Pointing a domain to your server public IP

1. Ngnix ready

2. Edit "A" record of your domain and point it to your public IP address.
Host : @
Points to : 52.65.138.1
TTL : 1 Hour

3. Nameservers remains defult.

4. Ngnix server block point your public IP:
    server {
        listen       8081;
        server_name  52.65.138.1;

5. Go! mydomail.com:8081 => Test ok!

Next step:

SRV (godaddy DNS):

Type : SRV
Service : _http
Protocol: _tcp
Name : e1.life110volts.com
Priority: 0
Weight : 0
Target : @
Prot : 8081
TTL : 1 Hour

Nginx on freeBSD: 3. Install free TLS/SSL certificates

(let assume you have a webserver with a public ip, and your DNS A record is pointing to your public IP)

Install Certbot:
# portsnap fetch
# portsnap extract

Install Let's Encrypt client:
# cd /usr/ports/security/py-certbot
# sudo make install clean

Install NGINX plugin for Certbot:
# cd /usr/ports/security/py-certbot-nginx
# sudo make install clean

Setting Up a Firewall and Allowing HTTPS Access:
Inside file, /etc/rc.conf
firewall_myservices="22/tcp 80/tcp 443/tcp"
Port 433/tpc must be open
IPFW is a stateful firewall written for FreeBSD.

Obtaining an SSL Certificate:
# sudo certbot --nginx -d life110volts.com -d www.life110volts.com
Give your email, domain ownership challange.


IMPORTANT NOTES:
 - Congratulations! Your certificate and chain have been saved at:
   /usr/local/etc/letsencrypt/live/life110volts.com/fullchain.pem
   Your key file has been saved at:
   /usr/local/etc/letsencrypt/live/life110volts.com/privkey.pem
   Your cert will expire on 2019-03-28. To obtain a new or tweaked
   version of this certificate in the future, simply run certbot again
   with the "certonly" option. To non-interactively renew *all* of
   your certificates, run "certbot renew"
 - Your account credentials have been saved in your Certbot
   configuration directory at /usr/local/etc/letsencrypt. You should
   make a secure backup of this folder now. This configuration
   directory will also contain certificates and private keys obtained
   by Certbot so making regular backups of this folder is ideal.
 - If you like Certbot, please consider supporting our work by:

   Donating to ISRG / Let's Encrypt:   https://letsencrypt.org/donate
   Donating to EFF:                    https://eff.org/donate-le

Check your website:
SSL Server Test


Part: 2, 
Renew certificate:
You need to automate certificate renewal by setting up a cron task. It’s important to test that you’re able to renew certificates correctly.

# sudo certbot renew --dry-run
If you see no errors, you’re all set to create a new crontab:

# sudo crontab -e 
This will open a new crontab file, paste bellow line in that file, it will auto renew your certificate if it close to date.
0 0,12 * * * /usr/local/bin/certbot renew