Skip to content

apache_httpd: OWASP CRS 4.30.0 and CRS/reload fixes on Debian and Ubuntu - #424

Merged
markuslf merged 3 commits into
mainfrom
fix/apache-httpd-crs-debian-ubuntu
Oct 5, 2026
Merged

markuslf merged 3 commits into
mainfrom
fix/apache-httpd-crs-debian-ubuntu

Conversation

@markuslf

@markuslf markuslf commented Oct 5, 2026

Copy link
Copy Markdown
Member

Summary

  • PidFile on Debian/Ubuntu: the rendered apache2.conf set no PidFile, so the first run against a fresh host failed reloading Apache (apachectl graceful looked for the PID where the package-started server had not written it). The role now sets PidFile ${APACHE_PID_FILE} as Debian's own apache2.conf does; hosts still running with the old /run/apache2.pid are restarted once instead of reloaded.
  • CRS on Debian/Ubuntu: the role creates modsecurity.d, downloads the CRS on the controller, reloads Apache when the deployed release changes, extracts idempotently, and aborts with a clear message on Ubuntu 22.04, whose ModSecurity 2.9.5 cannot load CRS 4.
  • Bump the OWASP CRS to 4.30.0.
  • Molecule: the apache_httpd scenario runs behind the CRS and asserts a 403 for an attack, logged by the configured CRS release, on all platforms except Ubuntu 22.04. COMPATIBILITY.md marks apache_httpd as verified on all 8 platforms.

Test

Fresh clones of Rocky 8/9/10, Debian 12/13 and Ubuntu 22.04/24.04/26.04: prepare, converge, second converge with 0 changes, verify, all green. The transition from the old PID file was reproduced on Ubuntu 26.04 (restart instead of reload, idempotent afterwards). Cross-checked against DebOps roles/apache, which keeps Debian's apache2.conf and therefore the same PidFile.

… Debian and Ubuntu

The rendered apache2.conf set no PidFile, so Apache used the compiled-in
/run/apache2.pid, while apachectl reads APACHE_PID_FILE from
/etc/apache2/envvars (/run/apache2/apache2.pid). On a fresh host the
package-started server wrote the latter, `apachectl graceful` did not
find it, tried to start a second server and failed on the bound ports.
Reproduced on Ubuntu 26.04 with main. Hosts still running with the old
PID file are restarted once instead of reloaded. Debian's own
apache2.conf (and DebOps, which keeps it) sets the same PidFile.
- create modsecurity.d, which only the RHEL package ships
- assert ModSecurity >= 2.9.6 (CRS 4 uses MULTIPART_PART_HEADERS;
  Ubuntu 22.04 ships 2.9.5, verified)
- download the CRS on the controller instead of the target
- reload Apache when the CRS symlink or crs-setup.conf change
- extract with fixed modes, otherwise `chmod -R g-w` made every run
  re-extract the archive
- molecule: run the scenario behind the CRS and assert a 403 from the
  configured release on all platforms except Ubuntu 22.04
@markuslf
markuslf merged commit d5e2078 into main Oct 5, 2026
13 checks passed
@markuslf
markuslf deleted the fix/apache-httpd-crs-debian-ubuntu branch October 5, 2026 14:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant