Repository navigation
apache_httpd: OWASP CRS 4.30.0 and CRS/reload fixes on Debian and Ubuntu - #424
Merged
Merged
Conversation
… Debian and Ubuntu The rendered apache2.conf set no PidFile, so Apache used the compiled-in /run/apache2.pid, while apachectl reads APACHE_PID_FILE from /etc/apache2/envvars (/run/apache2/apache2.pid). On a fresh host the package-started server wrote the latter, `apachectl graceful` did not find it, tried to start a second server and failed on the bound ports. Reproduced on Ubuntu 26.04 with main. Hosts still running with the old PID file are restarted once instead of reloaded. Debian's own apache2.conf (and DebOps, which keeps it) sets the same PidFile.
- create modsecurity.d, which only the RHEL package ships - assert ModSecurity >= 2.9.6 (CRS 4 uses MULTIPART_PART_HEADERS; Ubuntu 22.04 ships 2.9.5, verified) - download the CRS on the controller instead of the target - reload Apache when the CRS symlink or crs-setup.conf change - extract with fixed modes, otherwise `chmod -R g-w` made every run re-extract the archive - molecule: run the scenario behind the CRS and assert a 403 from the configured release on all platforms except Ubuntu 22.04
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
apache2.confset noPidFile, so the first run against a fresh host failed reloading Apache (apachectl gracefullooked for the PID where the package-started server had not written it). The role now setsPidFile ${APACHE_PID_FILE}as Debian's ownapache2.confdoes; hosts still running with the old/run/apache2.pidare restarted once instead of reloaded.modsecurity.d, downloads the CRS on the controller, reloads Apache when the deployed release changes, extracts idempotently, and aborts with a clear message on Ubuntu 22.04, whose ModSecurity 2.9.5 cannot load CRS 4.apache_httpdscenario runs behind the CRS and asserts a 403 for an attack, logged by the configured CRS release, on all platforms except Ubuntu 22.04. COMPATIBILITY.md marksapache_httpdas verified on all 8 platforms.Test
Fresh clones of Rocky 8/9/10, Debian 12/13 and Ubuntu 22.04/24.04/26.04: prepare, converge, second converge with 0 changes, verify, all green. The transition from the old PID file was reproduced on Ubuntu 26.04 (restart instead of reload, idempotent afterwards). Cross-checked against DebOps
roles/apache, which keeps Debian'sapache2.confand therefore the samePidFile.