Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - emar

Pages: [1] 2 3 ... 5
1
@overseer yes have Comodo WAF enabled

I don't know what's causing this but it's knocking off Apache and a proxy server set up for audio streaming.
Every time the proxy failes or restarts, none of the https stream url's work, then Apache stops and knocks the websites off.

2
Hi,

I've cleaned up the server logs, fixed a few errors, so only one or two errors remain,

Having issues with Apache,
Upgraded web server from Apache Only to Nginx, Vanish Apache
And randomly finding Apache offline so something is not right.

If I switch back to Apache Only, I can't restart Apache at all.
When set to Nginx, Vanish, Apache, Apache goes offline randomly, but I'm able to restart it.

So, I looked in usr/local/apache/logs

Quote
ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "5.55.154.55"] [uri "/.env"] [unique_id "ZQbGaAHhrTaYwGUNEoolBwAAAIE"]

Quote
[Sun Sep 17 09:35:53.078555 2023] [:notice] [pid 5153:tid 139887043213184] ModSecurity: StatusEngine call failed. Query: GIXDSLRRFRAXAYLDNBSS6MROGQXDKNZA.FBKW42LYFEQE64DFNYWDCLRWFYZC6MJO.GYXDELBYFYZTELZYFYZTEIBSGAYTELJR.GEWTGMBMFBXHK3DMFEWDELRZFYYSYY3E.GYYGIM3FMUZDMNRTMMYGKNRTMM4TAYLD.ME4DQMZTMQ3TENLDMJRTCYJYGYYGM.1694939744.status.modsecurity.org


Any advice appreciated

3
Are these the correct commands for configtest?

[root@svr1 /]# /usr/local/apache/bin/apachectl configtest
Syntax OK

[root@svr1 /]# /usr/local/apache/bin/apachectl -t
Syntax OK
You have new mail

[root@svr1 /]# /usr/local/apache/bin/httpd -t
Syntax OK

Could this be the cause, because I just found apache offline again,

[Mon Sep 11 03:13:40.289534 2023] [:notice] [pid 7260:tid 139969124296576] ModSecurity: StatusEngine call failed. Query: GIXDSLRRFRAXAYLDNBSS6MROGQXDKNZA.FBKW42LYFEQE64DFNYWDCLRWFYZC6MJO.GYXDELBYFYZTELZYFYZTEIBSGAYTELJR.GEWTGMBMFBXHK3DMFEWDELRZFYYSYY3E.GYYGIM3FMUZDMNRTMMYGKNRTMM4TAYLD.ME4DQMZTMQ3TENLDMJRTCYJYGYYGM.1694398412.status.modsecurity.org

[Mon Sep 11 03:13:40.489500 2023] [ssl:warn] [pid 7321:tid 139969124296576] AH01873: Init: Session Cache is not configured [hint: SSLSessionCache]

I don't see much else in the apache error_log
I guess I cleaned up a lot of crap and not many errors any more.

But syil lhave apache failing and my other proxy for the streaming server.

4
Quote
Apache Server Status (live load)
● httpd.service - Web server Apache
   Loaded: loaded (/usr/lib/systemd/system/httpd.service; enabled; vendor preset: disabled)
   Active: active (running) since Sun 2023-09-10 03:44:51 IST; 20h ago
 Main PID: 31743 (httpd)
   CGroup: /system.slice/httpd.service
           ├─ 1815 /usr/local/apache/bin/httpd -k start
           ├─31743 /usr/local/apache/bin/httpd -k start
           ├─31745 /usr/local/apache/bin/httpd -k start
           ├─31746 /usr/local/apache/bin/httpd -k start
           ├─31796 /usr/local/apache/bin/httpd -k start
           └─32215 /usr/local/apache/bin/httpd -k start

Sep 10 03:44:42 svr1.me.it systemd[1]: Starting Web server Apache...
Sep 10 03:44:51 svr1.me.it systemd[1]: Started Web server Apache. [quote

Quote
[root@svr1 /]# systemctl status
● svr1.me.it
    State: degraded
     Jobs: 0 queued
   Failed: 1 units
    Since: Fri 2023-09-01 00:31:48 IST; 1 weeks 2 days ago
   CGroup: /
           ├─1 /usr/lib/systemd/systemd --switched-root --system --deserialize 22
           ├─user.slice
           │ └─user-0.slice
           │   ├─session-c184201.scope
           │   │ ├─ 6181 /usr/local/centovacast/shoutcast2/sc_serv ../carl_weed/etc/server.conf
           │   │ ├─ 6187 /usr/local/centovacast/sctrans2/sc_trans ../carl_weed/etc/source.conf
           │   │ ├─23292 /usr/local/centovacast/shoutcast2/sc_serv ../csl_a221/etc/server.conf
           │   │ ├─23313 /usr/local/centovacast/sctrans2/sc_trans ../csl_a221/etc/source.conf
           │   │ ├─24072 cc-control [rpc]
           │   │ ├─24081 /usr/local/centovacast/sbin/cc-comet -d -u ccuser -g ccuser /usr/local/centovacast/etc/cc-comet.conf
           │   │ ├─24090 cc-ftpd (SERVER)
           │   │ ├─24106 imaged [master]
           │   │ ├─24108 imaged [worker]
           │   │ └─24109 imaged [worker]
           │   ├─session-c160966.scope
           │   │ ├─12928 /usr/local/centovacast/shoutcast2/sc_serv ../csl_002/etc/server.conf
           │   │ ├─13491 /usr/local/centovacast/shoutcast2/sc_serv ../csl_203/etc/server.conf
           │   │ ├─14178 /usr/local/centovacast/shoutcast2/sc_serv ../csl_204/etc/server.conf
           │   │ └─15010 /usr/local/centovacast/shoutcast2/sc_serv ../csl_209/etc/server.conf
           │   ├─session-c21478.scope
           │   │ ├─32744 /usr/local/centovacast/shoutcast2/sc_serv ../csl_a203/etc/server.conf
           │   │ └─32752 /usr/local/centovacast/sctrans2/sc_trans ../csl_a203/etc/source.conf
           │   ├─session-24900.scope
           │   │ └─12115 /usr/local/centovacast/shoutcast2/sc_serv ../csl_223/etc/server.conf
           │   └─session-1664.scope
           │     ├─ 9741 /usr/local/centovacast/shoutcast2/sc_serv ../csl_405/etc/server.conf
           │     └─22913 /usr/local/centovacast/shoutcast2/sc_serv ../csl_224/etc/server.conf
           └─system.slice
             ├─httpd.service
lines 1-35

5
Hi,

Trying to find what's causing Apache, and maybe other applications to stop.

I recently switched web server from Apache Only to Nginx, Vanish, Apache PHP-FPM.
The server was running PHP 7.4.latest then I installed and switched to PHP 8.1.

I've noticed several times Apache was stopped,
I can't see any related errors in / usr / local / apache / logs / error_log

I was having a few other issues with websites not loading, tried switching back to Apache Only,
But was unable to start Apache, I've since switched back to Nginx, Vanish, Apache PHP.FPM
The only one that I find stopped is Apache, I can restart Apache if  using Nginx, Vanish, Apache..
I can't start Apache, if Apache Only is selected.

Any tips appreciated

Thanks

6
SSL / Re: Session Cache is not configured [hint: SSLSessionCache]
« on: September 10, 2023, 06:39:03 AM »
Other than these messages, the server Apache error log looks pretty clean.

Quote
ModSecurity for Apache/2.9.1 (http://www.modsecurity.org/) configured.
[Sun Sep 10 03:44:42.896658 2023] [:notice] [pid 31661:tid 140076391253888] ModSecurity: APR compiled version="1.6.2"; loaded version="1.6.2"
[Sun Sep 10 03:44:42.896662 2023] [:notice] [pid 31661:tid 140076391253888] ModSecurity: PCRE compiled version="8.32 "; loaded version="8.32 2012-11-30"
[Sun Sep 10 03:44:42.896664 2023] [:notice] [pid 31661:tid 140076391253888] ModSecurity: LIBXML compiled version="2.9.1"
[Sun Sep 10 03:44:42.896698 2023] [:notice] [pid 31661:tid 140076391253888] ModSecurity: StatusEngine call: "2.9.1,Apache/2.4.57 (Unix) Open,1.6.2/1.6.2,8.32/8.32 2012-11-30,(null),2.9.1,cd60d3ee2663c00aca8833d725cbc1a860f"
[Sun Sep 10 03:44:51.005973 2023] [:notice] [pid 31661:tid 140076391253888] ModSecurity: StatusEngine call failed. Query: GIXDSLRRFRAXAYXDKNZA.FBKW42LYFEQE64DFNYWDCLRWFYZC6MJO.GYXDELBYFYZTELZYFYZTEIBSGAYTELJR.GEWTGMBMFBXHK3DMFRZFYYSYY3E.GYYGIM3FMUZDKNRTMM4TAYLD.ME4DQMZTMQ3TENLDM.1694313882.status.modsecurity.org
[Sun Sep 10 03:44:51.204162 2023] [ssl:warn] [pid 31743:tid 140076391253888] AH01873: Init: Session Cache is not configured [hint: SSLSessionCache]

7
SSL / Re: Session Cache is not configured [hint: SSLSessionCache]
« on: September 09, 2023, 11:56:15 PM »
Ok done, error log is now cleared, I'll check it again in a while.

BTW I was in / etc / httpd / logs / ssl_error_log
But all I can find is: /etc / httpd_bak / logs, there's no / etc / httpd/

Is that another issue and should I create httpd directory and delete that httpd_bak ?

8
SSL / Re: Session Cache is not configured [hint: SSLSessionCache]
« on: September 08, 2023, 09:57:03 PM »
@overseer

The second module is already active

#   Inter-Process Session Cache:
#   Configure the SSL Session Cache: First the mechanism
#   to use and second the expiring timeout (in seconds).
#SSLSessionCache         "dbm:/usr/local/apache/logs/ssl_scache"
SSLSessionCache        "shmcb:/usr/local/apache/logs/ssl_scache(512000)"
SSLSessionCacheTimeout  300

9
SSL / Session Cache is not configured [hint: SSLSessionCache]
« on: September 08, 2023, 04:21:24 AM »
Hi,

Any advice on fixing this issue appreciated.

[Fri Sep 08 04:06:59.386698 2023] [ssl:warn] [pid 14456:tid 140467374864256] AH01873: Init: Session Cache is not configured [hint: SSLSessionCache]

I tried a fix from another topic by enabling:

LoadModule socache_memcache_module modules/mod_socache_memcache.so

In: / usr / local / apache / conf / httpd.conf

10
Apache / Re: Apache won't start after upgrading to php 8+ (httpd failed)
« on: September 07, 2023, 03:33:46 AM »
So if my domain's username is mix1 [under User Accounts > List Accounts]

for user in $(ls /home); do chown $user:nobody /home/mix1/public_html ; done

Would reset the public_html directory's Group to "nobody"

11
Apache / Re: Apache won't start after upgrading to php 8+ (httpd failed)
« on: September 07, 2023, 12:11:53 AM »
Is that command to set every domain's Owner & Group to their correct user?

Because I made the mistake of using this command and it set every domain's Owner & Group to the same user.
Which I discovered was wrong, because each domain under /home/ has it's own user.

for i in $(ls /home); do chown $i:$i /home/$i; done

12
Apache / Re: Apache won't start after upgrading to php 8+ (httpd failed)
« on: September 06, 2023, 08:23:45 AM »
I asked our data-center if there was a command to fix directories owner & group for each domain under /home/

For example

cd /home/domain-user
chown -R domain:domain public_html/

I have mentioned to CWP several times that the fix permissions option sets all directories owner & group to nobody.

I'm sure it's not suppose to do that so why does it?

Anyway, thank god the sites are back.

13
Apache / Re: Apache won't start after upgrading to php 8+ (httpd failed)
« on: September 05, 2023, 08:30:14 PM »
I did go for one time support, they switched it to nginx, apache, vanish, php-fpm
But Apache won't start if I switch web servers back to Apache Only, not that I want to switch it back.
The sites were running fine on Apache Only and PHP 7.4, now they won't run with that version or any.

I have a few WordPress sites that were kicking up that they needed PHP 8.0 or 8.1 so I upgraded.
PHP 8.0 is no good because they skipped past PHP 8.0 with the new Ioncube.

I'd be happy to pay CWPto check it out, it's probably not a serious bug, I can't fix it quick enough.
Every time I upgrade php, or change web servers this happens.

I've only a couple of websites on the server and audio streaming application, with proxy to get secure https urls.
The streaming server is running fine independently, but I can't use the domain names for the https stream url's.
I have a few broadcasters using one of the streams, we do regular shows from my website, well we did until this.

My sites are down since last week, since I switched to ngnix, apache, vanish, php-fpm, Access Denied on websites.

That ioncube is a pain too, it's not compatible with newer PHP versions,
Then I saw they did a release for PHP 8.1 and installed PHP 8.1, no luck with the sites.

I'll try fix that SSL issues, as far as I know, it says I'm missing an A record
But I don't think the domains are missing any A records, not 100% sure.

I'm getting to oconfused, I have logs that are like 500mb, had to clear them just to open them.

I love CWP, it's just a bit stressful when things go wrong, i'll be up for the night again.

14
Apache / Re: Apache won't start after upgrading to php 8+ (httpd failed)
« on: September 05, 2023, 04:09:13 PM »
I think we'll have to migrate to a new server manager.
I'm 100% sure this is not something I have caused.

15
Apache / Re: Apache won't start after upgrading to php 8+ (httpd failed)
« on: September 04, 2023, 05:13:05 AM »
Hi,

I ran /usr/local/apache/bin/apachectl configtest

Syntax OK

From: /usr/ local/apache/logs/error_log

[Mon Sep 04 05:20:45.445656 2023] [mpm_event:notice] [pid 23752:tid 140413806012288] AH00493: SIGUSR1 received.  Doing graceful restart
Failed loading /usr/local/ioncube/ioncube_loader_lin_8.1.so:  /usr/local/ioncube/ioncube_loader_lin_8.1.so: undefined symbol: file_globals
Failed loading /usr/local/ioncube/ioncube_loader_lin_8.1.so:  /usr/local/ioncube/ioncube_loader_lin_8.1.so: undefined symbol: file_globals
Failed loading /usr/local/ioncube/ioncube_loader_lin_8.1.so:  /usr/local/ioncube/ioncube_loader_lin_8.1.so: undefined symbol: file_globals
Failed loading /usr/local/ioncube/ioncube_loader_lin_8.1.so:  /usr/local/ioncube/ioncube_loader_lin_8.1.so: undefined symbol: file_globals
Failed loading /usr/local/ioncube/ioncube_loader_lin_8.1.so:  /usr/local/ioncube/ioncube_loader_lin_8.1.so: undefined symbol: file_globals
[Mon Sep 04 05:20:45.654488 2023] [ssl:warn] [pid 23752:tid 140413806012288] AH01873: Init: Session Cache is not configured [hint: SSLSessionCache]

[Mon Sep 04 05:20:45.665045 2023] [ssl:warn] [pid 23752:tid 140413806012288] AH01909: cpanel.site.biz:443:0 server certificate does NOT include an ID which matches the server name
[Mon Sep 04 05:20:45.665451 2023] [ssl:warn] [pid 23752:tid 140413806012288] AH01909: mail.site.biz:443:0 server certificate does NOT include an ID which matches the server name

From: /var/ log/httpd/error_log

[Thu Aug 31 20:49:05.761282 2023] [ssl:emerg] [pid 25913] AH02311: Fatal error initialising mod_ssl, exiting. See /etc/httpd/logs/ssl_error_log for more information
[Thu Aug 31 20:49:09.660173 2023] [suexec:notice] [pid 26142] AH01232: suEXEC mechanism enabled (wrapper: /usr/sbin/suexec)
[Thu Aug 31 20:49:09.660434 2023] [core:emerg] [pid 26142] (28)No space left on device: AH00023: Couldn't create the ssl-cache mutex
AH00016: Configuration Failed

--

So, I'm looking for /etc/httpd/logs/ssl_error_log
But all I can find is: etc/httpd_bak/logs, there's no /etc/httpd/

Is that another issue?

From: /etc/httpd_bak/logs/ssl_error_log

[Thu Aug 31 20:33:33.700527 2023] [ssl:emerg] [pid 20549] SSL Library Error: error:0B080074:x509 certificate routines:X509_check_private_key:key values mismatch
[Thu Aug 31 20:49:05.761231 2023] [ssl:warn] [pid 25913] AH01906: RSA server certificate is a CA certificate (BasicConstraints: CA == TRUE !?)
[Thu Aug 31 20:49:05.761243 2023] [ssl:warn] [pid 25913] AH01909: RSA certificate configured for svr1.site.it:443 does NOT include an ID which matches the server name
[Thu Aug 31 20:49:05.761254 2023] [ssl:emerg] [pid 25913] AH02238: Unable to configure RSA server private key
[Thu Aug 31 20:49:05.761273 2023] [ssl:emerg] [pid 25913] SSL Library Error: error:0B080074:x509 certificate routines:X509_check_private_key:key values mismatch


Have Web Server set to Nging, Apache, Vanish, PHP-FPM.
They all seem to be running fine from looking at the dashboard.

Have the server updated to latest version.
PHP version: 8.1.22 Forced PHP-FPM: 8.1

All websites are down.

Error 503 Backend fetch failed
Backend fetch failed

Guru Meditation:
XID: 196794

Varnish cache server

Also, I tried Fix Permissions under User Accounts,
Now all websites Owner & group are set to "nobody"
Do I need to fix those back to the right owners.

Pages: [1] 2 3 ... 5