<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://leo.leung.xyz/wiki/index.php?action=history&amp;feed=atom&amp;title=SuPHP</id>
	<title>SuPHP - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://leo.leung.xyz/wiki/index.php?action=history&amp;feed=atom&amp;title=SuPHP"/>
	<link rel="alternate" type="text/html" href="https://leo.leung.xyz/wiki/index.php?title=SuPHP&amp;action=history"/>
	<updated>2026-10-06T08:37:18Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://leo.leung.xyz/wiki/index.php?title=SuPHP&amp;diff=1567&amp;oldid=prev</id>
		<title>Leo: Created page with &quot;Here is a script that will set up suPHP, similar to what cPanel does with Easy Apache.  {{highlight|lang=terminal|code= yum -y install psmisc net-tools wget  yum -y install bz...&quot;</title>
		<link rel="alternate" type="text/html" href="https://leo.leung.xyz/wiki/index.php?title=SuPHP&amp;diff=1567&amp;oldid=prev"/>
		<updated>2016-01-13T18:38:09Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;Here is a script that will set up suPHP, similar to what cPanel does with Easy Apache.  {{highlight|lang=terminal|code= yum -y install psmisc net-tools wget  yum -y install bz...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Here is a script that will set up suPHP, similar to what cPanel does with Easy Apache.&lt;br /&gt;
&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
yum -y install psmisc net-tools wget&lt;br /&gt;
&lt;br /&gt;
yum -y install bzip2 wget cc gcc make openssl-devel perl&lt;br /&gt;
&lt;br /&gt;
wget http://leo.home.steamr.com/source/httpd-2.4.16.tar.gz&lt;br /&gt;
tar -xzf httpd-2.4.16.tar.gz&lt;br /&gt;
cd httpd*/srclib&lt;br /&gt;
wget http://leo.home.steamr.com/source/apr-1.5.2.tar.bz2&lt;br /&gt;
tar -xjf apr-1.5.2.tar.bz2&lt;br /&gt;
mv apr-1.5.2 apr&lt;br /&gt;
wget http://leo.home.steamr.com/source/apr-util-1.5.4.tar.bz2&lt;br /&gt;
tar -xjf apr-util-1.5.4.tar.bz2&lt;br /&gt;
mv apr-util-1.5.4 apr-util&lt;br /&gt;
&lt;br /&gt;
./configure \&lt;br /&gt;
 --enable-rewrite --enable-suexec --enable-ssl \&lt;br /&gt;
 --enable-deflate --enable-expires --enable-headers \&lt;br /&gt;
 --with-included-apr \&lt;br /&gt;
 --with-ssl=/usr \&lt;br /&gt;
 --with-pcre \&lt;br /&gt;
 --with-crypto --with-mpm=prefork  \&lt;br /&gt;
 --with-suexec-caller=nobody \&lt;br /&gt;
 --with-suexec-docroot=/ \&lt;br /&gt;
 --with-suexec-gidmin=100 \&lt;br /&gt;
 --with-suexec-logfile=/usr/local/apache/logs/suexec_log \&lt;br /&gt;
 --with-suexec-uidmin=100 \&lt;br /&gt;
 --with-suexec-userdir=public_html&lt;br /&gt;
&lt;br /&gt;
make -j 4&lt;br /&gt;
make install&lt;br /&gt;
ln -s /usr/local/apache2 /etc/httpd&lt;br /&gt;
cp build/rpm/httpd.init  /etc/init.d/httpd&lt;br /&gt;
chmod 755  /etc/init.d/httpd&lt;br /&gt;
&lt;br /&gt;
# change perl interpreter from &amp;#039;/replace/with/path/to/perl/interpreter&amp;#039; to &amp;#039;/usr/bin/perl&amp;#039;&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;HTTPD=/usr/local/apache2/bin/httpd&amp;quot; &amp;gt; /etc/sysconfig/httpd&lt;br /&gt;
echo &amp;quot;PIDFILE=/usr/local/apache2/logs/httpd.pid&amp;quot; &amp;gt;&amp;gt; /etc/sysconfig/httpd&lt;br /&gt;
# update the init script so that the pidfile: line is set to the path above.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
yum -y install gcc-c++&lt;br /&gt;
wget http://leo.home.steamr.com/source/pcre-8.37.tar.gz&lt;br /&gt;
tar -xzf pcre-8.37.tar.gz&lt;br /&gt;
cd pcre-8.37&lt;br /&gt;
./configure --prefix=/opt/pcre --enable-unicode-properties&lt;br /&gt;
make -j 4&lt;br /&gt;
make install&lt;br /&gt;
cd /opt/pcre&lt;br /&gt;
ln -s lib lib64&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
cd&lt;br /&gt;
wget http://leo.home.steamr.com/source/libmcrypt-2.5.8.tar.gz&lt;br /&gt;
tar -xzf libmcrypt-2.5.8.tar.gz&lt;br /&gt;
cd libmcrypt-2.5.8&lt;br /&gt;
./configure --prefix=/opt/libmcrypt&lt;br /&gt;
make -j 4&lt;br /&gt;
make install&lt;br /&gt;
cd /opt/libmcrypt&lt;br /&gt;
ln -s lib lib64&lt;br /&gt;
&lt;br /&gt;
cd&lt;br /&gt;
wget http://leo.home.steamr.com/source/mm-1.4.2.tar.gz&lt;br /&gt;
tar -xzf mm-1.4.2.tar.gz&lt;br /&gt;
cd mm-1.4.2&lt;br /&gt;
./configure --prefix=/opt/mm&lt;br /&gt;
make -j 4&lt;br /&gt;
make install&lt;br /&gt;
cd /opt/mm&lt;br /&gt;
ln -s lib lib64&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
yum -y install libtool&lt;br /&gt;
cd&lt;br /&gt;
wget http://leo.home.steamr.com/source/tidy.tar.gz&lt;br /&gt;
tar -xzf tidy.tar.gz&lt;br /&gt;
cd tidy/tidy&lt;br /&gt;
sh build/gnuauto/setup.sh&lt;br /&gt;
./configure --prefix=/opt/tidy&lt;br /&gt;
make -j 4&lt;br /&gt;
make install&lt;br /&gt;
cd /opt/tidy&lt;br /&gt;
ln -s lib lib64&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
cd&lt;br /&gt;
wget http://leo.home.steamr.com/source/libxslt.tar.gz&lt;br /&gt;
tar -xzf libxslt.tar.gz&lt;br /&gt;
cd libxslt-1.1.28&lt;br /&gt;
./configure --prefix=/opt/xslt&lt;br /&gt;
make -j 4&lt;br /&gt;
make install&lt;br /&gt;
cd /opt/xslt&lt;br /&gt;
ln -s lib lib64&lt;br /&gt;
yum install mariadb-devel mariadb-server&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
yum -y install libxml2-devel bzip2-devel libcurl-devel \&lt;br /&gt;
libjpeg-turbo-devel libpng-devel libXpm-devel  freetype-devel zlib-devel \&lt;br /&gt;
libicu-devel aspell-devel expat-devel&lt;br /&gt;
&lt;br /&gt;
cd ~/php*&lt;br /&gt;
./configure --with-config-file-path=/etc --disable-opcache --enable-bcmath --enable-calendar --enable-exif --enable-f&amp;gt;&lt;br /&gt;
&lt;br /&gt;
# Excluded&lt;br /&gt;
# --with-kerberos --with-imap=/opt/php_with_imap_client/ --with-imap-ssl=/usr&lt;br /&gt;
&lt;br /&gt;
make -j 4&lt;br /&gt;
make install&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
cd&lt;br /&gt;
wget http://leo.home.steamr.com/source/suphp-patches.tar.gz&lt;br /&gt;
tar -xzf suphp-patches.tar.gz&lt;br /&gt;
&lt;br /&gt;
wget http://leo.home.steamr.com/source/suphp-0.7.2.tar.gz&lt;br /&gt;
tar -xzf suphp-0.7.2.tar.gz&lt;br /&gt;
cd suphp-0.7.2&lt;br /&gt;
for i in `ls ../patch` ; do patch -Np1 -d . &amp;lt; ../patch/$i ; done&lt;br /&gt;
autoreconf -if&lt;br /&gt;
./configure --prefix=/opt/suphp --with-apxs=/usr/local/apache2/bin/apxs --with-logfile=/usr/local/apache2/logs/suphp_&amp;gt;&lt;br /&gt;
make -j 4&lt;br /&gt;
make install&lt;br /&gt;
&lt;br /&gt;
# Ensure that libphp is not loaded by apache.&lt;br /&gt;
&lt;br /&gt;
cat &amp;lt;&amp;lt;EOF  &amp;gt;&amp;gt; /etc/httpd/conf/httpd.conf&lt;br /&gt;
LoadModule suphp_module modules/mod_suphp.so&lt;br /&gt;
suPHP_Engine on&lt;br /&gt;
AddType application/x-httpd-php5 .php5 .php&lt;br /&gt;
&amp;lt;Directory /&amp;gt;&lt;br /&gt;
    suPHP_AddHandler application/x-httpd-php5&lt;br /&gt;
&amp;lt;/Directory&amp;gt;&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
mkdir /opt/suphp/etc&lt;br /&gt;
chmod 755 /opt/suphp/etc&lt;br /&gt;
# Configure suphp. Ensure that the apache user (in webserver_user) matches the user running apache.&lt;br /&gt;
&lt;br /&gt;
cat &amp;lt;&amp;lt;EOF &amp;gt; /opt/suphp/etc/suphp.conf&lt;br /&gt;
; This file is parse anew by suPHP for each request&lt;br /&gt;
; rather than being loaded once.&lt;br /&gt;
&lt;br /&gt;
[global]&lt;br /&gt;
;Path to logfile&lt;br /&gt;
logfile=/usr/local/apache2/logs/suphp_log&lt;br /&gt;
&lt;br /&gt;
;Loglevel&lt;br /&gt;
loglevel=info&lt;br /&gt;
&lt;br /&gt;
;User Apache is running as&lt;br /&gt;
; MANDATORY&lt;br /&gt;
webserver_user=nobody&lt;br /&gt;
&lt;br /&gt;
; Path all scripts have to be in&lt;br /&gt;
; This works as a prefix when a trailing slash is not specified.&lt;br /&gt;
; e.g. /home will match /home /home2 /home3 etc While /home/ will only match /home/&lt;br /&gt;
;&lt;br /&gt;
; Changing this to a more specific path will improve security&lt;br /&gt;
docroot=/&lt;br /&gt;
&lt;br /&gt;
;Path to chroot() to before executing script&lt;br /&gt;
;chroot=/home&lt;br /&gt;
&lt;br /&gt;
; Security options&lt;br /&gt;
allow_file_group_writeable=false&lt;br /&gt;
allow_file_others_writeable=false&lt;br /&gt;
allow_directory_group_writeable=false&lt;br /&gt;
allow_directory_others_writeable=false&lt;br /&gt;
&lt;br /&gt;
; Check whether script is within DOCUMENT_ROOT&lt;br /&gt;
; Does NOT perform this check on included scripts.&lt;br /&gt;
; i.e. include_once(&amp;quot;/test3.php&amp;quot;); works even though it&amp;#039;s in the root directory&lt;br /&gt;
;&lt;br /&gt;
; Changing this to true will improve security but make all php userdir requests fail&lt;br /&gt;
check_vhost_docroot=false&lt;br /&gt;
&lt;br /&gt;
; Allow the user and group specified by a ~userdir request to override the&lt;br /&gt;
; suPHP_UserGroup directive inside the source virtualhost&lt;br /&gt;
;&lt;br /&gt;
; Changing this to false will improve security but make some types of php userdir&lt;br /&gt;
; requests fail&lt;br /&gt;
userdir_overrides_usergroup=true&lt;br /&gt;
&lt;br /&gt;
; suPHP Paranoid mode checks that the target script UID and GID match&lt;br /&gt;
; the UID and GID of the user running the script.  To disable these&lt;br /&gt;
; checks change the following values to false.  Without these checks, mod_suphp&lt;br /&gt;
; is effectively running in &amp;quot;Force&amp;quot; mode.&lt;br /&gt;
paranoid_uid_check=true&lt;br /&gt;
paranoid_gid_check=true&lt;br /&gt;
&lt;br /&gt;
;Send minor error messages to browser&lt;br /&gt;
errors_to_browser=false&lt;br /&gt;
&lt;br /&gt;
;PATH environment variable&lt;br /&gt;
env_path=&amp;quot;/bin:/usr/bin&amp;quot;&lt;br /&gt;
&lt;br /&gt;
;Umask to set, specify in octal notation&lt;br /&gt;
umask=0022&lt;br /&gt;
&lt;br /&gt;
; Minimum UID&lt;br /&gt;
;min_uid=100&lt;br /&gt;
&lt;br /&gt;
; Minimum GID&lt;br /&gt;
;min_gid=100&lt;br /&gt;
&lt;br /&gt;
; Normally suPHP only displays the PHP binary in process lists (ps aux).&lt;br /&gt;
; Setting this option to &amp;#039;true&amp;#039; will cause suPHP to display both the&lt;br /&gt;
; PHP binary and the script filename.&lt;br /&gt;
full_php_process_display=true&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[handlers]&lt;br /&gt;
;Handler for php-scripts&lt;br /&gt;
application/x-httpd-php=&amp;quot;php:/usr/local/bin/php-cgi&amp;quot;&lt;br /&gt;
application/x-httpd-php5=&amp;quot;php:/usr/local/bin/php-cgi&amp;quot;&lt;br /&gt;
&lt;br /&gt;
;Handler for CGI-scripts&lt;br /&gt;
;x-suphp-cgi=&amp;quot;execute:!self&amp;quot;&lt;br /&gt;
&lt;br /&gt;
[phprc_paths]&lt;br /&gt;
;Uncommenting these will force all requests to that handler to use the php.ini&lt;br /&gt;
;in the specified directory regardless of suPHP_ConfigPath settings.&lt;br /&gt;
;application/x-httpd-php=/usr/local/lib/&lt;br /&gt;
;application/x-httpd-php5=/usr/local/lib/&lt;br /&gt;
&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;&amp;lt;?php phpinfo(); &amp;quot; &amp;gt; /usr/local/apache2/htdocs/phpinfo.php&lt;br /&gt;
chown nobody:nobody /usr/local/apache2/htdocs/phpinfo.php&lt;br /&gt;
chmod 644 /usr/local/apache2/htdocs/phpinfo.php&lt;br /&gt;
&lt;br /&gt;
# Files must be 644&lt;br /&gt;
# Dirs must be 711&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# Adding hosts for hidden services&lt;br /&gt;
# They go on individual ports like so:&lt;br /&gt;
&lt;br /&gt;
Listen 81&lt;br /&gt;
&amp;lt;VirtualHost *:81&amp;gt;&lt;br /&gt;
    ServerName webhost01.onion&lt;br /&gt;
    DocumentRoot /home/bob/public_html&lt;br /&gt;
    ServerAdmin support@webhost.onion&lt;br /&gt;
    &amp;lt;IfModule mod_suphp.c&amp;gt;&lt;br /&gt;
    ¦   suPHP_UserGroup bob bob&lt;br /&gt;
    &amp;lt;/IfModule&amp;gt;&lt;br /&gt;
&amp;lt;/VirtualHost&amp;gt;&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Leo</name></author>
	</entry>
</feed>