#!/bin/bash ############################################################################## # Web server installer on CentOS 7 # ############################################################################## # This program is distributed under the "GPLv3" License # # TODO: add dialog for minimal GUI # ############################################################################## header() { echo "Web server installer version 1.0" echo "Installer for web server with Apache and Tomcat" echo "GPLv3" echo } showhelp() { header echo 'Usage: ./web_server_installer [OPTIONS]' echo echo 'OPTIONS:' echo '-h | --help: Show this help screen. Install java before apache.' echo '-j | --java : Java url to be downloaded. Base url is ' \ 'https://download.oracle.com/otn-pub/java/jdk/ -- append the ' \ 'remaining part of the url.' echo '-t | --tomcat : Add the apache ' \ 'tomcat version (e.g. "9.0.31") and add the java version as well ' \ '(e.g. 11.0.6).' echo '-a | --apache : install apache with the config for ' \ 'the host provided' echo '-c | --certificate : install letsencrypt for apache ' \ 'the host provided' } java_setup() { # Extract java version version=`echo "$1" | cut -d'_' -f 1 | rev | cut -d"/" -f 1 | rev` # Download Java from the Oracle repository # stanrdard url works as https://download.oracle.com/otn-pub/java/jdk/ # in java11 is https://download.oracle.com/otn-pub/java/jdk/11.0.6+8/90eb79fb590d45c8971362673c5ab495/jdk-11.0.6_linux-x64_bin.rpm # for java 13 wget --no-cookies --no-check-certificate --header "Cookie: oraclelicense=accept-securebackup-cookie" https://download.oracle.com/otn-pub/java/jdk/13.0.2+8/d4173c853231432d94f001e99d882ca7/jdk-13.0.2_linux-x64_bin.rpm wget --no-cookies --no-check-certificate --header "Cookie: oraclelicense=accept-securebackup-cookie" $1 # Install java sudo rpm -Uvh /tmp/${version}_linux-x64_bin.rpm # File cleanup sudo rm /tmp/${version}_linux-x64_bin.rpm } tomcat_setup() { # Check if java has already been installed if type -p java; then echo found java executable in PATH _java=java elif [[ -n "$JAVA_HOME" ]] && [[ -x "$JAVA_HOME/bin/java" ]]; then echo found java executable in JAVA_HOME _java="$JAVA_HOME/bin/java" else echo "Java must be installed for tomcat to be installed and setup" exit fi # Variable for the latest Tomcat version. Change this varible for # newer versions tommy="apache-tomcat-"$1 ver=`echo "$1" | cut -d'.' -f 1` # version=`echo "$tommy" | rev | cut -d'-' -f 1 | rev` ext=".tar.gz" url="http://mirror.nohup.it/apache/tomcat/tomcat-"$ver"/v"$1"/bin/" # Add the Tomcat user and group to which our application will attach to # note that the -s is done to avoid the chance of logging in as tomcat sudo useradd -m -U -d /opt/tomcat -s /bin/false tomcat # Download the latest Tomcat Version wget $url$tommy$ext # Unzip the tar file into the /tmp folder tar -xf $tommy$ext # Move the folder into its folder sudo mv $tommy /opt/tomcat/ # Create a soft link for the tomcat folder as latest sudo ln -s /opt/tomcat/$tommy /opt/tomcat/latest # Set the owner of the tomcat folder to the tomcat user sudo chown -R tomcat: /opt/tomcat # We need to make the shell script executable to make sure we can invoke them # into a service for startup and shutdown of the tomcat platform sudo sh -c 'chmod +x /opt/tomcat/latest/bin/*.sh' # Create the service file. We configure it so that by enabling it we will # be able to make our tomcat starting up on boot by enabling the service echo ' [Unit] Description=Tomcat 9 servlet container After=network.target [Service] Type=forking User=tomcat Group=tomcat Environment="JAVA_HOME=/usr/java/jdk-'$2'" Environment="JAVA_OPTS=-Djava.security.egd=file:///dev/urandom" Environment="CATALINA_BASE=/opt/tomcat/latest" Environment="CATALINA_HOME=/opt/tomcat/latest" Environment="CATALINA_PID=/opt/tomcat/latest/temp/tomcat.pid" Environment="CATALINA_OPTS=-Xms512M -Xmx1024M -server -XX:+UseParallelGC" ExecStart=/opt/tomcat/latest/bin/startup.sh ExecStop=/opt/tomcat/latest/bin/shutdown.sh [Install] WantedBy=multi-user.target' > /etc/systemd/system/tomcat.service # Reload the daemon since we created a new service sudo systemctl daemon-reload # Enable the Tomcat service and start it sudo systemctl enable tomcat sudo systemctl start tomcat # File cleanup sudo rm /tmp/$tommy$ext # Exclusion for firewall sudo firewall-cmd --permanent --add-port=8090/tcp # Restart the firewall sudo systemctl restart firewalld # Note that this files need to be configured # /opt/tomcat/latest/conf/server.xml to add ajp and port 8090 for http # for the ajp the connector need to be decommendted and add # secretRequired="false" # for the 8090 port you just need to find the simple connector # with port 8080 and change it # # /opt/tomcat/latest/conf/tomcat-users.xml to add roles and users # add for example: # # # # # # # # # /opt/tomcat/latest/webapps/manager/META-INF/context.xml to add manager # outside localhost # add the ips, |192.168.1.\d+ (it may vary with your network) } apache_setup() { # We do not want www if [ `echo "$1" | cut -d'.' -f 1` == 'www' ] then echo "Do not add www to the host pls" exit fi # Install httpd and add the exclusion to the firewall sudo yum install httpd -y # Add the http and https for the certification part and the 8443 for tomcat sudo firewall-cmd --permanent --add-service=http sudo firewall-cmd --permanent --add-service=https sudo firewall-cmd --permanent --add-port=8443/tcp # Restart the firewall sudo systemctl restart firewalld # Enable and start the service sudo systemctl enable httpd sudo systemctl start httpd # We'll get the first element of the domain as user, therefore, if we have # example.com our base user will be example. user=`echo "$1" | cut -d'.' -f 1` i=1 # The first if shoul be enough, but never be too sure while [ $user == "www" ] do # If the user passed www we want to exclude it user=`echo "$1" | cut -d'.' -f "$i" | rev | cut -d'.' | rev` i=$i+1 done # Add the Tomcat user and group to which our application will attach to # note that the -s is done to avoid the chance of logging in as tomcat sudo useradd -m -U -d /var/www/$1/ -s /bin/false $user # Create the base folder for the base url sudo mkdir -p /var/www/html/$1/ sudo mkdir -p /var/www/$1/log # Change owner of the folder sudo chown -R $user:$user /var/www/html/$1 # Change mod sudo chmod -R 755 /var/www/ # Create the sites-available and sites-enabled folder for apache sudo mkdir /etc/httpd/sites-available /etc/httpd/sites-enabled # We also add the configuration for tomcat (we will need to make it # available from the server tomcat file as well) echo ' Listen '$2' IncludeOptional sites-enabled/*.conf LoadModule proxy_module modules/mod_proxy.so LoadModule proxy_ajp_module modules/mod_proxy_ajp.so' >> /etc/httpd/conf/httpd.conf echo ' ServerName www.'$1' ServerAlias '$1' DocumentRoot /var/www/html/'$1'/ ErrorLog /var/www/'$1'/log/error.log CustomLog /var/www/'$1'/log/requests.log combined ProxyRequests Off ProxyPreserveHost On Order deny,allow Allow from all ProxyPass / ajp://localhost:8009/ ' > /etc/httpd/sites-available/$1.conf # Create the softlink sudo ln -s /etc/httpd/sites-available/$1.conf /etc/httpd/sites-enabled/$1.conf # Adjust the SELinux policy for Apache globally sudo setsebool -P httpd_unified 1 # Restart the service sudo systemctl restart httpd # Check the list of contents of thhe log folder to see whether or not # Apache created the files ls -lZ /var/www/$1/log } certification_setup() { # We do not want www if [ `echo "$1" | cut -d'.' -f 1` == 'www' ] then echo "Do not add www to the host pls" exit fi # Install the epel release sudo yum install epel-release -y # Install certbot sudo yum install certbot python2-certbot-apache mod_ssl -y # Obtain the certificate: if you want the alias decomment it sudo certbot --apache -d $1 # -d www.$1 # The next part is interactive and require the user to choose: it is better # to redirect to https # Renewal crontab -l | { cat; echo "0 0,12 * * * python -c 'import random; import time; time.sleep(random.random() * 3600)' && certbot renew"; } | crontab - # Change default listening port sudo sed -i 's/443/'$2'/g' /etc/httpd/sites-available/$1-le-ssl.conf # Restart the service sudo systemctl restart httpd # Add permanent zone to firewall firewall-cmd --zone=public --add-masquerade --permanent # Forward of the 8443 port to 443 port since letsencrypt works only on # that firewall-cmd --zone=public \ --add-forward-port=port=8443:proto=tcp:toport=443 --permanent # Restart the firewall systemctl restart firewalld } # We need super user privileges to execute the script user_id=$(id -u) if [ "$user_id" != "0" ]; then echo "You need super user priviliges for this." exit fi # Download and execute the commands inside the tmp folder cd /tmp while [ "$1" ]; do case $1 in '-h' | '--help' | '?' ) showhelp exit ;; '--java' | '-j' ) java_setup "$2" exit ;; '--tomcat' | '-t' ) tomcat_setup "$2" "$3" exit ;; '--apache' | '-a' ) apache_setup "$2" "$3" exit ;; '--certificate' | '-c' ) certification_setup "$2" "$3" exit ;; esac shift done