Forbidden 403 error when accessing Nagios Web Interface

Support forum for Nagios Core, Nagios Plugins, NCPA, NRPE, NSCA, NDOUtils and more. Engage with the community of users including those using the open source solutions.
CSSI
Posts: 20
Joined: Fri Jun 07, 2013 3:15 pm

Forbidden 403 error when accessing Nagios Web Interface

Post by CSSI »

I wanted to open it up for external access but only have it accessible via https

I followed these steps to perform this
http://blog.stefandanielschwarz.de/2010 ... agios.html

It was right after doing this when I started being unable to access the nagios control panel, even locally.
I receive the error 403 Forbidden. You don't have permission to access /nagios/ on this server. When accessing localhost using port 80 it reports that it works and that it is the default web page for the server.

My httpd.conf file for Apache2 is empty
Here are the contents of my apache2.conf file

Code: Select all

# Based upon the NCSA server configuration files originally by Rob McCool.
    #
    # This is the main Apache server configuration file.  It contains the
    # configuration directives that give the server its instructions.
    # See http://httpd.apache.org/docs/2.2/ for detailed information about
    # the directives.
    #
    # Do NOT simply read the instructions in here without understanding
    # what they do.  They're here only as hints or reminders.  If you are unsure
    # consult the online docs. You have been warned.  
    #
    # The configuration directives are grouped into three basic sections:
    #  1. Directives that control the operation of the Apache server process as a
    #     whole (the 'global environment').
    #  2. Directives that define the parameters of the 'main' or 'default' server,
    #     which responds to requests that aren't handled by a virtual host.
    #     These directives also provide default values for the settings
    #     of all virtual hosts.
    #  3. Settings for virtual hosts, which allow Web requests to be sent to
    #     different IP addresses or hostnames and have them handled by the
    #     same Apache server process.
    #
    # Configuration and logfile names: If the filenames you specify for many
    # of the server's control files begin with "/" (or "drive:/" for Win32), the
    # server will use that explicit path.  If the filenames do *not* begin
    # with "/", the value of ServerRoot is prepended -- so "foo.log"
    # with ServerRoot set to "/etc/apache2" will be interpreted by the
    # server as "/etc/apache2/foo.log".
    #
    
    ### Section 1: Global Environment
    #
    # The directives in this section affect the overall operation of Apache,
    # such as the number of concurrent requests it can handle or where it
    # can find its configuration files.
    #
    
    #
    # ServerRoot: The top of the directory tree under which the server's
    # configuration, error, and log files are kept.
    #
    # NOTE!  If you intend to place this on an NFS (or otherwise network)
    # mounted filesystem then please read the LockFile documentation (available
    # at <URL:http://httpd.apache.org/docs/2.2/mod/mpm_common.html#lockfile>);
    # you will save yourself a lot of trouble.
    #
    # Do NOT add a slash at the end of the directory path.
    #
    #ServerRoot "/etc/apache2"
    
    #
    # The accept serialization lock file MUST BE STORED ON A LOCAL DISK.
    #
    LockFile ${APACHE_LOCK_DIR}/accept.lock
    
    #
    # PidFile: The file in which the server should record its process
    # identification number when it starts.
    # This needs to be set in /etc/apache2/envvars
    #
    PidFile ${APACHE_PID_FILE}
    
    #
    # Timeout: The number of seconds before receives and sends time out.
    #
    Timeout 300
    
    #
    # KeepAlive: Whether or not to allow persistent connections (more than
    # one request per connection). Set to "Off" to deactivate.
    #
    KeepAlive On
    
    #
    # MaxKeepAliveRequests: The maximum number of requests to allow
    # during a persistent connection. Set to 0 to allow an unlimited amount.
    # We recommend you leave this number high, for maximum performance.
    #
    MaxKeepAliveRequests 100
    
    #
    # KeepAliveTimeout: Number of seconds to wait for the next request from the
    # same client on the same connection.
    #
    KeepAliveTimeout 5
    
    ##
    ## Server-Pool Size Regulation (MPM specific)
    ## 
    
    # prefork MPM
    # StartServers: number of server processes to start
    # MinSpareServers: minimum number of server processes which are kept spare
    # MaxSpareServers: maximum number of server processes which are kept spare
    # MaxClients: maximum number of server processes allowed to start
    # MaxRequestsPerChild: maximum number of requests a server process serves
    <IfModule mpm_prefork_module>
        StartServers          5
        MinSpareServers       5
        MaxSpareServers      10
        MaxClients          150
        MaxRequestsPerChild   0
    </IfModule>
    
    # worker MPM
    # StartServers: initial number of server processes to start
    # MinSpareThreads: minimum number of worker threads which are kept spare
    # MaxSpareThreads: maximum number of worker threads which are kept spare
    # ThreadLimit: ThreadsPerChild can be changed to this maximum value during a
    #              graceful restart. ThreadLimit can only be changed by stopping
    #              and starting Apache.
    # ThreadsPerChild: constant number of worker threads in each server process
    # MaxClients: maximum number of simultaneous client connections
    # MaxRequestsPerChild: maximum number of requests a server process serves
    <IfModule mpm_worker_module>
        StartServers          2
        MinSpareThreads      25
        MaxSpareThreads      75 
        ThreadLimit          64
        ThreadsPerChild      25
        MaxClients          150
        MaxRequestsPerChild   0
    </IfModule>
    
    # event MPM
    # StartServers: initial number of server processes to start
    # MinSpareThreads: minimum number of worker threads which are kept spare
    # MaxSpareThreads: maximum number of worker threads which are kept spare
    # ThreadsPerChild: constant number of worker threads in each server process
    # MaxClients: maximum number of simultaneous client connections
    # MaxRequestsPerChild: maximum number of requests a server process serves
    <IfModule mpm_event_module>
        StartServers          2
        MinSpareThreads      25
        MaxSpareThreads      75 
        ThreadLimit          64
        ThreadsPerChild      25
        MaxClients          150
        MaxRequestsPerChild   0
    </IfModule>
    
    # These need to be set in /etc/apache2/envvars
    User ${APACHE_RUN_USER}
    Group ${APACHE_RUN_GROUP}
    
    #
    # AccessFileName: The name of the file to look for in each directory
    # for additional configuration directives.  See also the AllowOverride
    # directive.
    #
    
    AccessFileName .htaccess
    
    #
    # The following lines prevent .htaccess and .htpasswd files from being 
    # viewed by Web clients. 
    #
    <Files ~ "^\.ht">
        Order allow,deny
        Deny from all
        Satisfy all
    </Files>
    
    #
    # DefaultType is the default MIME type the server will use for a document
    # if it cannot otherwise determine one, such as from filename extensions.
    # If your server contains mostly text or HTML documents, "text/plain" is
    # a good value.  If most of your content is binary, such as applications
    # or images, you may want to use "application/octet-stream" instead to
    # keep browsers from trying to display binary files as though they are
    # text.
    #
    # It is also possible to omit any default MIME type and let the
    # client's browser guess an appropriate action instead. Typically the
    # browser will decide based on the file's extension then. In cases
    # where no good assumption can be made, letting the default MIME type
    # unset is suggested  instead of forcing the browser to accept
    # incorrect  metadata.
    #
    DefaultType None
    
    
    #
    # HostnameLookups: Log the names of clients or just their IP addresses
    # e.g., www.apache.org (on) or 204.62.129.132 (off).
    # The default is off because it'd be overall better for the net if people
    # had to knowingly turn this feature on, since enabling it means that
    # each client request will result in AT LEAST one lookup request to the
    # nameserver.
    #
    HostnameLookups Off
    
    # ErrorLog: The location of the error log file.
    # If you do not specify an ErrorLog directive within a <VirtualHost>
    # container, error messages relating to that virtual host will be
    # logged here.  If you *do* define an error logfile for a <VirtualHost>
    # container, that host's errors will be logged there and not here.
    #
    ErrorLog ${APACHE_LOG_DIR}/error.log
    
    #
    # LogLevel: Control the number of messages logged to the error_log.
    # Possible values include: debug, info, notice, warn, error, crit,
    # alert, emerg.
    #
    LogLevel warn
    
    # Include module configuration:
    Include mods-enabled/*.load
    Include mods-enabled/*.conf
    
    # Include all the user configurations:
    Include httpd.conf
    
    # Include ports listing
    Include ports.conf
    
    #
    # The following directives define some format nicknames for use with
    # a CustomLog directive (see below).
    # If you are behind a reverse proxy, you might want to change %h into %{X-Forwarded-For}i
    #
    LogFormat "%v:%p %h %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" vhost_combined
    LogFormat "%h %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" combined
    LogFormat "%h %l %u %t \"%r\" %>s %O" common
    LogFormat "%{Referer}i -> %U" referer
    LogFormat "%{User-agent}i" agent
    
    # Include of directories ignores editors' and dpkg's backup files,
    # see README.Debian for details.
    
    # Include generic snippets of statements
    Include conf.d/
    
    # Include the virtual host configurations:
    Include sites-enabled/
Any ideas? Thanks in advance!
abrist
Red Shirt
Posts: 8334
Joined: Thu Nov 15, 2012 1:20 pm

Re: Forbidden 403 error when accessing Nagios Web Interface

Post by abrist »

Could you post your vhost file(s) for nagios?
Former Nagios employee
"It is turtles. All. The. Way. Down. . . .and maybe an elephant or two."
VI VI VI - The editor of the Beast!
Come to the Dark Side.
CSSI
Posts: 20
Joined: Fri Jun 07, 2013 3:15 pm

Re: Forbidden 403 error when accessing Nagios Web Interface

Post by CSSI »

I'm sorry, but do you know where that might be?
abrist
Red Shirt
Posts: 8334
Joined: Thu Nov 15, 2012 1:20 pm

Re: Forbidden 403 error when accessing Nagios Web Interface

Post by abrist »

Lets find out where it is:

Code: Select all

find / -name nagios.conf
Former Nagios employee
"It is turtles. All. The. Way. Down. . . .and maybe an elephant or two."
VI VI VI - The editor of the Beast!
Come to the Dark Side.
CSSI
Posts: 20
Joined: Fri Jun 07, 2013 3:15 pm

Re: Forbidden 403 error when accessing Nagios Web Interface

Post by CSSI »

nagios.conf contains

Code: Select all

# SAMPLE CONFIG SNIPPETS FOR APACHE WEB SERVER
# Last Modified: 11-26-2005
#
# This file contains examples of entries that need
# to be incorporated into your Apache web server
# configuration file.  Customize the paths, etc. as
# needed to fit your system.

ScriptAlias /nagios/cgi-bin "/usr/local/nagios/sbin"

<Directory "/usr/local/nagios/sbin">
   SSLRequireSSL
   Options ExecCGI
   AllowOverride None
   Order allow,deny
   Allow from all
#  Order deny,allow
#  Deny from all
#  Allow from 127.0.0.1
   AuthName "Nagios Access"
   AuthType Basic
   AuthUserFile /usr/local/nagios/etc/htpasswd.users
   Require valid-user
</Directory>

Alias /nagios "/usr/local/nagios/share"

<Directory "/usr/local/nagios/share">
   SSLRequireSSL
   Options None
   AllowOverride None
   Order allow,deny
   Allow from all
#  Order deny,allow
#  Deny from all
#  Allow from 127.0.0.1
   AuthName "Nagios Access"
   AuthType Basic
   AuthUserFile /usr/local/nagios/etc/htpasswd.users
   Require valid-user
</Directory>
However there is also a nagios.conf~SSLRequireSSL file with the contents

Code: Select all

# SAMPLE CONFIG SNIPPETS FOR APACHE WEB SERVER
# Last Modified: 11-26-2005
#
# This file contains examples of entries that need
# to be incorporated into your Apache web server
# configuration file.  Customize the paths, etc. as
# needed to fit your system.

ScriptAlias /nagios/cgi-bin "/usr/local/nagios/sbin"

<Directory "/usr/local/nagios/sbin">
#  SSLRequireSSL
   Options ExecCGI
   AllowOverride None
   Order allow,deny
   Allow from all
#  Order deny,allow
#  Deny from all
#  Allow from 127.0.0.1
   AuthName "Nagios Access"
   AuthType Basic
   AuthUserFile /usr/local/nagios/etc/htpasswd.users
   Require valid-user
</Directory>

Alias /nagios "/usr/local/nagios/share"

<Directory "/usr/local/nagios/share">
#  SSLRequireSSL
   Options None
   AllowOverride None
   Order allow,deny
   Allow from all
#  Order deny,allow
#  Deny from all
#  Allow from 127.0.0.1
   AuthName "Nagios Access"
   AuthType Basic
   AuthUserFile /usr/local/nagios/etc/htpasswd.users
   Require valid-user
</Directory>
abrist
Red Shirt
Posts: 8334
Joined: Thu Nov 15, 2012 1:20 pm

Re: Forbidden 403 error when accessing Nagios Web Interface

Post by abrist »

This is definitely confusing as neither of these files has your cert declared nor do you have a virtualhost created for port 443. what distro are you running?
Former Nagios employee
"It is turtles. All. The. Way. Down. . . .and maybe an elephant or two."
VI VI VI - The editor of the Beast!
Come to the Dark Side.
CSSI
Posts: 20
Joined: Fri Jun 07, 2013 3:15 pm

Re: Forbidden 403 error when accessing Nagios Web Interface

Post by CSSI »

Ubuntu
abrist
Red Shirt
Posts: 8334
Joined: Thu Nov 15, 2012 1:20 pm

Re: Forbidden 403 error when accessing Nagios Web Interface

Post by abrist »

What errors do you have in your httpd logs (your logs may in a few different locations depending on the ubuntu version):

Code: Select all

tail -25 /var/log/apache2/error.log
tail -25 /var/log/apache2/access.log
OR:

Code: Select all

tail -25 /var/log/httpd/error_log
tail -25 /var/log/httpd/access_log
Former Nagios employee
"It is turtles. All. The. Way. Down. . . .and maybe an elephant or two."
VI VI VI - The editor of the Beast!
Come to the Dark Side.
CSSI
Posts: 20
Joined: Fri Jun 07, 2013 3:15 pm

Re: Forbidden 403 error when accessing Nagios Web Interface

Post by CSSI »

After entering tail -25 /var/log/apache2/error.log

Code: Select all

tail -25 /var/log/apache2/error.log
[Wed Jun 26 11:35:10 2013] [warn] The ScriptAlias directive in /etc/apache2/conf.d/nagios.conf.old at line 9 will probably never match because it overlaps an earlier ScriptAlias.
[Wed Jun 26 11:35:10 2013] [warn] The Alias directive in /etc/apache2/conf.d/nagios.conf.old at line 26 will probably never match because it overlaps an earlier Alias.
[Wed Jun 26 11:35:10 2013] [error] (EAI 5)No address associated with hostname: Could not resolve host name *:443 -- ignoring!
apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.1.1 for ServerName
[Wed Jun 26 11:35:10 2013] [warn] RSA server certificate CommonName (CN) `nagios.cssi.us' does NOT match server name!?
[Wed Jun 26 11:35:10 2013] [notice] Apache/2.2.22 (Ubuntu) PHP/5.3.10-1ubuntu3.5 with Suhosin-Patch mod_ssl/2.2.22 OpenSSL/1.0.1 configured -- resuming normal operations
[Wed Jun 26 11:35:13 2013] [error] [client 127.0.0.1] access to /usr/local/nagios/share/ failed, reason: SSL connection required
[Wed Jun 26 11:35:14 2013] [error] [client 127.0.0.1] access to /usr/local/nagios/share/ failed, reason: SSL connection required
[Wed Jun 26 11:36:54 2013] [notice] Graceful restart requested, doing restart
[Wed Jun 26 11:36:54 2013] [error] (9)Bad file descriptor: apr_socket_accept: (client socket)
[Wed Jun 26 11:36:54 2013] [error] (EAI 5)No address associated with hostname: Could not resolve host name *:443 -- ignoring!
apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.1.1 for ServerName
[Wed Jun 26 11:36:54 2013] [warn] RSA server certificate CommonName (CN) `nagios.cssi.us' does NOT match server name!?
[Wed Jun 26 11:36:54 2013] [notice] Apache/2.2.22 (Ubuntu) PHP/5.3.10-1ubuntu3.5 with Suhosin-Patch mod_ssl/2.2.22 OpenSSL/1.0.1 configured -- resuming normal operations
[Wed Jun 26 11:37:25 2013] [error] [client 127.0.0.1] access to /usr/local/nagios/share/ failed, reason: SSL connection required
[Wed Jun 26 11:37:26 2013] [error] [client 127.0.0.1] access to /usr/local/nagios/share/ failed, reason: SSL connection required
[Wed Jun 26 11:49:26 2013] [error] [client 127.0.0.1] access to /usr/local/nagios/share/ failed, reason: SSL connection required
[Wed Jun 26 13:14:45 2013] [error] [client 127.0.0.1] File does not exist: /etc/apache2/htdocs
[Wed Jun 26 13:14:50 2013] [error] [client 127.0.0.1] access to /usr/local/nagios/share/ failed, reason: SSL connection required
[Wed Jun 26 13:18:50 2013] [error] [client 127.0.0.1] access to /usr/local/nagios/share/ failed, reason: SSL connection required
[Thu Jun 27 07:58:22 2013] [notice] Graceful restart requested, doing restart
[Thu Jun 27 07:58:22 2013] [error] (EAI 5)No address associated with hostname: Could not resolve host name *:443 -- ignoring!
apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.1.1 for ServerName
[Thu Jun 27 07:58:22 2013] [warn] RSA server certificate CommonName (CN) `nagios.cssi.us' does NOT match server name!?
[Thu Jun 27 07:58:22 2013] [notice] Apache/2.2.22 (Ubuntu) PHP/5.3.10-1ubuntu3.5 with Suhosin-Patch mod_ssl/2.2.22 OpenSSL/1.0.1 configured -- resuming normal operations

After entering tail -25 /var/log/apache2/access.log

Code: Select all

tail -25 /var/log/apache2/access.log127.0.0.1 - - [27/Jun/2013:07:21:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:07:26:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:07:31:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:07:36:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:07:41:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:07:46:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:07:51:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:07:56:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:08:01:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:08:06:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:08:11:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:08:16:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:08:21:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:08:26:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:08:31:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:08:36:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:08:41:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:08:46:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:08:51:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:08:56:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:09:01:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:09:06:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:09:11:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:09:16:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
127.0.0.1 - - [27/Jun/2013:09:21:12 -0400] "GET / HTTP/1.0" 200 454 "-" "check_http/v1861 (nagios-plugins 1.4.11)"
abrist
Red Shirt
Posts: 8334
Joined: Thu Nov 15, 2012 1:20 pm

Re: Forbidden 403 error when accessing Nagios Web Interface

Post by abrist »

You may want to revert your configs to no ssl, and start again with a different guide. You have a number of vhost-related errors now:

Script Alias errors:

Code: Select all

[Wed Jun 26 11:35:10 2013] [warn] The ScriptAlias directive in /etc/apache2/conf.d/nagios.conf.old at line 9 will probably never match because it overlaps an earlier ScriptAlias.
[Wed Jun 26 11:35:10 2013] [warn] The Alias directive in /etc/apache2/conf.d/nagios.conf.old at line 26 will probably never match because it overlaps an earlier Alias.
Hostname/dns issues and apache directive problems:

Code: Select all

[Wed Jun 26 11:35:10 2013] [error] (EAI 5)No address associated with hostname: Could not resolve host name *:443 -- ignoring!
apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.1.1 for ServerName
[Wed Jun 26 11:35:10 2013] [warn] RSA server certificate CommonName (CN) `nagios.cssi.us' does NOT match server name!?
SSL errors:

Code: Select all

[Wed Jun 26 13:14:50 2013] [error] [client 127.0.0.1] access to /usr/local/nagios/share/ failed, reason: SSL connection required
[Wed Jun 26 13:18:50 2013] [error] [client 127.0.0.1] access to /usr/local/nagios/share/ failed, reason: SSL connection required
Former Nagios employee
"It is turtles. All. The. Way. Down. . . .and maybe an elephant or two."
VI VI VI - The editor of the Beast!
Come to the Dark Side.
Locked