host.html revision ffeb75f44c82228ec2b18b47722f428b91b191e5
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<!-- Background white, links blue (unvisited), navy (visited), red (active) -->
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster BGCOLOR="#FFFFFF"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster TEXT="#000000"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster LINK="#0000FF"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster VLINK="#000080"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ALINK="#FF0000"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<!--#include virtual="header.html" -->
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<H1 ALIGN="CENTER">Apache non-IP Virtual Hosts</H1>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<A HREF="virtual-host.html">Virtual Host Support</A>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<P>The "Virtual Host" refers to the practice of maintaining more than
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterone server on one machine, as differentiated by their apparent
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterhostname. For example, it is often desirable for companies sharing a
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterweb server to have their own domains, with web servers accessible as
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<CODE>www.company1.com</CODE> and <CODE>www.company2.com</CODE>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterwithout requiring the user to know any extra path information.</P>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<P>Apache was one of the first servers to support virtual hosts right
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterout of the box, but since the base <CODE>HTTP</CODE> (HyperText
8af80418ba1ec431c8027fa9668e5678658d3611Allan FosterTransport Protocol) standard does not allow any method for the server
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterto determine the hostname it is being addressed as, Apache's virtual
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterhost support has required a separate IP address for each
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterserver. Documentation on using this approach (which still works very
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterwell) <A HREF="virtual-host.html">is available</A>.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<P>While the approach described above works, with the available IP
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosteraddress space growing smaller, and the number of domains increasing,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterit is not the most elegant solution, and is hard to implement on some
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fostermachines. The <CODE>HTTP/1.1</CODE> protocol contains a method for the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterserver to identify what name it is being addressed as. Apache 1.1 and
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterlater support this approach as well as the traditional
8af80418ba1ec431c8027fa9668e5678658d3611Allan FosterIP-address-per-hostname method.</P>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<P>The benefits of using the new virtual host support is a practically
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterunlimited number of servers, ease of configuration and use, and
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterrequires no additional hardware or software. The main disadvantage is
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterthat the user's browser must support this part of the protocol. The
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterlatest versions of many browsers (including Netscape Navigator 2.0 and
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterlater) do, but many browsers, especially older ones, do not. This can
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fostercause problems, although a possible solution is addressed below.</P>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<P>Using the new virtual hosts is quite easy, and superficially looks
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterlike the old method. You simply add to one of the Apache configuration
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterfiles (most likely <CODE>httpd.conf</CODE> or <CODE>srm.conf</CODE>)
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fostercode similar to the following:</P>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <VirtualHost www.apache.org>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </VirtualHost>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<P>Of course, any additional directives can (and should) be placed
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterinto the <CODE><VirtualHost></CODE> section. To make this work,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterall that is needed is to make sure that the <CODE>www.apache.org</CODE>
8af80418ba1ec431c8027fa9668e5678658d3611Allan FosterDNS entry points to the same IP address as the main
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterserver. Optionally, you could simply use that IP address in the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<VirtualHost> entry.</P>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<P>Additionally, many servers may wish to be accessible by more than
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterone name. For example, the Apache server might want to be accessible
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosteras <CODE>apache.org</CODE>, or <CODE>ftp.apache.org</CODE>, assuming
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterthe IP addresses pointed to the same server. In fact, one might want it
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterso that all addresses at <CODE>apache.org</CODE> were picked up by the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterserver. This is possible with the <CODE>ServerAlias</CODE>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterdirective, placed inside the <VirtualHost> section. For
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<P>Note that you can use <CODE>*</CODE> and <CODE>?</CODE> as wild-card
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fostercharacters.</P>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<P>You also might need ServerAlias if you are serving local users who
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterdo not always include the domain name. For example, if local users are
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterfamiliar with typing "www" or "www.physics" then you will need to add
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<CODE>ServerAlias www www.physics</CODE>. It isn't possible for the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterserver to know what domain the client uses for their name resolution
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterbecause the client doesn't provide that information in the request.</P>
8af80418ba1ec431c8027fa9668e5678658d3611Allan FosterApache allows all virtual hosts to be made accessible via the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<CODE>Host:</CODE> header through all IP interfaces, even those which
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterare configured to use different IP interfaces. For example, if the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterconfiguration for <CODE>www.foo.com</CODE> contained a virtual host
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fostersection for <CODE>www.bar.com</CODE>, and <CODE>www.bar.com</CODE> was
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fostera separate IP interface, such that
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosternon-<CODE>Host:</CODE>-header-supporting browsers can use it, as
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterbefore with Apache 1.0. If a request is made to
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<CODE>www.foo.com</CODE> and the request includes the header
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<CODE>Host: www.bar.com</CODE>, a page from <CODE>www.bar.com</CODE>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterwill be sent.
8af80418ba1ec431c8027fa9668e5678658d3611Allan FosterThis is a security concern if you are controlling access to a
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterparticular server based on IP-layer controls, such as from within a
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterfirewall or router. Let's say <CODE>www.bar.com</CODE> in the above
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterexample was instead an intra-net server called
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<CODE>private.foo.com</CODE>, and the router used by foo.com only let
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterinternal users access <CODE>private.foo.com</CODE>. Obviously,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<CODE>Host:</CODE> header functionality now allows someone who has
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<CODE>private.foo.com</CODE>, if they send a <CODE>Host:
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterprivate.foo.com</CODE> header. It is important to note that this
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fostercondition exists only if you only implement this policy at the IP
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterlayer - all security controls used by Apache (<EM>i.e.</EM>, <A
8af80418ba1ec431c8027fa9668e5678658d3611Allan FosterHREF="/mod/mod_access.html">Allow, Deny from,</A> <EM>etc.</EM>) are
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterconsistently respected.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<P>As mentioned earlier, a majority of browsers do not send the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterrequired data for the new virtual hosts to work properly. These
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterbrowsers will always be sent to the main server's pages. There is a
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterworkaround, albeit a slightly cumbersome one:</P>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<P>To continue the <CODE>www.apache.org</CODE> example (Note: Apache's
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosterweb server does not actually function in this manner), we might use the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fosternew <CODE>ServerPath</CODE> directive in the <CODE>www.apache.org</CODE>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Fostervirtual host, for example:
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ServerPath /apache
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<P>What does this mean? It means that a request for any file beginning
<!--#include virtual="footer.html" -->