<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Apache on Sysadmin Tales</title>
    <link>https://blog.ssb-tech.net/tags/apache/</link>
    <description>Recent content in Apache on Sysadmin Tales</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:39:10 -0400</lastBuildDate>
    <atom:link href="https://blog.ssb-tech.net/tags/apache/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Configuring Apache for OIDC with an Authentik backend</title>
      <link>https://blog.ssb-tech.net/posts/apache-oidc-authentik/</link>
      <pubDate>Wed, 26 Feb 2025 20:06:16 -0500</pubDate>
      <guid>https://blog.ssb-tech.net/posts/apache-oidc-authentik/</guid>
      <description>&lt;h2 id=&#34;summary&#34;&gt;Summary&lt;/h2&gt;&#xA;&lt;p&gt;For the past year and half I&amp;rsquo;ve been running my own mailserver using &lt;a href=&#34;https://www.postfix.org/&#34;&gt;Postfix&lt;/a&gt; and &lt;a href=&#34;https://www.dovecot.org/&#34;&gt;Dovecot&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;This setup works quite well, and I&amp;rsquo;ve also installed &lt;a href=&#34;https://roundcube.net/&#34;&gt;Roundcube&lt;/a&gt; to have a convenient web frontend. It&amp;rsquo;s nice to have, though most of the time I interact with the mailserver via apps like Thunderbird or FairEmail.&lt;/p&gt;&#xA;&lt;p&gt;While Roundcube is quite nice, I don&amp;rsquo;t necessarily trust the authentication mechanism to be exposed directly to the internet.&lt;/p&gt;&#xA;&lt;p&gt;Since I set this up, I put Apache basic authentication in front of it as a deterrent. However, the issue with basic auth is that it requires you to log in again &lt;em&gt;every single time&lt;/em&gt; you restart your browser.&lt;/p&gt;&#xA;&lt;p&gt;So, I decided on a more robust solution. I&amp;rsquo;ve already been running Authentik for some of the other services in my lab that support OIDC, so I decided to tie back into that system, which will give me nice single sign on features.&lt;/p&gt;&#xA;&lt;h2 id=&#34;configuring-apache&#34;&gt;Configuring Apache&lt;/h2&gt;&#xA;&lt;p&gt;Here&amp;rsquo;s how you can set this up for yourself.&lt;/p&gt;&#xA;&lt;p&gt;First, install the Apache module that adds OIDC support:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo apt install mod_auth_openidc&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Enable the module:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo a2enmod auth_openidc&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Here&amp;rsquo;s an example Apache virtual host with working OIDC support:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;&amp;lt;VirtualHost *:443&amp;gt;&#xA;ServerAdmin webmaster@localhost&#xA;ServerName mail.example.net&#xA;&#xA;OIDCProviderMetadataURL &amp;#34;https://auth.example.net/application/o/roundcube-webmail/.well-known/openid-configuration&amp;#34;&#xA;OIDCClientID redacted&#xA;OIDCClientSecret redacted&#xA;OIDCRedirectURI &amp;#34;https://mail.example.net/roundcube&amp;#34;&#xA;OIDCCacheType file&#xA;OIDCCacheDir /var/cache/mod_auth_openidc&#xA;OIDCCryptoPassphrase redacted&#xA;&#xA;&amp;lt;Location /roundcube&amp;gt;&#xA;AuthType openid-connect&#xA;Require valid-user&#xA;&amp;lt;/Location&amp;gt;&#xA;&#xA;&amp;lt;Location /&amp;gt;&#xA;AuthType openid-connect&#xA;Require valid-user&#xA;&amp;lt;/Location&amp;gt;&#xA;&#xA;# Handle the case if someone hits the root location and redirect them to /roundcube &#xA;RewriteEngine On&#xA;RewriteCond %{REQUEST_URI} ^/$&#xA;RewriteCond %{HTTP_REFERER} !auth.example.net [NC]&#xA;RewriteRule ^/$ /roundcube/ [R=302,L]&#xA;&#xA;ErrorLog ${APACHE_LOG_DIR}/error.log&#xA;CustomLog ${APACHE_LOG_DIR}/access.log combined&#xA;&#xA;SSLEngine on&#xA;SSLCertificateFile      /etc/letsencrypt/live/mail.example.net/cert.pem&#xA;SSLCertificateKeyFile /etc/letsencrypt/live/mail.example.net/privkey.pem&#xA;SSLCertificateChainFile /etc/letsencrypt/live/mail.example.net/fullchain.pem&#xA;&amp;lt;/VirtualHost&amp;gt;&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Once you have this set up, restart apache:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo systemctl restart apache2&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;On systems other than Ubuntu the service may be called httpd rather than apache2.&lt;/p&gt;&#xA;&lt;h2 id=&#34;oidc-configuration-options&#34;&gt;OIDC configuration options&lt;/h2&gt;&#xA;&lt;p&gt;&lt;code&gt;OIDCClientId&lt;/code&gt;, &lt;code&gt;OIDCProviderMetadataURL&lt;/code&gt; and &lt;code&gt;OIDCClientSecret&lt;/code&gt; can both be found in your Authentik provider configuration.&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt;OIDCCryptoPassphrase&lt;/code&gt; is only used internally. You can generate any random string for this, I&amp;rsquo;d recommend at least 64 characters.&lt;/p&gt;&#xA;&lt;p&gt;Don&amp;rsquo;t forget that you also need to set the redirect URI in the provider settings!&lt;/p&gt;&#xA;</description>
    </item>
  </channel>
</rss>
