[lool@scw-6b31f8 ~]$ sudo yum install httpd mod_ssl
[lool@scw-6b31f8 ~]$ sudo yum install --enablerepo=epel,webtatic mod_php72w php72w-mbstring php72w-common php72w-mysqlnd php72w-gd php72w-xml php72w-pdo
[lool@scw-6b31f8 ~]$ diff -urw /etc/httpd/conf/httpd.conf.orig /etc/httpd/conf/httpd.conf
--- /etc/httpd/conf/httpd.conf.orig 2018-04-11 05:27:26.000000000 +0900
+++ /etc/httpd/conf/httpd.conf 2018-05-28 17:49:27.559577372 +0900
@@ -94,6 +94,15 @@
#ServerName www.example.com:80
+ServerTokens Prod
+Header unset X-Powered-By
+Header append X-Frame-Options SAMEORIGIN
+Header set X-XSS-Protetion "1; mode=block"
+Header set X-Content-Type-Options nosniff
+RequestHeader unset Proxy
+TraceEnable Off
+ServerSignature Off
# Deny access to the entirety of your server's filesystem. You must
# explicitly permit access to web content directories in other
@@ -141,14 +150,16 @@
# http://httpd.apache.org/docs/2.4/mod/core.html#options
# for more information.
- Options Indexes FollowSymLinks
+ #Options Indexes FollowSymLinks
+ Options FollowSymLinks
# AllowOverride controls what directives may be placed in .htaccess files.
# It can be "All", "None", or any combination of the keywords:
# Options FileInfo AuthConfig Limit
- AllowOverride None
+ #AllowOverride None
+ AllowOverride All
# Controls who can get stuff from this server.
Nextcloud <->libre(Proxy)<->lool
Nextcloud内のLibreOfficeとの連携アプリ「Collabora Online」がhttps接続のみしか受け付けない仕様となっていたので、
<VirtualHost *:443>
Servername nextcloud.lancardcom.xyz
DirectoryIndex index.html index.php
DocumentRoot /var/www/nextcloud/
SSLEngine on
SSLProtocol all -SSLv2 -SSLv3
SSLCertificateFile /etc/letsencrypt/live/nextcloud.lancardcom.xyz/cert.pem
SSLCertificateKeyFile /etc/letsencrypt/live/nextcloud.lancardcom.xyz/privkey.pem
SSLCertificateChainFile /etc/letsencrypt/live/nextcloud.lancardcom.xyz/chain.pem
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains"
LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
CustomLog "|/usr/sbin/rotatelogs /var/log/httpd/nextcloud/ssl_access_log_%Y%m%d 86400 540" combined
ErrorLog /var/log/httpd/nextcloud/ssl_error_log
<Directory "/var/www/nextcloud/">
AllowOverride All
Options FollowSymLinks
<VirtualHost *:80>
Servername nextcloud.lancardcom.xyz
RewriteEngine on
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [R,L]
DirectoryIndex index.html index.php
DocumentRoot /var/www/nextcloud/
LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
CustomLog "|/usr/sbin/rotatelogs /var/log/httpd/nextcloud/access_log_%Y%m%d 86400 540" combined
ErrorLog /var/log/httpd/nextcloud/error_log
<Directory "/var/www/nextcloud/">
AllowOverride All
Options FollowSymLinks
<VirtualHost *:443>
Servername libre.lancardcom.xyz
DirectoryIndex index.html index.php
DocumentRoot /var/www/libre/
SSLEngine on
SSLProtocol all -SSLv2 -SSLv3
SSLCertificateFile /etc/letsencrypt/live/libre.lancardcom.xyz/cert.pem
SSLCertificateKeyFile /etc/letsencrypt/live/libre.lancardcom.xyz/privkey.pem
SSLCertificateChainFile /etc/letsencrypt/live/libre.lancardcom.xyz/chain.pem
SSLHonorCipherOrder on
# Encoded slashes need to be allowed
AllowEncodedSlashes NoDecode
# Container uses a unique non-signed certificate
SSLProxyEngine On
SSLProxyVerify None
SSLProxyCheckPeerCN Off
SSLProxyCheckPeerName Off
# keep the host
ProxyPreserveHost On
# static html, js, images, etc. served from loolwsd
# loleaflet is the client part of LibreOffice Online
ProxyPass /loleaflet https://lool.lancardcom.xyz:9980/loleaflet retry=0
ProxyPassReverse /loleaflet https://lool.lancardcom.xyz:9980/loleaflet
# WOPI discovery URL
ProxyPass /hosting/discovery https://lool.lancardcom.xyz:9980/hosting/discovery retry=0
ProxyPassReverse /hosting/discovery https://lool.lancardcom.xyz:9980/hosting/discovery
# Main websocket
ProxyPassMatch "lool/(.*)/ws$" wss://lool.lancardcom.xyz:9980/lool/$1/ws nocanon
# Admin Console websocket
ProxyPass /lool/adminws wss://lool.lancardcom.xyz:9980/lool/adminws
# Download as, Fullscreen prezentation and Image upload operations
ProxyPass /lool https://lool.lancardcom.xyz:9980/lool
ProxyPassReverse /lool https://lool.lancardcom.xyz:9980/lool
Loglevel debug
CustomLog "|/usr/sbin/rotatelogs /var/log/httpd/libre/ssl_access_log_%Y%m%d 86400 540" combined
ErrorLog /var/log/httpd/libre/ssl_error_log
#Header always set Content-Security-Policy "default-src 'none'"
<Directory "/var/www/libre/">
AllowOverride All
Options FollowSymLinks
<VirtualHost *:80>
Servername libre.lancardcom.xyz
RewriteEngine on
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [R,L]
DirectoryIndex index.html index.php
DocumentRoot /var/www/libre/
CustomLog "|/usr/sbin/rotatelogs /var/log/httpd/libre/access_log_%Y%m%d 86400 540" combined
<Directory "/var/www/libre/">
AllowOverride All
Options FollowSymLinks
このバーチャルホストはLet’s EncryptでSSL証明書を取るためのダミーだったりします。
<VirtualHost *:80>
Servername lool.lancardcom.xyz
RewriteEngine on
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [R,L]
DirectoryIndex index.html index.php
DocumentRoot /var/www/lool/
CustomLog "|/usr/sbin/rotatelogs /var/log/httpd/lool/access_log_%Y%m%d 86400 540" combined
ErrorLog /var/log/httpd/lool/error_log
<Directory "/var/www/lool/">
AllowOverride All
Options FollowSymLinks
--- loolwsd.xml.orig 2018-06-04 09:59:41.709736164 +0900
+++ loolwsd.xml 2018-06-07 10:49:16.111249275 +0900
@@ -3,7 +3,7 @@
<!-- Note: 'default' attributes are used to document a setting's default value as well as to use as fallback. -->
<!-- Note: When adding a new entry, a default must be set in WSD in case the entry is missing upon deployment. -->
- <allowed_languages desc="List of supported languages on this instance." default="de_DE en_GB en_US es_ES fr_FR it nl pt_BR pt_PT ru">de_DE en_GB en_US es_ES fr_FR it nl pt_BR pt_PT ru</allowed_languages>
+ <allowed_languages desc="List of supported languages on this instance." default="de_DE en_GB en_US es_ES fr_FR it nl pt_BR pt_PT ru">ja de_DE en_GB en_US es_ES fr_FR it nl pt_BR pt_PT ru</allowed_languages>
<tile_cache_path desc="Path to a directory where to keep the tile cache." type="path" relative="false" default="/usr/local/var/cache/loolwsd"></tile_cache_path>
<sys_template_path desc="Path to a template tree with shared libraries etc to be used as source for chroot jails for child processes." type="path" relative="true" default="systemplate"></sys_template_path>
@@ -39,7 +39,7 @@
<color type="bool">true</color>
<level type="string" desc="Can be 0-8, or none (turns off logging), fatal, critical, error, warning, notice, information, debug, trace" default="trace">trace</level>
<file enable="true">
- <property name="path" desc="Log file path.">/tmp/loolwsd.log</property>
+ <property name="path" desc="Log file path.">/opt/lool/loolwsd.log</property>
<property name="rotation" desc="Log file rotation strategy. See Poco FileChannel.">never</property>
<property name="archive" desc="Append either timestamp or number to the archived log filename.">timestamp</property>
<property name="compress" desc="Enable/disable log file compression.">true</property>
@@ -65,16 +65,19 @@
<net desc="Network settings">
<proto type="string" default="all" desc="Protocol to use IPv4, IPv6 or all for both">all</proto>
<post_allow desc="Allow/deny client IP address for POST(REST)." allow="true">
- <host desc="Regex pattern of ip address to allow.">192\.168\.[0-9]{1,3}\.[0-9]{1,3}</host>
+ <host desc="Regex pattern of ip address to allow.">localhost</host>
+ <host desc="Regex pattern of ip address to allow.">nextcloud.lancardcom.xyz</host>
+ <host desc="Regex pattern of ip address to allow.">libre.lancardcom.xyz</host>
+ <host desc="Regex pattern of ip address to allow.">lool.lancardcom.xyz</host>
<ssl desc="SSL settings">
<enable type="bool" default="true">true</enable>
<termination desc="Connection via proxy where loolwsd acts as working via https, but actually uses http." type="bool" default="true">false</termination>
- <cert_file_path desc="Path to the cert file" relative="false">/etc/loolwsd/cert.pem</cert_file_path>
- <key_file_path desc="Path to the key file" relative="false">/etc/loolwsd/key.pem</key_file_path>
- <ca_file_path desc="Path to the ca file" relative="false">/etc/loolwsd/ca-chain.cert.pem</ca_file_path>
+ <cert_file_path desc="Path to the cert file" relative="false">/etc/letsencrypt/live/lool.lancardcom.xyz/cert.pem</cert_file_path>
+ <key_file_path desc="Path to the key file" relative="false">/etc/letsencrypt/live/lool.lancardcom.xyz/privkey.pem</key_file_path>
+ <ca_file_path desc="Path to the ca file" relative="false">/etc/letsencrypt/live/lool.lancardcom.xyz/chain.pem</ca_file_path>
<cipher_list desc="List of OpenSSL ciphers to accept" default="ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH"></cipher_list>
<hpkp desc="Enable HTTP Public key pinning" enable="false" report_only="false">
<max_age desc="HPKP's max-age directive - time in seconds browser should remember the pins" enable="true">1000</max_age>
@@ -94,6 +97,9 @@
<filesystem allow="false" />
<wopi desc="Allow/deny wopi storage. Mutually exclusive with webdav." allow="true">
<host desc="Regex pattern of hostname to allow or deny." allow="true">localhost</host>
+ <host desc="Regex pattern of hostname to allow or deny." allow="true">nextcloud.lancardcom.xyz</host>
+ <host desc="Regex pattern of hostname to allow or deny." allow="true">libre.lancardcom.xyz</host>
+ <host desc="Regex pattern of hostname to allow or deny." allow="true">lool.lancardcom.xyz</host>
<host desc="Regex pattern of hostname to allow or deny." allow="true">10\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}</host>
<host desc="Regex pattern of hostname to allow or deny." allow="true">172\.1[6789]\.[0-9]{1,3}\.[0-9]{1,3}</host>
<host desc="Regex pattern of hostname to allow or deny." allow="true">172\.2[0-9]\.[0-9]{1,3}\.[0-9]{1,3}</host>
* ログ用のディレクトリを未作成、もしくはオーナー、パーミッションの設定間違い
* SSL証明書のディレクトリのパーミッション設定(700でroot以外読めなかった)
* ドキュメントルートのディレクトリを未作成
* 単純なconfファイルのタイポ
[root@scw-6b31f8 ~]# mysql -u root -p
Enter password:
elcome to the MariaDB monitor. Commands end with ; or \g.
Your MariaDB connection id is 9
Server version: 5.5.56-MariaDB MariaDB Server
Copyright (c) 2000, 2017, Oracle, MariaDB Corporation Ab and others.
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
MariaDB [(none)]> CREATE DATABASE データベース名;
Query OK, 1 row affected (0.00 sec)
MariaDB [(none)]> GRANT ALL PRIVILEGES ON データベース名.* TO ユーザ名@localhost IDENTIFIED BY 'パスワード' ;
Query OK, 0 rows affected (0.01 sec)
MariaDB [(none)]> FLUSH PRIVILEGES ;
Query OK, 0 rows affected (0.00 sec)
MariaDB [(none)]> QUIT
[lool@scw-6b31f8 Archives]$ wget https://download.nextcloud.com/server/releases/nextcloud-13.0.2.zip
[lool@scw-6b31f8 Archives]$ unzip nextcloud-13.0.2.zip
[lool@scw-6b31f8 Archives]$ sudo cp -rp nextcloud/* /var/www/nextcloud/
[lool@scw-6b31f8 Archives]$ sudo chown -R apache. /var/www/nextcloud
[lool@scw-6b31f8 Archives]$ sudo systemctl restart httpd
CentOS7にNextcloudインストール | server-memo.net
CentOS 7 : NextCloud インストール : Server World
最後に、NexcloudのWebUI上の「アプリ」から「Collabora Online」を有効にします。
すると、「設定」の左サイドメニューに「Collabora Online」の項目が表示されますので、そこで、loolwsdサーバを指定します。
やはり…Microsoft Office365やGoogleAppsなどの大手商用サービスと比較すると、ユーザビリティに一歩劣る感は否めませんでした。
– どうしてもデータをクラウド上に置けない。オンプレミスである必要がある。
– 内部での共有のみで、外部とのドキュメント等のやり取りをほぼ行わない。
– ライセンスにコストをかけたくない