一。配置StorageSrv
第一步:安装服务
yum install mariadb-server # 不要装mariadb
第二步:启动服务
systemctl start mariadb
systemctl start nfs
systemctl start slapd
第三步:设置密码
_________________________________________________________________
第四步:配置数据库
mysql -u root -p
create database wordpress;
GRANT ALL PRIVILEGES ON *.* TO 'root'@'%' IDENTIFIED BY 'Chinaskill21!' WITH GRANT OPTION;
flush privileges;
第五步:重启服务
systemctl restart mariadb
二。配置AppSrv
第一步:安装所需服务
yum install httpd mod_ssl mod_ldap php php-fpm php-mysql php-mbstring mariadb-server
第二步:创建用户
useradd -r webuser
vim /etc/http/conf/httpd.conf
User webuser
Group webuser
第三步:限制物理内存
systemctl enable httpd
vim /etc/systemd/system/multi-user.target.wants/httpd.service
[Service]
MemoryLimit=500M
systemctl daemon-reload
systemctl restart httpd
第四步:限制IPMAX连接数
vim /etc/httpd/conf/httpd.conf
MaxConnperip 50
第五步:WordPress
上传文件到 /webdata/wwwroot/wordpress
cp -a wp-config.-sample.php wp-config.php
touch /webdata/download/test.mp3
touch /webdata/download/test.pdf
dd if=/dev/zero of=test.mp4 bs=100M count=1
chmod 777 /webdata/wwwroot/wordpress
第六步:修改配置
vim /etc/httpd/conf/httpd.conf
ServerSignature Off //不显示系统和WEB服务器版本信息
ServerTokens Prod //不显示系统和WEB服务器版本信息
redirect permanent / https://www.chinaskills.cn/
DocumentRoot "/webdata/wordpress"
ServerName www.chinaskills.cn
SSLEngine on
SSLCertificateFile /csk-rootca/httpd.crt
SSLCertificateKeyFile /csk-rootca/httpd.key
Require all granted
DocumentRoot "/webdata"
ServerName download.chinaskills.cn
SSLEngine on
SSLCertificateFile /csk-rootca/httpd.crt
SSLCertificateKeyFile /csk-rootca/httpd.key
Order deny,allow
Deny from All
AuthName "LADP AUTHENTICATION"
AuthType Basic
AuthBasicProvider ldap
AuthLDAPURL ldap://192.168.100.200/ou=users,dc=chinaskills,dc=cn?uid
Require ldap-user wuusr lsusr zsuser
Satisfy any
download网站需要以下操作
vim /etc/httpd/conf.d/welcome.conf
<LocationMatch "^/*$">
options +Indexes
注意:/etc/httpd/conf/httpd.conf
第七步:赋予wordpress 权限
chmod 777 wordpress/
第八步:重启服务
systemctl restart httpd
扩展
apachectl -t 检查语法
select user,host from mysql.user; 查看数据库所有用户的权限
drop user 'username'@'address';