notes: all work should be done as user "root" or "sudo user"
legend: <ur> = user response <sr> = system response ================================================ <sr> [root@host] # my prompt
<ur> dnf install epel-release # optional command (you may already have this) <sr> ...verbage ensues... [root@host] # prompt
<ur> dnf makecache
<sr> ....verbage ensues.... [root@host] #
<ur> dnf install nginx
<sr> ...verbage ensues...
[root@host] #
------------------------------------------------
# task: modify the default config using "vi" or "nano"
# If testing in parallel with Apache: # set the port to 8080 # do not enable ssl on 443 for now # set hostname to be your system's URL (required for SSL) # set "error_log /var/log/nginx/error.log;" # set "access_log /var/log/nginx/access.log main buffer=8k flush=1m;"
------------------------------------------------ <ur> vi /etc/nginx/nginx.conf # modify the default config using "vi" or "nano" ...editor typing happens here... <sr> [root@host] #
<ur> nginx -t # test your config <sr> nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful [root@host]
<ur> systemctl start nginx # start the server (but do not enable it at this time) <sr> ...verbage ensues...
[root@host] #
------------------------------------------------
# now test your website by entering a URL similar to these:
# If testing in parallel with Apache: http://neilrieck.net:8080
# Otherwise:
http://neilrieck.net
https://neilrieck.net
<sr> [root@host] # my prompt
<ur> dnf install fcgiwrap # this will also install fcgi
<sr> ...verbage ensues....
[root@host] #
<ur> man fcgiwrap # check out online help
<sr> ...help text is displayed...
[root@host] #
------------------------------------------------
# task: locate the socket template filename (name contains: @ )
# I want to type this command:
# find / -name fcgi*.sock* -exec ls -lad {} \;
# but asterisks must be escaped with a forward slash
------------------------------------------------
<ur> find / -name fcgi\*.sock\* -exec ls -lad {} \;
<sr> -rw-r--r-- 1 root root 180 Jan 27 2022 /usr/lib/systemd/system/fcgiwrap@.socket
[root@host]
------------------------------------------------
# task: use the discovered filename to start the socket listener
# note: executing the next command will create this file entry:
# /run/fcgiwrap/fcgiwrap-nginx.sock
# which must be entered into the location directive of nginx.conf
# (see my example config at the bottom of this page)
------------------------------------------------
<ur> systemctl enable --now fcgiwrap@nginx.socket
<sr> ...verbage ensues...
[root@host] #
<ur> vi /etc/nginx/nginx.conf # modify the default config using "vi" or "nano"
...typing ensues... # create a location directive for CGI
------------------------------------------------
<ur> [root@host] nginx -t # test your config <sr> nginx: the configuration file /etc/nginx/nginx.conf syntax is ok nginx: configuration file /etc/nginx/nginx.conf test is successful [root@host] #
<ur> systemctl restart nginx # restart the web server
------------------------------------------------
now test your website by entering a URL similar to these:
https://neilrieck.net/cgi-bin/hello.cgi
#!/usr/bin/env bash
echo "Content-type: text/html"
echo ""
now="$(date)"
echo '<html><head><title>Hello World - CGI app</title></head>'
echo '<body>'
echo '<h2>Hello World!</h2>'
echo "Computer name : $HOSTNAME<br/>"
echo "The current date and time : ${now}<br/>"
echo '</body>'
echo '</html>'
<sr> [root@host]
<ur> dnf install nginx-mod-fancyindex
<sr> ...verbage ensues...
[root@host]
----------------------------------------------
see my example config at the bottom of this page
Caveat:
Creating/populating a password file:
htpasswd -c /etc/nginx/folder-name myusername1 # only use switch -c for the very first entry
htpasswd /etc/nginx/folder-name myusername2 # adding a second account
# if something goes wrong, use an editor to repair the file
sh -c "echo -n 'myusername1:' >> /etc/nginx/folder-name" # first half of adding an account (the user name)
sh -c "openssl passwd -apr1 >> /etc/nginx/folder-name" # second half of adding an account (the password)
# if something goes wrong, use an editor to repair the file
Now update the config file
server {
listen 80;
# listen [::]:80;
server_name neilrieck.net *.neilrieck.net;
# root /usr/share/nginx/html;
root /var/www/html; # my Apache files live here
# Load configuration files for the default server block.
include /etc/nginx/default.d/*.conf;
# redirect http to httpd
# note: 301 means permanently moved
return 301 https://$host$request_uri;
}
# ============================================================================
# For more information on configuration, see:
# * Official English Documentation: http://nginx.org/en/docs/
# * Official Russian Documentation: http://nginx.org/ru/docs/
# ============================================================================
# 1) 2026-09-14: changes to get CGI working with fastcgi / fcgi.
# 2) 2026-09-14: enabled autoindex
# 3) 2026-09-15: switched over to fancyindex (an optional package that might
# not be on your system). On AlmaLinux-9 you need to do this first:
# sudo dnf install nginx-mod-fancyindex.x86_64
# 4) 2026-09-16: enabled password protection on one folder
# 5) 2026-09-19: added an expires directive (two places)
# 6) 2026-09-20: concated my cert + intermediate certs into a bundle (all
# browsers work properly but python-based test scripts failed; oops!)
# 7) 2026-09-22: tweaks to fancyindex_css_href
# 8) 2026-09-24: now redirect all http requests to httpd (but I will leave all
# port 80 directives in place in case I change my mind)
# ============================================================================
user nginx;
worker_processes auto;
error_log /var/log/nginx/error.log;
pid /run/nginx.pid;
# Load dynamic modules. See /usr/share/doc/nginx/README.dynamic.
include /usr/share/nginx/modules/*.conf;
events {
worker_connections 1024;
}
http {
log_format main '$remote_addr - $remote_user [$time_local] "$request" '
'$status $body_bytes_sent "$http_referer" '
'"$http_user_agent" "$http_x_forwarded_for"';
# access_log /var/log/nginx/access.log main;
access_log /var/log/nginx/access.log main buffer=8k flush=1m;
sendfile on;
tcp_nopush on;
tcp_nodelay on;
keepalive_timeout 65;
types_hash_max_size 4096;
include /etc/nginx/mime.types;
default_type application/octet-stream;
# Load modular configuration files from the /etc/nginx/conf.d directory.
# See http://nginx.org/en/docs/ngx_core_module.html#include
# for more information.
include /etc/nginx/conf.d/*.conf;
server {
listen 80;
# listen [::]:80;
server_name neilrieck.net *.neilrieck.net;
# root /usr/share/nginx/html;
root /var/www/html; # my Apache files live here
# Load configuration files for the default server block.
include /etc/nginx/default.d/*.conf;
#error_page 404 /404.html;
#location = /404.html {
#}
#error_page 500 502 503 504 /50x.html;
#location = /50x.html {
#}
# redirect http to httpd
# note: 301 means permanently moved
return 301 https://$host$request_uri;
location ~ ^/mira/ {
auth_basic "Restricted Access";
# auth_basic_user_file /etc/nginx/.htpasswd;
auth_basic_user_file /etc/nginx/passwd-folder-mira;
# "autoindex" is built into nginx
# autoindex on;
# autoindex_exact_size off;
# ------------------------------------
# "fancyindex" is not built into nginx
fancyindex on;
fancyindex_default_sort name;
fancyindex_directories_first on;
fancyindex_case_sensitive off;
fancyindex_exact_size off;
fancyindex_time_format "%Y-%m-%d %H:%M";
fancyindex_css_href /css/nsr-folder-default.css;
try_files $uri $uri/ =404;
}
location / {
expires 3600; # this affects cache-contol, etc.
# "autoindex" is built into nginx
# autoindex on;
# autoindex_exact_size off;
# ------------------------------------
# "fancyindex" is not built into nginx
fancyindex on;
fancyindex_default_sort name;
fancyindex_directories_first on;
fancyindex_case_sensitive off;
fancyindex_exact_size off;
fancyindex_time_format "%Y-%m-%d %H:%M";
fancyindex_css_href /css/nsr-folder-default.css;
}
location /cgi-bin/ {
# Disable gzip so script outputs stream properly if needed
gzip off;
# The root directory where your 'cgi-bin' folder lives
# e.g., if files are in /var/www/html/cgi-bin/, set root to /var/www/html
root /var/www/html; # my Apache files live here
# Pass requests to the fcgiwrap Unix socket
# fastcgi_pass unix:/var/run/fcgiwrap.socket;
fastcgi_pass unix:/run/fcgiwrap/fcgiwrap-nginx.sock;
# Include standard Nginx FastCGI parameters
include fastcgi_params;
# Map the exact script filename to be executed
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
}
}
# Settings for a TLS enabled server.
#
server {
listen 443 ssl http2;
# listen [::]:443 ssl http2;
server_name neilrieck.net *.neilrieck.net;
# root /usr/share/nginx/html;
root /var/www/html; # my Apache files live here
# caveat: unlike Apache, Nginx has no provision for intermediate certs (eg. chain file) so you
# must create a bundle file which is a concat of the host cert file with the intermediate
# certs file file like so:
# 1) cd /etc/pki/tls/certs
# 2) cp host-file.crt chain-file.crt > bundle-file.crt
# 3) now use an editor to ensure that the file is in PEM format
# (a) the file does not contain any blank likes or
# (b) the certs in the file stop/start on new lines
#
# ssl_certificate "/etc/pki/nginx/server.crt";
# ssl_certificate "/etc/pki/tls/certs/neilrieck.net-20251022.cer";
ssl_certificate "/etc/pki/tls/certs/neilrieck.net-20251022-bundle.cer";
#
# ssl_certificate_key "/etc/pki/nginx/private/server.key";
ssl_certificate_key "/etc/pki/tls/private/neilrieck.net-20251022.key";
ssl_session_cache shared:SSL:1m;
ssl_session_timeout 10m;
ssl_ciphers PROFILE=SYSTEM;
ssl_prefer_server_ciphers on;
# Load configuration files for the default server block.
include /etc/nginx/default.d/*.conf;
#error_page 404 /404.html;
# location = /40x.html {
#}
#error_page 500 502 503 504 /50x.html;
# location = /50x.html {
#}
#
# password protected folder
# 1) this special folder is password protected so needs to be encountered first
# 2) this folder needs to have its own autoindex directives, or fancyindex directives.
# A common location entry (like the one 17-lines below) will not work here.
#
location ~ ^/mira/ {
expires 3600; # this affects cache-contol, etc.
auth_basic "Restricted Access";
# auth_basic_user_file /etc/nginx/.htpasswd;
auth_basic_user_file /etc/nginx/passwd-folder-mira;
# "autoindex" is built into nginx
# autoindex on;
# autoindex_exact_size off;
# ------------------------------------
# "fancyindex" is not built into nginx
fancyindex on;
fancyindex_default_sort name;
fancyindex_directories_first on;
fancyindex_case_sensitive off;
fancyindex_exact_size off;
fancyindex_time_format "%Y-%m-%d %H:%M";
fancyindex_css_href /css/nsr-folder-default.css;
try_files $uri $uri/ =404;
}
#
# this declaration affects all subseqent folders
#
location / {
expires 3600; # this affects cache-contol, etc.
# "autoindex" is built into nginx
# autoindex on;
# autoindex_exact_size off;
# ------------------------------------
# "fancyindex" is not built into nginx
fancyindex on;
fancyindex_default_sort name;
fancyindex_directories_first on;
fancyindex_case_sensitive off;
fancyindex_exact_size off;
fancyindex_time_format "%Y-%m-%d %H:%M";
fancyindex_css_href /css/nsr-folder-default.css;
}
location /cgi-bin/ {
# Disable gzip so script outputs stream properly if needed
gzip off;
# The root directory where your 'cgi-bin' folder lives
# e.g., if files are in /var/www/html/cgi-bin/, set root to /var/www/html
root /var/www/html;
# Pass requests to the fcgiwrap Unix socket
# fastcgi_pass unix:/var/run/fcgiwrap.socket;
fastcgi_pass unix:/run/fcgiwrap/fcgiwrap-nginx.sock;
# Include standard Nginx FastCGI parameters
include fastcgi_params;
# Map the exact script filename to be executed
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
}
}
}
Back to Home