
# Systemübersicht / Aktualisierung
## Schritt 1 – System aktualisieren
- ```apt update``` -> ```apt upgrade -y```

## Betriebssystem prüfen
- welche Ubuntu-Version und welcher Kernel wurde installiert.
- ```cat /etc/os-release```
- danach
- ```uname -a```

## Reboot
- ```reboot```

## User anlegen

- ```adduser linus```
   - Password: Tresor

### Adminrechte vergeben

```usermod -aG sudo linus```

#### Kontrolle
```groups linus```


## SSH für linus einrichten
- cd /home/linus
### .ssh-Verzeichnis anlegen
- mkdir .ssh
- chmod 700 .ssh
### Den bestehenden Public Key übernehmen
- cp /root/.ssh/authorized_keys /home/linus/.ssh/
### Eigentümer korrekt setzen
chown -R linus:linus /home/linus/.ssh
chmod 600 /home/linus/.ssh/authorized_keys
### Kontrolle
ls -la /home/linus/.ssh

## SSH absichern
- Sicherung aktuelle Konfiguration
- ```sudo cp /etc/ssh/sshd_config /etc/ssh/sshd_config.backup-2026-08-04```
  - Abfrage wirksamer Einstellungen
    - ```sudo sshd -T | grep -E '^(permitrootlogin|passwordauthentication|pubkeyauthentication)'```

    - Ergebnis
        ```
        permitrootlogin prohibit-password
        pubkeyauthentication yes
        passwordauthentication no
        ```
      
    - Bedeutung
      ```
        Root-Login per Passwort ist gesperrt.
        SSH-Schlüssel sind aktiviert.
        Passwort-Login ist vollständig deaktiviert.
        Root kann derzeit noch mit SSH-Key hinein.
        ```
## Ist SSH-Konfiguration syntaktisch sauber
- ```sudo sshd -t``` -> keine Ausgabe: dann ok


# Firewall einrichten
## Überprüfung ob UFW (Uncomplicated Firewall) installiert ist
- ```sudo ufw status verbose```
- Status: inactive -> 
  - SSH freistzen + Firewall aktivieren
  - ```sudo ufw allow OpenSSH```
  - ```sudo ufw enable```
  - erneut prüfen:
    - ```sudo ufw status verbose```

# Automatische Installation von Sicherheitsupdates
- ```sudo apt install unattended-upgrades -y```
- ```sudo dpkg-reconfigure unattended-upgrades``` -> Y

# RA-002 – Runtime Platform
## Apache
### Installation
- Ist zustand Apache
  - ```apache2 -v```

- Unstallation Apache 
- ```
  sudo apt update
  sudo apt install apache2 -y
  ```
  Nach installation auf sRx
```
Befehl: apache2 -v
Ausgabe
Server version: Apache/2.4.66 (Ubuntu)
Server built:   2026-07-06T15:33:20

Befehl: systemctl status apache2
Ausgabe
● apache2.service - The Apache HTTP Server
     Loaded: loaded (/usr/lib/systemd/system/apache2.service; enabled; preset: enabled)
     Active: active (running) since Wed 2026-08-05 05:35:07 UTC; 2min 21s ago
 Invocation: ea462e70632f45d5aef36b22fe4d2cfa
       Docs: https://httpd.apache.org/docs/2.4/
   Main PID: 5901 (apache2)
     Status: "Total requests: 0; Idle/Busy workers 100/0;Requests/sec: 0; Bytes served/sec:   0 B/sec"
      Tasks: 55 (limit: 7761)
     Memory: 6.4M (peak: 6.4M)
        CPU: 78ms
     CGroup: /system.slice/apache2.service
             ├─5901 /usr/sbin/apache2 -k start -DFOREGROUND
             ├─5917 /usr/sbin/apache2 -k start -DFOREGROUND
             └─5918 /usr/sbin/apache2 -k start -DFOREGROUND
```
### Firewall

Freigabe Firewall
```
sudo ufw allow "Apache"
```
Kontrolle
```
sudo ufw status
```

Ergebnnis: http://195.20.241.181/


## RA-002.2 – PHP Runtime

PHP-Version Ubuntu 26.04
```
apt policy php
```

```
apt search php8
```
### PHP Installation 
```
sudo apt install -y \
php \
libapache2-mod-php \
php-cli \
php-common \
php-mysql \
php-curl \
php-mbstring \
php-xml \
php-zip \
php-intl \
php-gd
```

Neustart Apache
```
sudo systemctl restart apache2
```
Verifikation
```
php -v
```

prüfen von zentralen Erweiterungen
```
php -m | grep -Ei 'curl|dom|gd|intl|libxml|mbstring|mysqli|pdo_mysql|simplexml|xml|xsl|zip'
```

temporäre Testdatei anlegen
```
echo '<?php phpinfo();' | sudo tee /var/www/html/phpinfo.php
```
Ergebnnis: http://195.20.241.181/phpinfo.php

Datei löschen
```
sudo rm /var/www/html/phpinfo.php
```

## MySQL
### MySQL Installation
Verfügbare Version
```
apt policy mysql-server
```

MySQl installieren
```
sudo apt install mysql-server -y
```

Dienst prüfen
```
sudo systemctl status mysql
```
Version  prüfen
```
mysql --version
```
### MySQL Sicherheit
Ist-Zustand prüfen -> als root anmelden
```
sudo mysql
```

Benutzer anzeigen
```
SELECT user, host, plugin FROM mysql.user;
```
Ergebnis
```
+------------------+-----------+-----------------------+
| user             | host      | plugin                |
+------------------+-----------+-----------------------+
| debian-sys-maint | localhost | auth_socket           |
| mysql.infoschema | localhost | caching_sha2_password |
| mysql.session    | localhost | caching_sha2_password |
| mysql.sys        | localhost | caching_sha2_password |
| root             | localhost | auth_socket           |
+------------------+-----------+-----------------------+
5 rows in set (0.00 sec)

Das bedeutet:
Root-Login lokal + Authentifizierung über Linux
->
Nur jemand mit administrativem Linux-Zugang (sudo) kann MySQL als Root administrieren.
Es existiert kein Root-Datenbankpasswort, das gestohlen oder erraten werden könnte.

```

Datenbank installieren
```
CREATE DATABASE rx_dev001
CHARACTER SET utf8mb4
COLLATE utf8mb4_0900_ai_ci;
```
```
CREATE DATABASE rx_dev001
CHARACTER SET utf8mb4
COLLATE utf8mb4_0900_ai_ci;

CREATE USER 'rx_dev001'@'localhost'
IDENTIFIED BY '<tresor>';

GRANT ALL PRIVILEGES
ON rx_dev001.*
TO 'rx_dev001'@'localhost';

FLUSH PRIVILEGES;
```

## RA-002.4 – Runtime Platform → Virtual Hosts

### A-record
dev.reconcilix.net
↓
195.20.241.181

done: http://dev.reconcilix.net/


### Verzeichnisstruktur anlegen
```
sudo mkdir -p /var/www/rx_dev001
sudo chown -R linus:www-data /var/www/rx_dev001
sudo chmod -R 755 /var/www/rx_dev001
```

### Apache-Module
```
sudo a2enmod rewrite
sudo a2enmod headers
sudo systemctl restart apache2
```


### Konfigurationsdatei anlegen
```
sudo nano /etc/apache2/sites-available/rx_dev001.conf
```
Inhalt für nano:
```
<VirtualHost *:80>

    ServerName dev.reconcilix.net

    ServerAdmin admin@reconcilix.net

    DocumentRoot /var/www/rx_dev001/public

    <Directory /var/www/rx_dev001/public>
        Options FollowSymLinks
        AllowOverride All
        Require all granted
    </Directory>

    ErrorLog ${APACHE_LOG_DIR}/rx_dev001_error.log
    CustomLog ${APACHE_LOG_DIR}/rx_dev001_access.log combined

</VirtualHost>
```

-> speichern
```
Strg + O

enter

Strg + X
```

### Backup conf-Dateien
```
sudo cp /etc/apache2/sites-available/rx_dev001.conf \
        /etc/apache2/sites-available/rx_dev001.conf.backup

sudo cp /etc/apache2/sites-available/rx_dev001-le-ssl.conf \
        /etc/apache2/sites-available/rx_dev001-le-ssl.conf.backup

```





### Verzeichnis public anlegen
```
sudo mkdir -p /var/www/rx_dev001/public
```

### Testdatei
```
echo "<h1>Reconcilix DEV</h1>" | sudo tee /var/www/rx_dev001/public/index.html
```

### Apache aktivieren
```
sudo a2ensite rx_dev001.conf
sudo a2dissite 000-default.conf
sudo apachectl configtest
```
UND RESTART:
```
sudo systemctl reload apache2
```
```
-> works: http://dev.reconcilix.net/
```
### HTTPS mit Let’s EncryptY
```
sudo apt install -y certbot python3-certbot-apache
```
```
sudo certbot --apache -d dev.reconcilix.net
```
#### Überprüfen
```
sudo certbot certificates
```
```
Ergebnis:
Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Found the following certs:
Certificate Name: dev.reconcilix.net
Serial Number: 6cd6a955f6e17fda87dc7bcb01dc80f8072
Key Type: ECDSA
Domains: dev.reconcilix.net
Expiry Date: 2026-11-03 07:24:49+00:00 (VALID: 89 days)
Certificate Path: /etc/letsencrypt/live/dev.reconcilix.net/fullchain.pem
Private Key Path: /etc/letsencrypt/live/dev.reconcilix.net/privkey.pem
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
```

```
systemctl status certbot.timer
```
```
Ergebnis:
 certbot.timer - Run certbot twice daily
     Loaded: loaded (/usr/lib/systemd/system/certbot.timer; enabled; preset: enabled)
     Active: active (waiting) since Wed 2026-08-05 08:16:00 UTC; 10min ago
 Invocation: 6558d134d5e24c79a4687edad9564b94
    Trigger: Wed 2026-08-05 21:12:16 UTC; 12h left
   Triggers: ● certbot.service
```

## Rechte an Dateien
### Eigentümer und Gruppe setzen
```
sudo chown -R linus:www-data /var/www/rx_dev001/v2
```
### Grundrechte für Verzeichnisse und Dateien
```
sudo find /var/www/rx_dev001/v2 -type d -exec chmod 750 {} \;
sudo find /var/www/rx_dev001/v2 -type f -exec chmod 640 {} \;
```
```
Damit kann:

linus lesen, schreiben und Verzeichnisse betreten,
Apache über die Gruppe www-data lesen und Verzeichnisse betreten,
sonst niemand auf den Anwendungscode zugreifen.

```
### Schreibbares Logverzeichnis + local-Verzeichnis
```
sudo chmod 2770 /var/www/rx_dev001/v2/logs
sudo chmod 2770 /var/www/rx_dev001/v2/local

Die führende 2 aktiviert das Setgid-Bit. Neu erzeugte Dateien übernehmen dadurch automatisch die Gruppe www-data.
```
Falls bereits logdaten vorhanden sind
```
sudo find /var/www/rx_dev001/v2/logs -type f -exec chmod 660 {} \;
```
### Credentials besonders kontrollieren
```
sudo chmod 640 /var/www/rx_dev001/v2/config/database.php
sudo chmod 640 /var/www/rx_dev001/v2/config/credentials.local.php
```

```
Kontrolle
ls -l /var/www/rx_dev001/v2/config/database.php
ls -l /var/www/rx_dev001/v2/config/credentials.local.php

Erwartet:
-rw-r----- 1 linus www-data ... database.php
-rw-r----- 1 linus www-data ... credentials.local.php
```

### Gesamtstruktur prüfen
```
find /var/www/rx_dev001/v2 -maxdepth 2 \
-printf '%M %u:%g %p\n' | sort
```


## Suche nach Sting
```
grep -RIn \
--exclude-dir=vendor \
--exclude-dir=.git \
"reconcilix.vocnet.org/context/0001" \
/var/www/rx_dev001/v2
```





