How To Set Up WebDAV With Lighttpd

Destiny
WebDAV stands for Web-based Distributed Authoring and Versioning and is a set of extensions to the HTTP protocol that allow users to directly edit files on the lighttpd server so that they do not need to be downloaded/uploaded via FTP. Of course, WebDAV can also be used to upload and download files.

Installing WebDAV

You can install lighttpd (if it’s not already installed), the lighttpd WebDAV module and the apache2-utils package (which contains the tool htpasswd which we will need later on to generate a password file for the WebDAV share) as follows:

1
:~$ sudo apt-get install lighttpd lighttpd-mod-webdav apache2-utils

Afterwards, we must make sure that the directory /var/run/lighttpd is owned by the www-data user and group. This directory will contain an SQLite database needed by WebDAV:

1
:~$ sudo chown www-data:www-data /var/run/lighttpd/

Next, we enable the modules mod_auth and mod_webdav:

1
2
:~$ sudo lighty-enable-mod auth
:~$ sudo lighty-enable-mod webdav

Reload lighttpd afterwards:

1
:`$ sudo systemctl restart lighttpd

Creating A Virtual Host

I will now create a lighttpd vhost (www.example.com) in the directory /var/www/web1/web. If you already have a vhost for which you’d like to enable WebDAV, you must adjust this tutorial to your situation.

First, we create the directory /var/www/web1/web and make the lighttpd user (www-data) the owner of that directory:

1
2
:~$ sudo mkdir -p /var/www/web1/web
:~$ sudo chown www-data:www-data /var/www/web1/web

Then we open /etc/lighttpd/lighttpd.conf and add the following vhost to the end of the file:

1
2
3
4
5
:~$ vim /etc/lighttpd/lighttpd.conf
[...]
$HTTP["host"] == "www.shixuen.com" {
server.document-root = "/var/www/web1/web"
}

Afterwards we restart lighttpd:

1
:~$ sudo systemctl restart lighttpd

Configure The Virtual Host For WebDAV

Now we create the WebDAV password file /var/www/web1/passwd.dav with the user test (the -c switch creates the new password file):

1
:~$ htpasswd -c /var/www/web1/passwd.dav test

You will be asked to type in a password for the user test.

(Please don’t use the -c switch if /var/www/web1/passwd.dav is already existing because this will recreate the file from scratch, meaning you lose all users in that file!)

Now we change the permissions of the /var/www/web1/passwd.dav file so that only root and the members of the www-data group can access it:

1
2
:~$ chown root:www-data /var/www/web1/passwd.dav
:~$ chmod 640 /var/www/web1/passwd.dav

Now we modify our vhost in /etc/lighttpd/lighttpd.conf so that it looks as follows:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
:~$ vim /etc/lighttpd/lighttpd.conf
$HTTP["host"] == "www.shixuen.com" {
server.document-root = "/var/www/web1/web"
alias.url = ( "/webdav" => "/var/www/web1/web" )
$HTTP["url"] =~ "^/webdav($|/)" {
dir-listing.activate = "enable"
dir-listing.encoding = "utf-8"
webdav.activate = "enable"
webdav.is-readonly = "disable"
webdav.sqlite-db-name = "/var/run/lighttpd/lighttpd.webdav_lock.db"
auth.backend = "htpasswd"
auth.backend.htpasswd.userfile = "/var/www/web1/passwd.dav"
auth.require = ( "" =>
(
"method" => "basic",
"realm" => "webdav",
"require" => "valid-user"
)
)
}
}

The alias.url directive makes ( together with $HTTP[“url”] =~ “^/webdav($|/)” ) that when you call /webdav, WebDAV is invoked, but you can still access the whole document root of the vhost. All other URLs of that vhost are still “normal” HTTP.

Restart lighttpd afterwards:

1
:~$ sudo systemctl restart lighttpd

Test WebDAV

Browser

1
:~$ firefox http://www.shixuen.com/webdav

Cadaver - WebDAV client

We will now install cadaver, a command-line WebDAV client:

1
:~$ apt-get install cadaver

To test if WebDAV works, type:

1
:~$ cadaver http://www.shixuen.com/webdav/

You should be prompted for a user name. Type in test and then the password for the user test. If all goes well, you should be granted access which means WebDAV is working ok. Type quit to leave the WebDAV shell:

1
2
3
4
5
6
7
root@server1:~# cadaver http://www.shixuen.com/webdav/
Authentication required for webdav on server 'www.shixuen.com':
Username: test
Password:
dav:/webdav/> quit
Connection to 'www.shixuen.com' closed.
root@server1:~#

Modules

lighttpd docs

mod_auth

lighttpd_auth module

Supported Methods

lighttpd supports both authentication methods described by RFC 2617:

basic

The Basic method transfers the username and the password in cleartext over the network (base64 encoded) and might result in security problems if not used in conjunction with a crypted channel between client and server.

digest

The Digest method only transfers a hashed value over the network which performs a lot of work to harden the authentication process in insecure networks.

Backends

Depending on the method lighttpd provides various way to store the credentials used for the authentication.

  • For basic auth:
  • plain
  • htpasswd
  • htdigest
  • ldap
  • gssapi
  • mysql
  • pam
  • sasl
  • For digest auth:
  • plain
  • htdigest

References:

  • Wikipedia
  • IETF-RFC2617
  • Lighttpd-Docs