HTTPError.net

The fastest way to diagnose, understand, and fix any HTTP status code

Apache

How to Fix 403 Forbidden Error in Apache

Quick Fix

The most common cause of 403 errors in Apache is: Incorrect file/directory permissions

Quick solution: Directories should be 755: sudo find /var/www/html -type d -exec chmod 755 {} \;

A 403 Forbidden error in Apache is usually caused by one of a handful of configuration problems. Work through the causes below in order - the first ones are the most common.

Common Causes in Apache

Step-by-Step Solutions

Solution 1: Check File Permissions
  1. Directories should be 755: sudo find /var/www/html -type d -exec chmod 755 {} \;
  2. Files should be 644: sudo find /var/www/html -type f -exec chmod 644 {} \;
  3. Ensure correct ownership: sudo chown -R www-data:www-data /var/www/html
  4. Test the site
Solution 2: Check Apache Configuration
  1. Edit Apache config: sudo nano /etc/apache2/sites-available/000-default.conf
  2. Ensure Directory directive allows access:
  3. \n Options FollowSymLinks\n AllowOverride All\n Require all granted\n
  4. Test config: sudo apache2ctl configtest
  5. Restart Apache: sudo systemctl restart apache2
Solution 3: Add Index File
  1. Make sure the directory contains an index file (index.html or index.php)
  2. Do not leave test files such as phpinfo() pages on a public server
  3. Ensure DirectoryIndex is set in Apache config: DirectoryIndex index.php index.html
Solution 4: Check .htaccess
  1. Temporarily rename .htaccess: mv .htaccess .htaccess.old
  2. Test if site works
  3. If fixed, review .htaccess for Deny directives
  4. Check for: Order deny,allow / Deny from all
  5. Update or remove problematic rules
Solution 5: Check SELinux Contexts
  1. Check SELinux status: getenforce
  2. Look for recent denials: sudo ausearch -m avc -ts recent
  3. Set the correct context: sudo chcon -R -t httpd_sys_content_t /var/www/html
  4. Make it persistent with semanage fcontext, then run restorecon -Rv /var/www/html
  5. Avoid disabling SELinux - fix the context instead

Prevention Tips