Apache
How to Fix 403 Forbidden Error in Apache
Quick Fix
The most common cause of 403 errors in Apache is: Incorrect file/directory permissions
Quick solution: Directories should be 755: sudo find /var/www/html -type d -exec chmod 755 {} \;
A 403 Forbidden error in Apache is usually caused by one of a handful of configuration problems. Work through the causes below in order - the first ones are the most common.
Common Causes in Apache
- Incorrect file/directory permissions
- Missing index file (index.html, index.php)
- Directory listing disabled
- .htaccess restrictions
- Apache configuration denying access
- SELinux blocking access
Step-by-Step Solutions
Solution 1: Check File Permissions
- Directories should be 755: sudo find /var/www/html -type d -exec chmod 755 {} \;
- Files should be 644: sudo find /var/www/html -type f -exec chmod 644 {} \;
- Ensure correct ownership: sudo chown -R www-data:www-data /var/www/html
- Test the site
Solution 2: Check Apache Configuration
- Edit Apache config: sudo nano /etc/apache2/sites-available/000-default.conf
- Ensure Directory directive allows access:
\n Options FollowSymLinks\n AllowOverride All\n Require all granted\n - Test config: sudo apache2ctl configtest
- Restart Apache: sudo systemctl restart apache2
Solution 3: Add Index File
- Make sure the directory contains an index file (index.html or index.php)
- Do not leave test files such as phpinfo() pages on a public server
- Ensure DirectoryIndex is set in Apache config: DirectoryIndex index.php index.html
Solution 4: Check .htaccess
- Temporarily rename .htaccess: mv .htaccess .htaccess.old
- Test if site works
- If fixed, review .htaccess for Deny directives
- Check for: Order deny,allow / Deny from all
- Update or remove problematic rules
Solution 5: Check SELinux Contexts
- Check SELinux status: getenforce
- Look for recent denials: sudo ausearch -m avc -ts recent
- Set the correct context: sudo chcon -R -t httpd_sys_content_t /var/www/html
- Make it persistent with semanage fcontext, then run restorecon -Rv /var/www/html
- Avoid disabling SELinux - fix the context instead
Prevention Tips
- Watch the Apache error logs and alert on rising error rates
- Test configuration changes in a staging environment first
- Keep configuration under version control so you can roll back quickly
- Run a configuration test (e.g. nginx -t or apachectl configtest) before every reload