phpMyAdmin Installation and Secure Access Guide
Step-by-step phpMyAdmin installation on Apache and Nginx, SSL configuration, user management, IP restrictions, and security hardening best practices.
Table of Contents
phpMyAdmin Installation and Secure Access Guide
phpMyAdmin is an open-source PHP application that lets you manage MySQL and MariaDB databases through a web browser. You can create databases, manage tables, run SQL queries, and handle user permissions through its graphical interface. This guide covers installation, Apache and Nginx configuration, SSL setup, and security hardening.
Prerequisites
Before installing phpMyAdmin, ensure the following are ready:
- Ubuntu 20.04/22.04 or Debian 11/12
- MySQL 8.0+ or MariaDB 10.5+
- PHP 7.4+ (recommended: PHP 8.1+)
- Apache 2.4+ or Nginx 1.18+
# System update
apt update && apt upgrade -y
# PHP and required modules
apt install -y php php-mysql php-mbstring php-zip php-gd php-json php-curl
# Check PHP version
php -v
Installing phpMyAdmin
Package Manager Installation
# Install phpMyAdmin
apt install -y phpmyadmin
During installation:
- Web server selection:
apache2orlighttpd(skip if using Nginx) - Configure database with
dbconfig-common:Yes - Set a password for phpMyAdmin
Manual Installation (Recommended)
Installing manually gives you the latest version and more control:
# Download the latest release
cd /tmp
wget https://www.phpmyadmin.net/downloads/phpMyAdmin-latest-all-languages.tar.gz
# Extract archive
tar xzf phpMyAdmin-latest-all-languages.tar.gz
# Move to web directory
mv phpMyAdmin-*-all-languages /var/www/html/phpmyadmin
# Set ownership
chown -R www-data:www-data /var/www/html/phpmyadmin
chmod -R 755 /var/www/html/phpmyadmin
# Create config file
cp /var/www/html/phpmyadmin/config.sample.inc.php /var/www/html/phpmyadmin/config.inc.php
Generate Blowfish Secret
# Generate a random 32-character key
openssl rand -base64 32
# Edit config.inc.php
nano /var/www/html/phpmyadmin/config.inc.php
// Paste the generated key here
$cfg['blowfish_secret'] = 'PASTE_YOUR_RANDOM_KEY_HERE';
// Set temp directory
$cfg['TempDir'] = '/tmp/phpmyadmin';
# Create temp directory
mkdir -p /tmp/phpmyadmin
chown www-data:www-data /tmp/phpmyadmin
Apache Configuration
Create Virtual Host
nano /etc/apache2/sites-available/phpmyadmin.conf
<VirtualHost *:80>
ServerName pma.example.com
DocumentRoot /var/www/html/phpmyadmin
<Directory /var/www/html/phpmyadmin>
Options FollowSymLinks
DirectoryIndex index.php
AllowOverride All
Require all granted
</Directory>
ErrorLog ${APACHE_LOG_DIR}/phpmyadmin_error.log
CustomLog ${APACHE_LOG_DIR}/phpmyadmin_access.log combined
</VirtualHost>
# Enable site
a2ensite phpmyadmin.conf
a2enmod rewrite
systemctl reload apache2
HTTP Basic Auth Protection
# Create .htpasswd file
htpasswd -c /etc/apache2/.htpasswd admin
<Directory /var/www/html/phpmyadmin>
AuthType Basic
AuthName 'phpMyAdmin Access'
AuthUserFile /etc/apache2/.htpasswd
Require valid-user
</Directory>
Nginx Configuration
nano /etc/nginx/sites-available/phpmyadmin
server {
listen 80;
server_name pma.example.com;
root /var/www/html/phpmyadmin;
index index.php;
# HTTP Auth protection
auth_basic 'phpMyAdmin Access';
auth_basic_user_file /etc/nginx/.htpasswd;
location / {
try_files $uri $uri/ =404;
}
location ~ \.php$ {
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/var/run/php/php8.1-fpm.sock;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
include fastcgi_params;
}
location ~ /\.ht {
deny all;
}
# Hide sensitive directories
location ~* /(libraries|setup/frames|setup/libs) {
deny all;
return 404;
}
}
# Create htpasswd for Nginx
apt install -y apache2-utils
htpasswd -c /etc/nginx/.htpasswd admin
# Enable site
ln -s /etc/nginx/sites-available/phpmyadmin /etc/nginx/sites-enabled/
nginx -t
systemctl reload nginx
SSL Configuration
Free SSL with Let's Encrypt
# Install Certbot
apt install -y certbot python3-certbot-apache
# or for Nginx:
apt install -y certbot python3-certbot-nginx
# Obtain SSL certificate for Apache
certbot --apache -d pma.example.com
# Obtain SSL certificate for Nginx
certbot --nginx -d pma.example.com
# Test auto-renewal
certbot renew --dry-run
Manual SSL Configuration (Nginx)
server {
listen 443 ssl http2;
server_name pma.example.com;
root /var/www/html/phpmyadmin;
index index.php;
ssl_certificate /etc/letsencrypt/live/pma.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/pma.example.com/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers HIGH:!aNULL:!MD5;
ssl_prefer_server_ciphers on;
# HSTS
add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains' always;
auth_basic 'phpMyAdmin Access';
auth_basic_user_file /etc/nginx/.htpasswd;
location ~ \.php$ {
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/var/run/php/php8.1-fpm.sock;
}
}
# Redirect HTTP to HTTPS
server {
listen 80;
server_name pma.example.com;
return 301 https://$host$request_uri;
}
User Management
Create Dedicated phpMyAdmin User
-- Connect to MySQL/MariaDB
mysql -u root -p
-- Create admin user for phpMyAdmin
CREATE USER 'pma_admin'@'localhost' IDENTIFIED BY 'StrongPassword123!';
GRANT ALL PRIVILEGES ON *.* TO 'pma_admin'@'localhost' WITH GRANT OPTION;
-- Create restricted app user
CREATE USER 'app_user'@'localhost' IDENTIFIED BY 'AppPassword456!';
GRANT ALL PRIVILEGES ON myapp.* TO 'app_user'@'localhost';
FLUSH PRIVILEGES;
Restrict Users in config.inc.php
// Allow only specific users
$cfg['Servers'][$i]['AllowDeny']['order'] = 'deny,allow';
$cfg['Servers'][$i]['AllowDeny']['rules'] = [
'deny % from all',
'allow pma_admin from localhost',
'allow app_user from 192.168.1.0/24',
];
// Block root login
$cfg['Servers'][$i]['AllowRoot'] = false;
Security Hardening
IP Restriction
# Nginx - allow only specific IPs
location / {
allow 192.168.1.0/24;
allow 10.0.0.5;
deny all;
}
# Apache - IP restriction
<Directory /var/www/html/phpmyadmin>
Require ip 192.168.1.0/24
Require ip 10.0.0.5
</Directory>
Change Default URL
# Rename the phpmyadmin directory
mv /var/www/html/phpmyadmin /var/www/html/db_manager_x7k2
# Update Nginx/Apache configuration accordingly
Session Security
// config.inc.php - security settings
$cfg['LoginCookieValidity'] = 1800; // 30 minute session timeout
$cfg['LoginCookieStore'] = 0; // Delete session on browser close
$cfg['ForceSSL'] = true; // Enforce SSL
$cfg['Servers'][$i]['ssl'] = true; // MySQL SSL connection
$cfg['SendErrorReports'] = 'never';
Remove Setup Directory
# Remove setup directory after installation
rm -rf /var/www/html/phpmyadmin/setup
Fail2Ban Brute Force Protection
nano /etc/fail2ban/filter.d/phpmyadmin.conf
[Definition]
failregex = ^<HOST> .* 'POST /phpmyadmin/index.php.*' (401|403)
ignoreregex =
# /etc/fail2ban/jail.local
[phpmyadmin]
enabled = true
port = http,https
filter = phpmyadmin
logpath = /var/log/nginx/phpmyadmin_access.log
maxretry = 5
bantime = 3600
Troubleshooting
# Check PHP error logs
tail -f /var/log/php8.1-fpm.log
# Nginx error logs
tail -f /var/log/nginx/error.log
# Apache error logs
tail -f /var/log/apache2/phpmyadmin_error.log
# Check phpMyAdmin permissions
ls -la /var/www/html/phpmyadmin/
# Verify PHP modules
php -m | grep -E 'mysql|mbstring|zip'
Conclusion
phpMyAdmin is a powerful database management tool, but without proper security configuration it poses serious risks. Always use SSL, add HTTP authentication, restrict by IP, and change the default URL. With these measures in place, phpMyAdmin can be used safely on REXE servers.
Related Articles
MySQL and MariaDB Installation: Basic Management Guide
Step-by-step MySQL and MariaDB installation on Linux, mysql_secure_installation, creating databases and users, basic SQL commands, remote access configuration, and performance tuning.
PostgreSQL Installation and Basic Management Guide
PostgreSQL installation on Ubuntu/Debian and RHEL/CentOS, creating users and databases, basic SQL commands, remote connection setup, and backup strategies. Step-by-step guide.
Redis and Memcached Setup: Cache Layer Guide
Redis and Memcached installation on Ubuntu/Debian, basic commands, persistence settings, TTL configuration, Redis vs Memcached comparison, and application integration.