Ffile2fix
Sign in Get started

How to fix Apache AH01630 "client denied by server configuration"

AH01630: client denied by server configuration: /var/www/html/index.php

Apache's authorization module checked the Require rules for the requested path and none of them allowed the request, so it returned 403 Forbidden. It is a configuration decision, not a file permission problem.

Also appears as: [authz_core:error] [pid 1234] [client 203.0.113.5:51234] AH01630: client denied by server configuration: /var/www/example.com/public/ · AH01797: client denied by server configuration (mod_access_compat) · client denied by server configuration: /usr/share/phpmyadmin · Forbidden: You don't have permission to access this resource. (403 with AH01630 in the log)

Common causes

  • The DocumentRoot is outside /var/www and has no <Directory> block with Require all granted (the default config denies /)
  • Old Apache 2.2 syntax (Order deny,allow / Deny from all) mixed with Apache 2.4 Require directives
  • Require ip or Require host rules that do not include the client's IP, often behind a proxy or Cloudflare
  • A <Files> or <FilesMatch> block denying .php, .env or other patterns that matches more than intended
  • Aliases (phpMyAdmin, /.well-known) pointing to folders without their own access rules
  • Security plugins writing Require all denied into .htaccess in a parent or uploads folder

How to fix it

  1. Read the full log line. The path at the end of the AH01630 message shows exactly which folder or file was denied. Check the configs and .htaccess files on that path.
  2. Grant access to the DocumentRoot. Add a <Directory> block for your site's real path with Require all granted, then run apachectl configtest and reload.
  3. Replace Apache 2.2 access syntax. Convert Order allow,deny / Allow from all to Require all granted, and Deny from all to Require all denied. Avoid mixing old and new styles in the same scope.
  4. Fix IP-based rules behind a proxy. If Require ip rules apply and you use Cloudflare or a load balancer, enable mod_remoteip with the proxy ranges so Apache sees the real client IP.
  5. Check Files and FilesMatch blocks. Make sure deny patterns target only sensitive files such as \.env$ or wp-config\.php$ and not all PHP files.

Apache 2.4 vhost

<VirtualHost *:80>
    ServerName example.com
    DocumentRoot /srv/sites/example.com/public
    <Directory /srv/sites/example.com/public>
        AllowOverride All
        Require all granted
    </Directory>
    <FilesMatch "^\.env$">
        Require all denied
    </FilesMatch>
</VirtualHost>

How to stop it happening again

  • Use only Apache 2.4 Require syntax in new configs and .htaccess
  • Add a matching <Directory> block whenever you change DocumentRoot or add an Alias
  • Review security plugin rules after updates

Frequently asked questions

Is AH01630 a file permission problem?

No. File permission problems log "Permission denied" with error 13. AH01630 means an Apache access rule refused the request.

Can I still use Order and Deny in Apache 2.4?

Only if mod_access_compat is loaded, and mixing them with Require causes confusing results. Converting to Require directives is the reliable fix.

Why does it happen only for my new folder outside /var/www?

Apache's default config denies access to the whole filesystem and grants it only to /var/www. Any new location needs its own Require all granted.