CIS Apache HTTP Server 2.2 L2 v3.6.0 Middleware

Audit Details

Name: CIS Apache HTTP Server 2.2 L2 v3.6.0 Middleware

Updated: 4/12/2023

Authority: CIS

Plugin: Unix

Revision: 1.9

Estimated Item Count: 38

File Details

Filename: CIS_Apache_HTTP_Server_2.2_Benchmark_v3.6.0_Level_2_Middleware.audit

Size: 161 kB

MD5: 1431f8e02289c2d45a366f3fd0bea616
SHA256: fc9d25264f715737931ec6c0df5d78ca931d6ad580b99b0c5be71121a67dac25

Audit Changelog

 
Revision 1.9

Apr 12, 2023

Miscellaneous
  • Metadata updated.
  • Platform check updated.
  • Variables updated.
Revision 1.8

Mar 7, 2023

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.7

Jan 4, 2023

Miscellaneous
  • Metadata updated.
  • Variables updated.
Revision 1.6

Dec 7, 2022

Miscellaneous
  • Metadata updated.
Revision 1.5

Aug 9, 2022

Functional Update
  • 11.2 Ensure Apache Processes Run in the httpd_t Confined Context
  • 5.12 Ensure IP Address Based Requests Are Disallowed - 'httpd.conf RewriteCond %{HTTP_HOST} exists'
  • 5.12 Ensure IP Address Based Requests Are Disallowed - 'httpd.conf RewriteCond %{REQUEST_URI} exists'
  • 5.12 Ensure IP Address Based Requests Are Disallowed - 'httpd.conf RewriteEngine = on'
  • 5.12 Ensure IP Address Based Requests Are Disallowed - 'httpd.conf RewriteRule ^.(.*) - [L,F] exists'
  • 5.12 Ensure IP Address Based Requests Are Disallowed - Rewrite module not loaded
  • 6.6 Ensure ModSecurity Is Installed and Enabled
Miscellaneous
  • Platform check updated.
Revision 1.4

Apr 25, 2022

Miscellaneous
  • Metadata updated.
Revision 1.3

Mar 29, 2022

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.2

Jun 17, 2021

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.1

May 6, 2021

Functional Update
  • 5.11 Ensure Access to Inappropriate File Extensions Is Restricted - 'httpd.conf FileMatch directive Require all denied'
  • 5.12 Ensure IP Address Based Requests Are Disallowed - 'httpd.conf RewriteCond %{HTTP_HOST} exists'
  • 5.12 Ensure IP Address Based Requests Are Disallowed - 'httpd.conf RewriteCond %{REQUEST_URI} exists'
  • 5.12 Ensure IP Address Based Requests Are Disallowed - 'httpd.conf RewriteEngine = on'
  • 5.12 Ensure IP Address Based Requests Are Disallowed - 'httpd.conf RewriteRule ^.(.*) - [L,F] exists'
  • 6.2 Ensure a Syslog Facility Is Configured for Error Logging - 'httpd.conf <VirtualHost> Syslog is configured'
  • 7.11 Ensure HTTP Strict Transport Security Is Enabled - 'httpd.conf Strict-Transport-Security 'max-age=480'
  • 7.11 Ensure HTTP Strict Transport Security Is Enabled - 'httpd.conf Strict-Transport-Security configuration'
Miscellaneous
  • Metadata updated.
  • References updated.