Revision 1.4

Sep 17, 2021
Functional Update
  • 2.1 Ensure Only Necessary Authentication and Authorization Modules Are Enabled
  • 2.3 Ensure the WebDAV Modules Are Disabled
  • 2.4 Ensure the Status Module Is Disabled
  • 2.5 Ensure the Autoindex Module Is Disabled
  • 2.6 Ensure the Proxy Modules Are Disabled
  • 2.7 Ensure the User Directories Module Is Disabled
  • 2.8 Ensure the Info Module Is Disabled
  • 2.9 Ensure the Basic and Digest Authentication Modules are Disabled - auth_basic_module
  • 2.9 Ensure the Basic and Digest Authentication Modules are Disabled - auth_digest_module
  • 3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'httpd services are running as apache user'
  • 3.2 Ensure the Apache User Account Has an Invalid Shell
  • 4.1 Ensure Access to OS Root Directory Is Denied By Default
  • 4.1 Ensure Access to OS Root Directory Is Denied By Default - 'httpd.conf Require all denied'
  • 4.1 Ensure Access to OS Root Directory Is Denied By Default - 'httpd.conf no Allow directives exist'
  • 4.2 Ensure Appropriate Access to Web Content Is Allowed
  • 4.3 Ensure OverRide Is Disabled for the OS Root Directory - AllowOverride None
  • 4.3 Ensure OverRide Is Disabled for the OS Root Directory - exclude AllowOverrideList
  • 4.4 Ensure OverRide Is Disabled for All Directories - AllowOverride
  • 5.1 Ensure Options for the OS Root Directory Are Restricted
  • 5.10 Ensure Access to .ht* Files Is Restricted
  • 5.2 Ensure Options for the Web Root Directory Are Restricted
  • 5.3 Ensure Options for Other Directories Are Minimized
  • 5.7 Ensure HTTP Request Methods Are Restricted
  • 5.9 Ensure Old HTTP Protocol Versions Are Disallowed - 'httpd.conf <VirtualHost> RewriteEngine = on'
  • 5.9 Ensure Old HTTP Protocol Versions Are Disallowed - 'httpd.conf <VirtualHost> RewriteOptions = inherit'
  • 6.1 Ensure the Error Log Filename and Severity Level Are Configured Correctly - 'ErrorLog 'logs/error_log'
  • 6.1 Ensure the Error Log Filename and Severity Level Are Configured Correctly - 'httpd.conf <VirtualHost> ErrorLog is configured'
  • 6.3 Ensure the Server Access Log Is Configured Correctly - 'httpd.conf CustomLog is configured'
  • 7.1 Ensure mod_ssl and/or mod_nss Is Installed - 'mod_ssl is loaded'
  • 7.2 Ensure a Valid Trusted Certificate Is Installed
  • 7.5 Ensure Weak SSL/TLS Ciphers Are Disabled - 'Global SSLCipherSuite'
  • 7.5 Ensure Weak SSL/TLS Ciphers Are Disabled - 'Global SSLHonorCipherOrder = On'
  • 7.5 Ensure Weak SSL/TLS Ciphers Are Disabled - 'VirtualHost SSLCipherSuite'
  • 7.5 Ensure Weak SSL/TLS Ciphers Are Disabled - 'VirtualHost SSLHonorCipherOrder = On'
  • 7.8 Ensure Medium Strength SSL/TLS Ciphers Are Disabled
  • 7.9 Ensure All Web Content is Accessed via HTTPS
Miscellaneous
  • References updated.
  • Variables updated.