CIS Apache HTTP Server 2.4 L1 v2.1.0 Middleware

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS Apache HTTP Server 2.4 L1 v2.1.0 Middleware

Updated: 2/10/2025

Authority: CIS

Plugin: Unix

Revision: 1.4

Estimated Item Count: 87

File Details

Filename: CIS_Apache_HTTP_Server_2.4_Benchmark_v2.1.0_Level_1_Middleware.audit

Size: 226 kB

MD5: 124d062d6a119570c9dab3de4390f0db
SHA256: 123cfd22655e4eeaf610ba157bc6dec01c78b77610b38a9afd7bf8e6024b7419

Audit Changelog

 
Revision 1.4

Feb 10, 2025

Miscellaneous
  • Audit deprecated.
  • Metadata updated.
  • References updated.
Revision 1.3

Oct 25, 2024

Functional Update
  • 7.6 Ensure Insecure SSL Renegotiation Is Not Enabled
  • 7.8 Ensure Medium Strength SSL/TLS Ciphers Are Disabled
  • 7.9 Ensure All Web Content is Accessed via HTTPS
  • 9.2 Ensure KeepAlive Is Enabled
Informational Update
  • 7.9 Ensure All Web Content is Accessed via HTTPS
Revision 1.2

Aug 28, 2024

Informational Update
  • 4.2 Ensure Appropriate Access to Web Content Is Allowed
  • 5.10 Ensure Access to .ht* Files Is Restricted
  • 5.11 Ensure Access to .git Files Is Restricted
  • 5.12 Ensure Access to .svn Files Is Restricted
  • 5.2 Ensure Options for the Web Root Directory Are Restricted
  • 5.4 Ensure Default HTML Content Is Removed - 'Server Information handler does not exist'
  • 5.4 Ensure Default HTML Content Is Removed - 'Server Status handler does not exist'
  • 5.4 Ensure Default HTML Content Is Removed - 'httpd-manual is not installed'
  • 5.4 Ensure Default HTML Content Is Removed - 'other handler does not exist'
  • 5.7 Ensure HTTP Request Methods Are Restricted - allow
  • 5.7 Ensure HTTP Request Methods Are Restricted - deny
  • 6.1 Ensure the Error Log Filename and Severity Level Are Configured Correctly - ErrorLog
  • 6.1 Ensure the Error Log Filename and Severity Level Are Configured Correctly - LogLevel
  • 6.1 Ensure the Error Log Filename and Severity Level Are Configured Correctly - VirtualHost
  • 6.3 Ensure the Server Access Log Is Configured Correctly - CustomLog'
  • 6.3 Ensure the Server Access Log Is Configured Correctly - LogFormat
  • 6.4 Ensure Log Storage and Rotation Is Configured Correctly - rotate
  • 6.4 Ensure Log Storage and Rotation Is Configured Correctly - weekly
  • 7.2 Ensure a Valid Trusted Certificate Is Installed
Miscellaneous
  • References updated.
Revision 1.1

Jun 17, 2024

Miscellaneous
  • Metadata updated.