TNS IBM HTTP Server Best Practice

Audit Details

Name: TNS IBM HTTP Server Best Practice

Updated: 12/22/2023

Authority: IBM

Plugin: Windows

Revision: 1.15

Estimated Item Count: 44

File Details

Filename: TNS_IBM_HTTP_Server_Best_Practice.audit

Size: 67.9 kB

MD5: 27d16fc0b7563af41dbb268f64fcbf63
SHA256: e76d384cb97c479f3eb29ca0d7bc67d60be40427c208f2b2fcd732d39d7cd89d

Audit Items

DescriptionCategories
Buffer overflow protection should be configured 'LimitRequestBody'

SYSTEM AND COMMUNICATIONS PROTECTION

Buffer overflow protection should be configured 'LimitRequestFields'

SYSTEM AND COMMUNICATIONS PROTECTION

Buffer overflow protection should be configured 'LimitRequestFieldsize'

SYSTEM AND COMMUNICATIONS PROTECTION

Buffer overflow protection should be configured 'LimitRequestline'

SYSTEM AND COMMUNICATIONS PROTECTION

CGI-BIN directory should be disabled. 'Addmodule mod_cgi.c'

CONFIGURATION MANAGEMENT

CGI-BIN directory should be disabled. 'AddModule mod_env.c'

CONFIGURATION MANAGEMENT

CGI-BIN directory should be disabled. 'Directory'

CONFIGURATION MANAGEMENT

CGI-BIN directory should be disabled. 'LoadModule cgi_module'

CONFIGURATION MANAGEMENT

CGI-BIN directory should be disabled. 'LoadModule env_module'

CONFIGURATION MANAGEMENT

CGI-BIN directory should be disabled. 'ScriptAlias'

CONFIGURATION MANAGEMENT

Configuration files should be secured against unauthorized access.
Directory access permissions should be restricted.

ACCESS CONTROL

File permissions in the root document should only be accessible by administrator
HTTP TRACE method should be disabled. 'RewriteCond'

CONFIGURATION MANAGEMENT

HTTP TRACE method should be disabled. 'RewriteEngine'

CONFIGURATION MANAGEMENT

HTTP TRACE method should be disabled. 'RewriteLog'

AUDIT AND ACCOUNTABILITY

HTTP TRACE method should be disabled. 'RewriteLogLevel'

AUDIT AND ACCOUNTABILITY

HTTP TRACE method should be disabled. 'RewriteRule'

CONFIGURATION MANAGEMENT

HTTP TRACE method should be disabled. 'TraceEnable'

CONFIGURATION MANAGEMENT

Keep Alive setting parameter value should be appropriately configured.

ACCESS CONTROL

Keep Alive Timeout setting value should be appropriately configured.

ACCESS CONTROL

Latest Patches/Fixes should be installed

SYSTEM AND INFORMATION INTEGRITY

Limit HTTP methods allowed by the Web Server.

CONFIGURATION MANAGEMENT

Logging Directives should be restricted to authorized users. - 'CustomLog logs/access_log combined'

AUDIT AND ACCOUNTABILITY

Logging Directives should be restricted to authorized users. - 'ErrorLog logs/error_log'

AUDIT AND ACCOUNTABILITY

Logging Directives should be restricted to authorized users. - 'LogFormat'

AUDIT AND ACCOUNTABILITY

Logging Directives should be restricted to authorized users. - 'LogLevel notice'

AUDIT AND ACCOUNTABILITY

Logs containing auditing information should be secured at the directory level.

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

MaxClients parameter value should be configured to appropriate value.

SYSTEM AND COMMUNICATIONS PROTECTION

MaxKeepAliveRequests parameter value should be appropriately configured.

SYSTEM AND COMMUNICATIONS PROTECTION

MaxSpareServers parameter value should be appropriately configured.

SYSTEM AND COMMUNICATIONS PROTECTION

MinSpareServers parameter value should be appropriately configured.

SYSTEM AND COMMUNICATIONS PROTECTION

Non-Essential modules should be disabled. 'mod_autoindex'

CONFIGURATION MANAGEMENT

Non-Essential modules should be disabled. 'mod_dav'

CONFIGURATION MANAGEMENT

Non-Essential modules should be disabled. 'mod_include'

CONFIGURATION MANAGEMENT

Non-Essential modules should be disabled. 'mod_info'

CONFIGURATION MANAGEMENT

Non-Essential modules should be disabled. 'mod_status'

CONFIGURATION MANAGEMENT

Non-Essential modules should be disabled. 'mod_userdir'

CONFIGURATION MANAGEMENT

Server version information parameters should be turned off - 'ServerSignature Off'

SYSTEM AND COMMUNICATIONS PROTECTION

Server version information parameters should be turned off - 'ServerTokens Prod'

SYSTEM AND COMMUNICATIONS PROTECTION

StartServers parameter value should be appropriately configured.

SYSTEM AND COMMUNICATIONS PROTECTION

Timeout value parameter value should be appropriately configured

ACCESS CONTROL

TNS_IBM_HTTP_Server_Best_Practice.audit
User IDs which disclose the privileges associated with it, should not be created.

ACCESS CONTROL