3.4 Ensure Apache Directories and Files Are Owned By Root

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The Apache directories and files should be owned by 'root'. This applies to all of the Apache software directories and files installed.

Rationale:

Restricting ownership of the Apache files and directories will reduce the probability of unauthorized modifications to those resources.

Solution

Perform the following:

Set ownership on the '$APACHE_PREFIX' directories such as '/usr/local/apache2':

$ chown -R root $APACHE_PREFIX

See Also

https://workbench.cisecurity.org/files/2381

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|5.1, CSCv7|14.6

Plugin: Unix

Control ID: 24c238d6b988702daa12d2156884c905e0ab8db367b6f12b9fcc70c1166ad837