Skip to content

Apache Server 2.4 UNIX Site Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000001-WSR-000002

    Group
  • SRG-APP-000014-WSR-000006

    Group
  • The Apache web server must use encryption strength in accordance with the categorization of data hosted by the Apache web server when remote connections are provided.

    The Apache web server has several remote communications channels. Examples are user requests via http/https, communication to a backend database, and communication to authenticate users. The encryp...
    Rule Medium Severity
  • SRG-APP-000095-WSR-000056

    Group
  • SRG-APP-000141-WSR-000015

    Group
  • SRG-APP-000141-WSR-000081

    Group
  • SRG-APP-000141-WSR-000082

    Group
  • The Apache web server must allow mappings to unused and vulnerable scripts to be removed.

    Scripts allow server-side processing on behalf of the hosted application user or as processes needed in the implementation of hosted applications. Removing scripts not needed for application operat...
    Rule Medium Severity
  • SRG-APP-000141-WSR-000083

    Group
  • SRG-APP-000141-WSR-000087

    Group
  • Users and scripts running on behalf of users must be contained to the document root or home directory tree of the Apache web server.

    A web server is designed to deliver content and execute scripts or applications on the request of a client or user. Containing user requests to files in the directory tree of the hosted web applica...
    Rule Medium Severity
  • SRG-APP-000142-WSR-000089

    Group
  • SRG-APP-000175-WSR-000095

    Group
  • The Apache web server must perform RFC 5280-compliant certification path validation.

    A certificate's certification path is the path from the end entity certificate to a trusted root certification authority (CA). Certification path validation is necessary for a relying party to make...
    Rule Medium Severity
  • SRG-APP-000176-WSR-000096

    Group
  • SRG-APP-000223-WSR-000011

    Group
  • Cookies exchanged between the Apache web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating Apache web server and hosted application.

    Cookies are used to exchange data between the web server and the client. Cookies, such as a session cookie, may contain session information and user credentials used to maintain a persistent connec...
    Rule Medium Severity
  • SRG-APP-000225-WSR-000074

    Group
  • The Apache web server must augment re-creation to a stable and known baseline.

    Making certain that the web server has not been updated by an unauthorized user is always a concern. Adding patches, functions, and modules that are untested and not part of the baseline opens the ...
    Rule Medium Severity
  • SRG-APP-000233-WSR-000146

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules