Apache Server 2.4 UNIX Site Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-APP-000001-WSR-000002
Group -
SRG-APP-000014-WSR-000006
Group -
The Apache web server must use encryption strength in accordance with the categorization of data hosted by the Apache web server when remote connections are provided.
The Apache web server has several remote communications channels. Examples are user requests via http/https, communication to a backend database, and communication to authenticate users. The encryp...Rule Medium Severity -
SRG-APP-000095-WSR-000056
Group -
SRG-APP-000141-WSR-000015
Group -
SRG-APP-000141-WSR-000081
Group -
SRG-APP-000141-WSR-000082
Group -
The Apache web server must allow mappings to unused and vulnerable scripts to be removed.
Scripts allow server-side processing on behalf of the hosted application user or as processes needed in the implementation of hosted applications. Removing scripts not needed for application operat...Rule Medium Severity -
SRG-APP-000141-WSR-000083
Group -
SRG-APP-000141-WSR-000087
Group -
Users and scripts running on behalf of users must be contained to the document root or home directory tree of the Apache web server.
A web server is designed to deliver content and execute scripts or applications on the request of a client or user. Containing user requests to files in the directory tree of the hosted web applica...Rule Medium Severity -
SRG-APP-000142-WSR-000089
Group -
SRG-APP-000175-WSR-000095
Group -
The Apache web server must perform RFC 5280-compliant certification path validation.
A certificate's certification path is the path from the end entity certificate to a trusted root certification authority (CA). Certification path validation is necessary for a relying party to make...Rule Medium Severity -
SRG-APP-000176-WSR-000096
Group -
SRG-APP-000223-WSR-000011
Group -
Cookies exchanged between the Apache web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating Apache web server and hosted application.
Cookies are used to exchange data between the web server and the client. Cookies, such as a session cookie, may contain session information and user credentials used to maintain a persistent connec...Rule Medium Severity -
SRG-APP-000225-WSR-000074
Group -
The Apache web server must augment re-creation to a stable and known baseline.
Making certain that the web server has not been updated by an unauthorized user is always a concern. Adding patches, functions, and modules that are untested and not part of the baseline opens the ...Rule Medium Severity -
SRG-APP-000233-WSR-000146
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.