Skip to content

The Apache web server must prohibit or restrict the use of nonsecure or unnecessary ports, protocols, modules, and/or services.

An XCCDF Rule

Description

Web servers provide numerous processes, features, and functionalities that use TCP/IP ports. Some of these processes may be deemed unnecessary or too unsecure to run on a production system. The web server must provide the capability to disable or deactivate network-related services that are deemed to be non-essential to the server mission, are too unsecure, or are prohibited by the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL) and vulnerability assessments.

ID
SV-214390r400015_rule
Version
AS24-W2-000780
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Ensure the website enforces the use of IANA well-known ports for HTTP and HTTPS.