Set httpd ServerSignature Directive to Off
An XCCDF Rule
Description
ServerSignature Off
restricts httpd
from displaying server version number
on error pages.
Add or correct the following directive in /etc/httpd/conf/httpd.conf
:
ServerSignature Off
Rationale
Information disclosed to clients about the configuration of the web server and system could be used to plan an attack on the given system. This information disclosure should be restricted to a minimum.
- ID
- xccdf_org.ssgproject.content_rule_httpd_serversignature_off
- Severity
- Unknown
- References
- Updated