Skip to content

Set httpd ServerSignature Directive to Off

An XCCDF Rule

Description

ServerSignature Off restricts httpd from displaying server version number on error pages.

Add or correct the following directive in /etc/httpd/conf/httpd.conf:

ServerSignature Off

Rationale

Information disclosed to clients about the configuration of the web server and system could be used to plan an attack on the given system. This information disclosure should be restricted to a minimum.

ID
xccdf_org.ssgproject.content_rule_httpd_serversignature_off
Severity
Unknown
References
Updated