Set httpd ServerTokens Directive to Prod
An XCCDF Rule
Description
ServerTokens Prod
restricts information in page headers, returning only the word "Apache."
Add or correct the following directive in /etc/httpd/conf/httpd.conf
:
ServerTokens Prod
Rationale
Information disclosed to clients about the configuration of the web server and system could be used to plan an attack on the given system. This information disclosure should be restricted to a minimum.
- ID
- xccdf_org.ssgproject.content_rule_httpd_servertokens_prod
- Severity
- Unknown
- References
- Updated