Skip to content

Set httpd ServerTokens Directive to Prod

An XCCDF Rule

Description

ServerTokens Prod restricts information in page headers, returning only the word "Apache."

Add or correct the following directive in /etc/httpd/conf/httpd.conf:

ServerTokens Prod

Rationale

Information disclosed to clients about the configuration of the web server and system could be used to plan an attack on the given system. This information disclosure should be restricted to a minimum.

ID
xccdf_org.ssgproject.content_rule_httpd_servertokens_prod
Severity
Unknown
References
Updated