Skip to content
Catalogs
XCCDF
Apache Server 2.4 UNIX Server Security Technical Implementation Guide
SRG-APP-000340-WSR-000029
Non-privileged accounts on the hosting system must only access Apache web server security-relevant information and functions through a distinct administrative account.
Non-privileged accounts on the hosting system must only access Apache web server security-relevant information and functions through a distinct administrative account. An XCCDF Rule
Non-privileged accounts on the hosting system must only access Apache web server security-relevant information and functions through a distinct administrative account.
Medium Severity
<VulnDiscussion>By separating Apache web server security functions from non-privileged users, roles can be developed that can then be used to administer the Apache web server. Forcing users to change from a non-privileged account to a privileged account when operating on the Apache web server or on security-relevant information forces users to only operate as a Web Server Administrator when necessary. Operating in this manner allows for better logging of changes and better forensic information and limits accidental changes to the Apache web server.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>