Member-only story

Security Settings for Apache Web Server.

Maciej
7 min readOct 28, 2020

--

Overview

In this article I would like to summarized the security settings that can be shared for Apache settings and their items.

Example settings:

[root@server vagrant]# cat /etc/httpd/conf.d/security.confServerTokens Prod  #version information
Header unset "X-Powered-By"
RequestHeader unset Proxy #httpoxy CountermeasureHeader append X-Frame-Options SAMEORIGIN #Clickjacking CountermeasureHeader set X-XSS-Protection "1; mode=block" #XSS Countermeasur
Header set X-Content-Type-Options nosniff
TraceEnable Off #XST Countermeasure<Directory /var/www/html>AllowOverride AllOptions -Indexes #Prohibit file list output<IfVersion < 2.3> # Apache 2.2 or earlier countermeasuresServerSignature Off #Hide version informationFileETag MTime Size # ETag inode information Hidden
</IfVersion>
</Directory>
<Directory "/var/www/cgi-bin">
<IfVersion < 2.3>
ServerSignature Off
FileETag MTime Size
</IfVersion>
</Directory>

--

--

Maciej
Maciej

Written by Maciej

DevOps Consultant. I’m strongly focused on automation, security, and reliability.

No responses yet