UCF STIG Viewer Logo

APACHE 2.2 Site for UNIX Security Technical Implementation Guide


Overview

Date Finding Count (29)
2019-01-07 CAT I (High): 4 CAT II (Med): 21 CAT III (Low): 4
STIG Description
All directives specified in this STIG must be specifically set (i.e. the server is not allowed to revert to programmed defaults for these directives). Included files should be reviewed if they are used. Procedures for reviewing included files are included in the overview document. The use of .htaccess files are not authorized for use according to the STIG. However, if they are used, there are procedures for reviewing them in the overview document. The Web Policy STIG should be used in addition to the Apache Site and Server STIGs in order to do a comprehensive web server review.

Available Profiles



Findings (MAC III - Administrative Classified)

Finding ID Severity Title
V-2258 High Web client access to the content directories must be restricted to read and execute.
V-2249 High Web server administration must be performed over a secure path or at the local console.
V-13686 High Web Administrators must only use encrypted connections for Document Root directory uploads.
V-2227 High Symbolic links must not be used in the web content directory tree.
V-13694 Medium Public web servers must use TLS if authentication is required.
V-26279 Medium Error logging must be enabled.
V-2270 Medium Anonymous FTP user access to interactive scripts is prohibited.
V-2254 Medium Only web sites that have been fully reviewed and tested must exist on a production web server.
V-2252 Medium Log file access must be restricted to System Administrators, Web Administrators or Auditors.
V-2250 Medium Logs of web server access and errors must be established and maintained
V-13687 Medium Remote authors or content providers must have all files scanned for viruses and malicious code before uploading files to the Document Root directory.
V-6531 Medium Private web servers must require certificates issued from a DoD-authorized Certificate Authority.
V-13688 Medium Log file data must contain required data elements.
V-3333 Medium The web document (home) directory must be in a separate partition from the web server’s system files.
V-13689 Medium Access to the web server log files must be restricted to administrators, web administrators, and auditors.
V-2272 Medium PERL scripts must use the TAINT option.
V-2228 Medium All interactive programs (CGI) must be placed in a designated directory with appropriate permissions.
V-2263 Medium A private web server will have a valid DoD server certificate.
V-2262 Medium A private web server must utilize an approved TLS version.
V-2260 Medium A web site must not contain a robots.txt file.
V-2226 Medium Web content directories must not be anonymously shared.
V-26280 Medium The sites error logs must log the correct format.
V-26281 Medium System logging must be enabled.
V-26282 Medium The LogLevel directive must be enabled.
V-2240 Medium The number of allowed simultaneous requests must be set.
V-15334 Low Web sites must utilize ports, protocols, and services according to PPSM guidelines.
V-2265 Low Java software on production web servers must be limited to class files and the JAVA virtual machine.
V-6373 Low The required DoD banner page must be displayed to authenticated users accessing a DoD private website.
V-2245 Low Each readable web document directory must contain either a default, home, index, or equivalent file.