UCF STIG Viewer Logo

OHS must have the HostnameLookups directive enabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-64635 OH12-1X-000198 SV-79125r1_rule Low
Description
Setting the "HostnameLookups" to "On" allows for more information to be logged in the event of an attack and subsequent investigation. This information can be added to other information gathered to narrow the attacker location. The DNS name can also be used for filtering access to the OHS hosted applications by denying particular types of hostnames.
STIG Date
Oracle HTTP Server 12.1.3 Security Technical Implementation Guide 2020-06-12

Details

Check Text ( C-65377r1_chk )
1. Open $DOMAIN_HOME/config/fmwconfig/components/OHS//httpd.conf and every .conf file (e.g., ssl.conf) included in it with an editor.

2. Search for the "HostnameLookups" directive at the server, virtual host, and directory configuration scopes.

3. If the "HostnameLookups" directive is omitted or is not set to "On", this is a finding.
Fix Text (F-70565r1_fix)
1. Open $DOMAIN_HOME/config/fmwconfig/components/OHS//httpd.conf and every .conf file (e.g., ssl.conf) included in it with an editor.

2. Search for the "HostnameLookups" directive at the server, virtual host, and directory configuration scopes.

3. Set the "HostnameLookups" directive to "On", add the directive if it does not exist.