DISA STIG Apache Server 2.2 Unix v1r11

Audit Details

Name: DISA STIG Apache Server 2.2 Unix v1r11

Updated: 10/15/2024

Authority: DISA STIG

Plugin: Unix

Revision: 1.13

Estimated Item Count: 84

File Details

Filename: DISA_STIG_Apache_Server-2.2_Unix_v1r11.audit

Size: 146 kB

MD5: 56c3b867c6597a50a37243bf2cb0c5d1
SHA256: d88f29bdf49b9213ad1f831318e7754b20d1d5c3efbf48133df5b3379cce0184

Audit Changelog

 
Revision 1.13

Oct 15, 2024

Miscellaneous
  • References updated.
  • Variables updated.
Added
  • WG040 A22 - Public web server resources must not be shared with private assets.
  • WG420 A22 - Backup interactive scripts on the production web server are prohibited.
Removed
  • WG040 A22 - Public web server resources must not be shared with private assets - .netrc
  • WG040 A22 - Public web server resources must not be shared with private assets - .rhosts
  • WG040 A22 - Public web server resources must not be shared with private assets - Systems
  • WG040 A22 - Public web server resources must not be shared with private assets - exports
  • WG040 A22 - Public web server resources must not be shared with private assets - hosts.equiv
  • WG040 A22 - Public web server resources must not be shared with private assets - hosts.lpd
  • WG040 A22 - Public web server resources must not be shared with private assets - mnttab
  • WG040 A22 - Public web server resources must not be shared with private assets - sharetab
  • WG080 A22 - Installation of a compiler on production web server is prohibited - gcc
  • WG080 A22 - Installation of a compiler on production web server is prohibited - javac
  • WG080 A22 - Installation of a compiler on production web server is prohibited - jdk
  • WG420 A22 - Backup interactive scripts on the production web server are prohibited - ??0
  • WG420 A22 - Backup interactive scripts on the production web server are prohibited - backup
  • WG420 A22 - Backup interactive scripts on the production web server are prohibited - bak
  • WG420 A22 - Backup interactive scripts on the production web server are prohibited - old
  • WG420 A22 - Backup interactive scripts on the production web server are prohibited - tmp
Revision 1.12

Jun 17, 2024

Miscellaneous
  • Metadata updated.
Revision 1.11

Nov 1, 2023

Miscellaneous
  • Platform check updated.
  • References updated.
Revision 1.10

Apr 12, 2023

Miscellaneous
  • Metadata updated.
  • Platform check updated.
  • Variables updated.
Revision 1.9

Mar 7, 2023

Miscellaneous
  • Metadata updated.
  • References updated.
  • Variables updated.
Revision 1.8

Dec 7, 2022

Functional Update
  • WA00565 A22 - HTTP request methods must be limited - LimitExcept
  • WA00565 A22 - HTTP request methods must be limited - Order
Miscellaneous
  • References updated.
  • Variables updated.
Added
  • WG280 - The access control files are owned by a privileged web server account - HTACCESS_DIR
  • WG280 - The access control files are owned by a privileged web server account - HTTPD_CONFIG_DIRECTORY/httpd.conf
Removed
  • WG280 - The access control files are owned by a privileged web server account - @HTACCESS_DIR@
  • WG280 - The access control files are owned by a privileged web server account - @HTTPD_CONFIG_DIRECTORY@/httpd.conf
Revision 1.7

Apr 25, 2022

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.6

Jul 30, 2021

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.5

Jun 17, 2021

Miscellaneous
  • Metadata updated.
Revision 1.4

Mar 23, 2021

Miscellaneous
  • Metadata updated.
  • References updated.