TNS IBM HTTP Server Best Practice

Audit Details

Name: TNS IBM HTTP Server Best Practice

Updated: 6/17/2024

Authority: IBM

Plugin: Windows

Revision: 1.16

Estimated Item Count: 44

File Details

Filename: TNS_IBM_HTTP_Server_Best_Practice.audit

Size: 67.9 kB

MD5: a9509cefb0a5469096ecbe7be09ccd97
SHA256: 1bac2a17f20209dc5983a9bc6714c80d613cc8a54b8506d4186df86f8bf215a3

Audit Items

DescriptionCategories
Buffer overflow protection should be configured 'LimitRequestBody'

SYSTEM AND COMMUNICATIONS PROTECTION

Buffer overflow protection should be configured 'LimitRequestFields'

SYSTEM AND COMMUNICATIONS PROTECTION

Buffer overflow protection should be configured 'LimitRequestFieldsize'

SYSTEM AND COMMUNICATIONS PROTECTION

Buffer overflow protection should be configured 'LimitRequestline'

SYSTEM AND COMMUNICATIONS PROTECTION

CGI-BIN directory should be disabled. 'Addmodule mod_cgi.c'

CONFIGURATION MANAGEMENT

CGI-BIN directory should be disabled. 'AddModule mod_env.c'

CONFIGURATION MANAGEMENT

CGI-BIN directory should be disabled. 'Directory'

CONFIGURATION MANAGEMENT

CGI-BIN directory should be disabled. 'LoadModule cgi_module'

CONFIGURATION MANAGEMENT

CGI-BIN directory should be disabled. 'LoadModule env_module'

CONFIGURATION MANAGEMENT

CGI-BIN directory should be disabled. 'ScriptAlias'

CONFIGURATION MANAGEMENT

Configuration files should be secured against unauthorized access.
Directory access permissions should be restricted.

ACCESS CONTROL

File permissions in the root document should only be accessible by administrator
HTTP TRACE method should be disabled. 'RewriteCond'

CONFIGURATION MANAGEMENT

HTTP TRACE method should be disabled. 'RewriteEngine'

CONFIGURATION MANAGEMENT

HTTP TRACE method should be disabled. 'RewriteLog'

AUDIT AND ACCOUNTABILITY

HTTP TRACE method should be disabled. 'RewriteLogLevel'

AUDIT AND ACCOUNTABILITY

HTTP TRACE method should be disabled. 'RewriteRule'

CONFIGURATION MANAGEMENT

HTTP TRACE method should be disabled. 'TraceEnable'

CONFIGURATION MANAGEMENT

Keep Alive setting parameter value should be appropriately configured.

ACCESS CONTROL

Keep Alive Timeout setting value should be appropriately configured.

ACCESS CONTROL

Latest Patches/Fixes should be installed

SYSTEM AND INFORMATION INTEGRITY

Limit HTTP methods allowed by the Web Server.

CONFIGURATION MANAGEMENT

Logging Directives should be restricted to authorized users. - 'CustomLog logs/access_log combined'

AUDIT AND ACCOUNTABILITY

Logging Directives should be restricted to authorized users. - 'ErrorLog logs/error_log'

AUDIT AND ACCOUNTABILITY

Logging Directives should be restricted to authorized users. - 'LogFormat'

AUDIT AND ACCOUNTABILITY

Logging Directives should be restricted to authorized users. - 'LogLevel notice'

AUDIT AND ACCOUNTABILITY

Logs containing auditing information should be secured at the directory level.

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

MaxClients parameter value should be configured to appropriate value.

SYSTEM AND COMMUNICATIONS PROTECTION

MaxKeepAliveRequests parameter value should be appropriately configured.

SYSTEM AND COMMUNICATIONS PROTECTION

MaxSpareServers parameter value should be appropriately configured.

SYSTEM AND COMMUNICATIONS PROTECTION

MinSpareServers parameter value should be appropriately configured.

SYSTEM AND COMMUNICATIONS PROTECTION

Non-Essential modules should be disabled. 'mod_autoindex'

CONFIGURATION MANAGEMENT

Non-Essential modules should be disabled. 'mod_dav'

CONFIGURATION MANAGEMENT

Non-Essential modules should be disabled. 'mod_include'

CONFIGURATION MANAGEMENT

Non-Essential modules should be disabled. 'mod_info'

CONFIGURATION MANAGEMENT

Non-Essential modules should be disabled. 'mod_status'

CONFIGURATION MANAGEMENT

Non-Essential modules should be disabled. 'mod_userdir'

CONFIGURATION MANAGEMENT

Server version information parameters should be turned off - 'ServerSignature Off'

SYSTEM AND COMMUNICATIONS PROTECTION

Server version information parameters should be turned off - 'ServerTokens Prod'

SYSTEM AND COMMUNICATIONS PROTECTION

StartServers parameter value should be appropriately configured.

SYSTEM AND COMMUNICATIONS PROTECTION

Timeout value parameter value should be appropriately configured

ACCESS CONTROL

TNS_IBM_HTTP_Server_Best_Practice.audit
User IDs which disclose the privileges associated with it, should not be created.

ACCESS CONTROL