OH12-1X-000198 - OHS must have the HostnameLookups directive enabled.

Information

Setting the 'HostnameLookups' to 'On' allows for more information to be logged in the event of an attack and subsequent investigation. This information can be added to other information gathered to narrow the attacker location. The DNS name can also be used for filtering access to the OHS hosted applications by denying particular types of hostnames.

Solution

1. Open $DOMAIN_HOME/config/fmwconfig/components/OHS/<componentName>/httpd.conf and every .conf file (e.g., ssl.conf) included in it with an editor.

2. Search for the 'HostnameLookups' directive at the server, virtual host, and directory configuration scopes.

3. Set the 'HostnameLookups' directive to 'On', add the directive if it does not exist.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_HTTP_Server_12-1-3_V2R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-221436r879887_rule, STIG-ID|OH12-1X-000198, STIG-Legacy|SV-79125, STIG-Legacy|V-64635, Vuln-ID|V-221436

Plugin: Unix

Control ID: 9dd01a0c8cf6a22f901a6e84db2f412a00671ce2c326cd3fc7018e04ae581841