Remote access to the Apache web server must follow access policy or work in conjunction with enterprise tools designed to enforce policy requirements.

From Apache Server 2.4 UNIX Site Security Technical Implementation Guide

Part of SRG-APP-000315-WSR-000003

Associated with: CCI-002314

AS24-U2-000670_rule Remote access to the Apache web server must follow access policy or work in conjunction with enterprise tools designed to enforce policy requirements.

Vulnerability discussion

Remote access to the Apache web server is any access that communicates through an external, non-organization-controlled network. Remote access can be used to access hosted applications or to perform management functions. The Apache web server can be accessed remotely and must be able to enforce remote access policy requirements or work in conjunction with enterprise tools designed to enforce policy requirements. Examples of the Apache web server enforcing a remote access policy are implementing IP filtering rules, using "https" instead of "http" for communication, implementing secure tokens, and validating users.

Check content

If web administration is performed at the console, this check is Not Applicable. If web administration is performed remotely, the following checks will apply. If administration of the server is performed remotely, it will be performed securely and only by System Administrators. If website administration or web application administration has been delegated, those users will be documented and approved by the Information System Security Officer. Remote administration must be in compliance with any requirements contained within the Windows Server STIGs and any applicable network STIGs. Remote administration of any kind will be restricted to documented and authorized personnel. All users performing remote administration must be authenticated. All remote sessions will be encrypted and they will use FIPS 140-2 approved protocols. FIPS 140-2-approved TLS versions include TLS V1.2 or greater. Review with site management how remote administration, if applicable, is configured on the website. If remote management meets the criteria listed above, this is not a finding. If remote management is used and does not meet the criteria listed above, this is a finding.

Fix text

Ensure the web server administration is performed only over a secure path.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer