SV-214301r612241_rule
V-214301
SRG-APP-000439-WSR-000153
AS24-U2-000870
CAT II
10
Determine the location of the "HTTPD_ROOT" directory and the "httpd.conf" file:
# httpd -V | egrep -i 'httpd_root|server_config_file'
-D HTTPD_ROOT="/etc/httpd"
-D SERVER_CONFIG_FILE="conf/httpd.conf"
Ensure the "SSLCompression" is added and looks like the following:
SSLCompression off
Restart Apache: apachectl restart
In a command line, run "httpd -M | grep -i ssl_module".
If "ssl_module" is not listed, this is a finding.
Determine the location of the "HTTPD_ROOT" directory and the "httpd.conf" file:
# httpd -V | egrep -i 'httpd_root|server_config_file'
-D HTTPD_ROOT="/etc/httpd"
-D SERVER_CONFIG_FILE="conf/httpd.conf"
If the "SSLCompression" directive does not exist or is set to "on", this is a finding.
V-214301
False
AS24-U2-000870
In a command line, run "httpd -M | grep -i ssl_module".
If "ssl_module" is not listed, this is a finding.
Determine the location of the "HTTPD_ROOT" directory and the "httpd.conf" file:
# httpd -V | egrep -i 'httpd_root|server_config_file'
-D HTTPD_ROOT="/etc/httpd"
-D SERVER_CONFIG_FILE="conf/httpd.conf"
If the "SSLCompression" directive does not exist or is set to "on", this is a finding.
M
3997