STIGQter STIGQter: STIG Summary: APACHE 2.2 Server for UNIX Security Technical Implementation Guide Version: 1 Release: 11 Benchmark Date: 25 Jan 2019:

The TRACE method must be disabled.

DISA Rule

SV-33227r1_rule

Vulnerability Number

V-26325

Group Title

WA00550

Rule Version

WA00550 A22

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Edit the httpd.conf file and add or set the value of EnableTrace to "Off".

Check Contents

Enter the following command:

grep "TraceEnable" /usr/local/apache2/conf/httpd.conf.

Review the results for the following directive:

TraceEnable.

For any enabled TraceEnable directives ensure they are part of the server level configuration (i.e. not nested in a <Directory> or <Location> directive). Also ensure that the TraceEnable directive is set to “Off”.

If the TraceEnable directive is not part of the server level configuration and/or is not set to “Off”, this is a finding.

If the directive does not exist in the conf file, this is a finding because the default value is "On".

Vulnerability Number

V-26325

Documentable

False

Rule Version

WA00550 A22

Severity Override Guidance

Enter the following command:

grep "TraceEnable" /usr/local/apache2/conf/httpd.conf.

Review the results for the following directive:

TraceEnable.

For any enabled TraceEnable directives ensure they are part of the server level configuration (i.e. not nested in a <Directory> or <Location> directive). Also ensure that the TraceEnable directive is set to “Off”.

If the TraceEnable directive is not part of the server level configuration and/or is not set to “Off”, this is a finding.

If the directive does not exist in the conf file, this is a finding because the default value is "On".

Check Content Reference

M

Responsibility

Web Administrator

Target Key

158

Comments