SV-33236r2_rule
V-26396
WA00565
WA00565 A22
CAT II
10
Edit the httpd.conf file and add the following entries for every enabled directory except root.
Order allow,deny
<LimitExcept GET POST OPTIONS>
Deny from all
</LimitExcept>
Note: If HTTP commands (GET, PUT, POST, DELETE) are not being used and server is solely configured as a proxy server, this is Not Applicable.
Enter the following command:
more /usr/local/apache2/conf/httpd.conf
For every enabled <Directory> directive (except root), ensure the following entry exists:
Order allow,deny
<LimitExcept GET POST OPTIONS>
Deny from all
</LimitExcept>
If the statement above is found in the root directory statement (i.e. <Directory />), this is a finding.
If the statement above is found enabled but without the appropriate LimitExcept or Order statement, this is a finding.
If the statement is not found inside an enabled <Directory> directive, this is a finding.
Note: If the LimitExcept statement above is operationally limiting. This should be explicitly documented with the Web Manager, at which point this can be considered not a finding.
V-26396
False
WA00565 A22
Note: If HTTP commands (GET, PUT, POST, DELETE) are not being used and server is solely configured as a proxy server, this is Not Applicable.
Enter the following command:
more /usr/local/apache2/conf/httpd.conf
For every enabled <Directory> directive (except root), ensure the following entry exists:
Order allow,deny
<LimitExcept GET POST OPTIONS>
Deny from all
</LimitExcept>
If the statement above is found in the root directory statement (i.e. <Directory />), this is a finding.
If the statement above is found enabled but without the appropriate LimitExcept or Order statement, this is a finding.
If the statement is not found inside an enabled <Directory> directive, this is a finding.
Note: If the LimitExcept statement above is operationally limiting. This should be explicitly documented with the Web Manager, at which point this can be considered not a finding.
M
Web Administrator
158