SV-36672r1_rule
V-6724
WG520
WG520 A22
CAT III
10
Edit the /usr/local/apache2/conf/httpd.conf file and ensure the directive is set to Prod.
Enter the following command:
grep "ServerTokens" /usr/local/apache2/conf/httpd.conf
The directive ServerTokens must be set to “Prod” (ex. ServerTokens Prod). This directive controls whether Server response header field that is sent back to clients that includes a description of the OS-type of the server as well as information about compiled-in modules.
If the web server or operating system information are sent to the client via the server response header or the directive does not exist, this is a finding.
Note: The default value is set to Full.
V-6724
False
WG520 A22
Enter the following command:
grep "ServerTokens" /usr/local/apache2/conf/httpd.conf
The directive ServerTokens must be set to “Prod” (ex. ServerTokens Prod). This directive controls whether Server response header field that is sent back to clients that includes a description of the OS-type of the server as well as information about compiled-in modules.
If the web server or operating system information are sent to the client via the server response header or the directive does not exist, this is a finding.
Note: The default value is set to Full.
M
Web Administrator
158