Details
In order to serve Web content, either the Apache Allow directive or the Require directive will need to be used to allow for appropriate access to directories, locations and virtual hosts that contain web content.
Rationale:
Either the Allow or Require directives may be used within a directory, a location or other context to allow appropriate access. Access may be allowed to all, or to specific networks, or hosts, or users as appropriate. The Allow/Deny/Order directives are deprecated and should be replaced by the Require directive. It is also recommended that either the Allow directive or the Require directive be used, but not both in the same context.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Perform the following to implement the recommended state:
Search the Apache configuration files (httpd.conf and any included configuration files) to find all
Include the appropriate Require directives, with values that are appropriate for the purposes of the directory.
The configurations below are just a few possible examples.
Require ip 192.169.
Require all granted
Require local
Require valid-user
Default Value:
The following is the default Web root directory configuration:
. . .
Require all granted
. . .
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: Access Control.This control applies to the following type of system Unix.