1. Home
  2. Security Hardening
  3. DISA STIG Apache Site 2.2 Unix V1R11 Middleware
  4. WG235 A22 – Web Administrators must only use encrypted connections for Document Root directory uploads.

WG235 A22 – Web Administrators must only use encrypted connections for Document Root directory uploads.

Details

Logging in to a web server via an unencrypted protocol or service, to upload documents to the web site, is a risk if proper encryption is not utilized to protect the data being transmitted. An encrypted protocol or service must be used for remote access to web administration tasks.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Use only secure encrypted logons and connections for uploading files to the web site.

Supportive Information

The following resource is also helpful.

This control applies to the following type of system Unix.

References

  • CAT|I
  • Rule-ID|SV-33024r1_rule
  • STIG-ID|WG235_A22
  • Vuln-ID|V-13686

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles