STIGQter STIGQter: STIG Summary: APACHE 2.2 Server for Windows Security Technical Implementation Guide Version: 1 Release: 13 Benchmark Date: 25 Jan 2019:

The KeepAliveTimeout directive must be defined.

DISA Rule

SV-32880r3_rule

Vulnerability Number

V-13726

Group Title

WA000-WWA024

Rule Version

WA000-WWA024 W22

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Modify the KeepAliveTimeout directive in the applicable Apache configuration files to have a value of 15 or less.

Check Contents

NOTE: This setting must be explicitly set.

Locate the Apache httpd.conf file.

Open the httpd.conf file with an editor such as notepad, and search for the following uncommented directive: KeepAliveTimeout

If any directive is not set to 15 or less, this is a finding.

NOTE: This vulnerability can be documented locally with the ISSM/ISSO if the site has an operational reason for not using persistent connections. If the site has this documented, this should be marked as Not a Finding.

Vulnerability Number

V-13726

Documentable

False

Rule Version

WA000-WWA024 W22

Severity Override Guidance

NOTE: This setting must be explicitly set.

Locate the Apache httpd.conf file.

Open the httpd.conf file with an editor such as notepad, and search for the following uncommented directive: KeepAliveTimeout

If any directive is not set to 15 or less, this is a finding.

NOTE: This vulnerability can be documented locally with the ISSM/ISSO if the site has an operational reason for not using persistent connections. If the site has this documented, this should be marked as Not a Finding.

Check Content Reference

M

Responsibility

Web Administrator

Target Key

158

Comments