STIGQter STIGQter: STIG Summary:

Apache Server 2.4 UNIX Site Security Technical Implementation Guide

Version: 2

Release: 7 Benchmark Date: 01 Jul 2026

CheckedNameTitle
☐SV-214280r960963_ruleThe Apache web server must not perform user management for hosted applications.
☐SV-214282r960963_ruleThe Apache web server must allow mappings to unused and vulnerable scripts to be removed.
☐SV-214284r960963_ruleUsers and scripts running on behalf of users must be contained to the document root or home directory tree of the Apache web server.
☐SV-214286r1051289_ruleThe Apache web server must perform RFC 5280-compliant certification path validation.
☐SV-214287r961041_ruleOnly authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.
☐SV-214288r1211011_ruleCookies exchanged between the Apache web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating Apache web server and hosted application.
☐SV-214289r961122_ruleThe Apache web server must augment re-creation to a stable and known baseline.
☐SV-214290r961131_ruleThe Apache web server document directory must be in a separate partition from the Apache web servers system files.
☐SV-214292r961167_ruleThe Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.
☐SV-214296r1043182_ruleThe Apache web server must set an inactive timeout for sessions.
☐SV-214297r961278_ruleThe Apache web server must restrict inbound connections from nonsecure zones.
☐SV-214298r961353_ruleNon-privileged accounts on the hosting system must only access Apache web server security-relevant information and functions through a distinct administrative account.
☐SV-214300r1051295_ruleThe Apache web server must only accept client certificates issued by DOD PKI or DoD-approved PKI Certification Authorities (CAs).
☐SV-214301r961632_ruleThe Apache web server cookies, such as session cookies, sent to the client using SSL/TLS must not be compressed.
☐SV-214303r961632_ruleCookies exchanged between the Apache web server and the client, such as session cookies, must have cookie properties set to force the encryption of cookies.
☐SV-214304r1211013_ruleThe Apache web server must prohibit or restrict the use of nonsecure or unnecessary ports, protocols, modules, and/or services.