STIGQter STIGQter: STIG Summary:

Apache Server 2.4 UNIX Site Security Technical Implementation Guide

Version: 2

Release: 7 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-214280r960963_ruleThe Apache web server must not perform user management for hosted applications.
SV-214282r960963_ruleThe Apache web server must allow mappings to unused and vulnerable scripts to be removed.
SV-214284r960963_ruleUsers and scripts running on behalf of users must be contained to the document root or home directory tree of the Apache web server.
SV-214286r1051289_ruleThe Apache web server must perform RFC 5280-compliant certification path validation.
SV-214287r961041_ruleOnly authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.
SV-214288r1211011_ruleCookies exchanged between the Apache web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating Apache web server and hosted application.
SV-214289r961122_ruleThe Apache web server must augment re-creation to a stable and known baseline.
SV-214290r961131_ruleThe Apache web server document directory must be in a separate partition from the Apache web servers system files.
SV-214292r961167_ruleThe Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.
SV-214296r1043182_ruleThe Apache web server must set an inactive timeout for sessions.
SV-214297r961278_ruleThe Apache web server must restrict inbound connections from nonsecure zones.
SV-214298r961353_ruleNon-privileged accounts on the hosting system must only access Apache web server security-relevant information and functions through a distinct administrative account.
SV-214300r1051295_ruleThe Apache web server must only accept client certificates issued by DOD PKI or DoD-approved PKI Certification Authorities (CAs).
SV-214301r961632_ruleThe Apache web server cookies, such as session cookies, sent to the client using SSL/TLS must not be compressed.
SV-214303r961632_ruleCookies exchanged between the Apache web server and the client, such as session cookies, must have cookie properties set to force the encryption of cookies.
SV-214304r1211013_ruleThe Apache web server must prohibit or restrict the use of nonsecure or unnecessary ports, protocols, modules, and/or services.