From 2a463b3cd73c32ee9dcd508248d0194923f435f4 Mon Sep 17 00:00:00 2001 From: Stefan Fritsch Date: Sat, 29 Mar 2014 21:56:19 +0100 Subject: Imported Upstream version 2.4.9 --- docs/manual/misc/security_tips.html.en | 28 ++++++++++------------------ 1 file changed, 10 insertions(+), 18 deletions(-) (limited to 'docs/manual/misc/security_tips.html.en') diff --git a/docs/manual/misc/security_tips.html.en b/docs/manual/misc/security_tips.html.en index 647e5647..192d7bc1 100644 --- a/docs/manual/misc/security_tips.html.en +++ b/docs/manual/misc/security_tips.html.en @@ -9,7 +9,7 @@ - @@ -334,11 +334,9 @@

In the server configuration file, put

-
-<Directory />
+    
<Directory />
     AllowOverride None
-</Directory>
-    
+</Directory>

This prevents the use of .htaccess files in all @@ -366,25 +364,21 @@ work around this, add the following block to your server's configuration:

-
-<Directory />
+    
<Directory />
     Require all denied
-</Directory>
-    
+</Directory>

This will forbid default access to filesystem locations. Add appropriate Directory blocks to allow access only in those areas you wish. For example,

-
-<Directory /usr/users/*/public_html>
+    
<Directory /usr/users/*/public_html>
     Require all granted
 </Directory>
 <Directory /usr/local/httpd>
     Require all granted
-</Directory>
-    
+</Directory>

Pay particular attention to the interactions of Location and Directory directives; for instance, even @@ -441,11 +435,9 @@ you probably commented out the following in your server configuration file:

-
-<Files ".ht*">
+    
<Files ".ht*">
     Require all denied
-</Files>
-    
+</Files>
top
@@ -487,7 +479,7 @@ var comments_identifier = 'http://httpd.apache.org/docs/2.4/misc/security_tips.h } })(window, document); //-->