Ver Fonte

Improve Apache2 security

Emmanuel Bouthenot há 7 anos atrás
pai
commit
65f9e442d5
1 ficheiros alterados com 9 adições e 0 exclusões
  1. 9 0
      roles/webserver/templates/apache2/conf.d/security.j2

+ 9 - 0
roles/webserver/templates/apache2/conf.d/security.j2

@@ -115,6 +115,15 @@ TraceEnable Off
     Header set X-Frame-Options: "sameorigin"
 </IfModule>
 
+#
+# Prevent at least directory listing from everywhere
+#
+<Directory />
+    Options FollowSymLinks
+    AllowOverride None
+    Require all granted
+</Directory>
+
 #
 # Various protections
 #  - stuff that should not be accessible publicly