Apache 2.2.16

General Discussion of atomic repo and development projects.

Ask for help here with anything else not covered by other forums.
daffoml
Forum User
Forum User
Posts: 7
Joined: Tue May 05, 2009 11:02 am

Apache 2.2.16

Unread post by daffoml »

I need to pass a PCI audit, and it is failing on my apache version, I have 2.2.3-43.el5.centos

Is there an atomic version of the latest, or is that not in the atomic repo?

This is a Cent 5.5 / Plesk 9.52 system, by the way.

The PCI audit wants to see 2.2.15

Thanks
scott
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 8355
Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:

Re: Apache 2.2.16

Unread post by scott »

That is a false positive, you can refer them to this: http://www.redhat.com/security/updates/ ... c_cid=3093

That being said, we're considering adding httpd to the repo.
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Apache 2.2.16

Unread post by mikeshinn »

Also, if you are running ASL it will not report the apache version to the scanner so you wont run into this problem with PCI-DSS scanners and will pass.
daffoml
Forum User
Forum User
Posts: 7
Joined: Tue May 05, 2009 11:02 am

Re: Apache 2.2.16

Unread post by daffoml »

mikeshinn wrote:Also, if you are running ASL it will not report the apache version to the scanner so you wont run into this problem with PCI-DSS scanners and will pass.
I thought I had that set in the httpd.conf by using the ServerSignature Off.
daffoml
Forum User
Forum User
Posts: 7
Joined: Tue May 05, 2009 11:02 am

Re: Apache 2.2.16

Unread post by daffoml »

scott wrote:That is a false positive, you can refer them to this: http://www.redhat.com/security/updates/ ... c_cid=3093
Thank you, I will try that route.
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Apache 2.2.16

Unread post by mikeshinn »

I believe ServerSignature Off. doesnt actually hide the version or if it does, it doesnt do it very well.
Post Reply