Email - Apache httpd.conf, webmail
Email Solution · Config document · referenced from Webmail
The global Apache configuration of the webmail server, written from the organisation's unified Apache template. The upper part is the distribution's file with things taken out, the lower part is the hardening block the template adds. The stock comments of the upper part are left out; the hardening part is shown with its comments, which are mine and the template's.
| Item | Value |
|---|---|
| Path on the server | /etc/httpd/conf/httpd.conf |
| Shown here | DC2-A-VCMSX002 |
| Stock file kept as | /etc/httpd/conf/httpd.conf.original |
| Software | Apache HTTP Server 2.4 from RHEL 7, with mod_ssl and PHP 5 as a module |
| Activated with | systemctl start httpd in the install notes |
The file
################################################################################
# Global HTTP configuration
################################################################################
ServerRoot "/etc/httpd"
Include conf.modules.d/*.conf
User apache
Group apache
ServerAdmin shared-infra@example.net
<Directory />
AllowOverride none
Require all denied
</Directory>
<Directory "/var/www">
AllowOverride None
Require all granted
</Directory>
<IfModule dir_module>
DirectoryIndex index.html index.php
</IfModule>
ErrorLog "logs/error_log"
LogLevel warn
<IfModule log_config_module>
LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
LogFormat "%h %l %u %t \"%r\" %>s %b" common
<IfModule logio_module>
LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\" %I %O" combinedio
</IfModule>
CustomLog "logs/access_log" combined
</IfModule>
<IfModule mime_module>
TypesConfig /etc/mime.types
AddType application/x-compress .Z
AddType application/x-gzip .gz .tgz
AddType text/html .shtml
AddOutputFilter INCLUDES .shtml
</IfModule>
AddDefaultCharset UTF-8
<IfModule mime_magic_module>
MIMEMagicFile conf/magic
</IfModule>
# Note: We are on Linux platform = syscall supported.
EnableMMAP on
EnableSendfile on
################################################################################
# Global HTTP configuration - Hardening
################################################################################
#
# The following lines prevent .htaccess and .htpasswd files from being
# viewed by Web clients.
#
<Files ".ht*">
Require all denied
</Files>
#
# Remove server version banner
#
# Note: Server sigranute cannot be removed entirely without using mod_security.
#
ServerTokens Prod
ServerSignature Off
#
# Disable "ETag"
#
# ETags (entity tags) are a well-known point of vulnerability in Apache web server.
# ETag is an HTTP response header that allows remote users to obtain sensitive information
# like inode number, child process ids, and multipart MIME boundary.
#
FileETag none
#
# Disable not needed HTTP request methods
#
<Location />
<LimitExcept GET POST HEAD>
deny from all
</LimitExcept>
</Location>
#
# Disable Trace HTTP Request
# Having this enabled can allow Cross Site Tracing attack and potentially giving an
# option to a hacker to steal cookie information.
#
TraceEnable off
#
# Lower the timeout value
#
Timeout 30
#
# Header security settings
#
<IfModule mod_headers.c>
#
# Enable XSS protection (in Browsers)
#
# This header enables the Cross-site scripting (XSS) filter built into most recent web browsers.
# It's usually enabled by default anyway, so the role of this header is to re-enable the filter for
# this particular website if it was disabled by the user.
# https://www.owasp.org/index.php/List_of_useful_HTTP_headers
#
Header set X-XSS-Protection "1; mode=block"
#
# Enable Content Security Policy (CSP)
#
# With Content Security Policy (CSP) enabled(and a browser that supports it (http://caniuse.com/#feat=contentsecuritypolicy),
# you can tell the browser that it can only download content from the domains you explicitly allow
# http://www.html5rocks.com/en/tutorials/security/content-security-policy/
# https://www.owasp.org/index.php/Content_Security_Policy
#
# Note: Best practice is to allow everything but only from the same origin (default-src 'self';).
# Example configuration -> Header set Content-Security-Policy "default-src 'self'"
#
# Note: Because those setting are very tightly related to application this settings must be configured per specific application == disabled by default in the Apache template.
# Example configuration for RoundCube -> Header set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self'; frame-src 'self'; connect-src 'self'; frame-ancestors 'self'; base-uri 'self'; form-action 'self'"
#
# Disabling content-type sniffing
#
# When serving user-supplied content, include a X-Content-Type-Options: nosniff header along with the Content-Type: header,
# to disable content-type sniffing on some browsers.
# https://www.owasp.org/index.php/List_of_useful_HTTP_headers
# currently suppoorted in IE > 8 http://blogs.msdn.com/b/ie/archive/2008/09/02/ie8-security-part-vi-beta-2-update.aspx
# http://msdn.microsoft.com/en-us/library/ie/gg622941(v=vs.85).aspx
# 'soon' on Firefox https://bugzilla.mozilla.org/show_bug.cgi?id=471020
#
Header set X-Content-Type-Options nosniff
#
# Enabling HSTS (avoid SSL striping)
#
# Config to enable HSTS(HTTP Strict Transport Security) https://developer.mozilla.org/en-US/docs/Security/HTTP_Strict_Transport_Security
# to avoid ssl stripping https://en.wikipedia.org/wiki/SSL_stripping#SSL_stripping
# also https://hstspreload.org/
#
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
#
# Avoiding clickjacking
#
# config to don't allow the browser to render the page inside an frame or iframe
# and avoid clickjacking http://en.wikipedia.org/wiki/Clickjacking
# if you need to allow [i]frames, you can use SAMEORIGIN or even set an uri with ALLOW-FROM uri
# https://developer.mozilla.org/en-US/docs/HTTP/X-Frame-Options
#
# Note: DENY == This setting will prevent a page displaying in a frame or iframe.
#
# Note: DENY value setting cannot be enabled for applications/systems which uses iframes (for example RoundCube).
# Because we need to allow [i]frames, we will use SAMEORIGIN value which is safe default for most application.
Header set X-Frame-Options SAMEORIGIN
#
# Protect cookies with HTTPOnly flag
# Mitigation of Cross Site Scripting attack using HttpOnly and Secure flag in a cookie. Without having HttpOnly and Secure, it is possible to steal or manipulate web application session and cookies and it.s dangerous.
#
Header edit Set-Cookie ^(.*)$ $1;HttpOnly;Secure
#
# Prevent information disclosure
#
Header unset Server
Header unset X-Powered-By
</IfModule>
################################################################################
# Supplemental HTTP configuration
################################################################################
#
# Load config files from "/etc/httpd/conf.d" directory.
#
IncludeOptional conf.d/*.conf
################################################################################
# Include Virtualhosts configuration (IPv4)
################################################################################
#
# Include IPv4 Virtualhosts
#
Include conf.d/*.conf4
################################################################################
# Include Virtualhosts configuration (IPv6)
################################################################################
#
# Include IPv6 Virtualhosts
#
Include conf.d/*.conf6What was changed against the stock file
From diff httpd.conf.original httpd.conf, without the changes in comments and whitespace.
| Directive | Stock file | As built |
|---|---|---|
Listen 80 | present | removed; the only Listen is *:443 in ssl.conf |
ServerAdmin | root@localhost | shared-infra@example.net |
DocumentRoot "/var/www/html" | present | removed; each virtual host sets its own |
<Directory "/var/www/html"> with Options Indexes FollowSymLinks | present | removed |
DirectoryIndex | index.html | index.html index.php |
<IfModule alias_module> with ScriptAlias /cgi-bin/ | present | removed |
<Directory "/var/www/cgi-bin"> | present | removed |
EnableMMAP | commented out | on |
<Files ".ht*"> | in the main part | moved into the hardening block |
| Hardening block | not present | ServerTokens, ServerSignature, FileETag, LimitExcept, TraceEnable, Timeout, the Header lines |
Include conf.d/.conf4 and Include conf.d/.conf6 | not present | added; the virtual hosts are loaded through them |
The organisation's name was removed from three comment lines. The Content Security Policy is described in the comments and not set: the template leaves it to the application, and the application file of this server is empty, see the application include.
Checked against Apache HTTP Server 2.4.69
| As built | Today |
|---|---|
| Apache 2.4.6 of RHEL 7 | 2.4.69, released 2026-10-01; RHEL 10 ships 2.4.63 |
Header set X-XSS-Protection "1; mode=block" | The header is deprecated and non-standard, and can itself create XSS vulnerabilities in otherwise safe sites; the replacement is a Content Security Policy |
deny from all inside LimitExcept | deny belongs to mod_access_compat, whose directives are deprecated by the authorization refactoring; the current form is Require all denied |
ServerTokens Prod | Syntax unchanged |
| PHP as an Apache module | mod_php is no longer available in RHEL 9; PHP runs through php-fpm, the default since RHEL 8 |
The one header this file explains and does not send, the Content Security Policy, is the one that replaced the first header it does send.