LINUXOR.SK ... open source notes ...

Email - Apache httpd.conf, webmail

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Webmail

The global Apache configuration of the webmail server, written from the organisation's unified Apache template. The upper part is the distribution's file with things taken out, the lower part is the hardening block the template adds. The stock comments of the upper part are left out; the hardening part is shown with its comments, which are mine and the template's.

ItemValue
Path on the server/etc/httpd/conf/httpd.conf
Shown hereDC2-A-VCMSX002
Stock file kept as/etc/httpd/conf/httpd.conf.original
SoftwareApache HTTP Server 2.4 from RHEL 7, with mod_ssl and PHP 5 as a module
Activated withsystemctl start httpd in the install notes

The file

apache
################################################################################
# Global HTTP configuration
################################################################################

ServerRoot "/etc/httpd"

Include conf.modules.d/*.conf

User apache
Group apache

ServerAdmin shared-infra@example.net

<Directory />

    AllowOverride none
    Require all denied

</Directory>

<Directory "/var/www">

    AllowOverride None

    Require all granted

</Directory>

<IfModule dir_module>

    DirectoryIndex index.html index.php

</IfModule>

ErrorLog "logs/error_log"

LogLevel warn

<IfModule log_config_module>

    LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
    LogFormat "%h %l %u %t \"%r\" %>s %b" common

    <IfModule logio_module>

        LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\" %I %O" combinedio

    </IfModule>

    CustomLog "logs/access_log" combined

</IfModule>

<IfModule mime_module>

    TypesConfig /etc/mime.types

    AddType application/x-compress .Z
    AddType application/x-gzip .gz .tgz

    AddType text/html .shtml
    AddOutputFilter INCLUDES .shtml

</IfModule>

AddDefaultCharset UTF-8

<IfModule mime_magic_module>

    MIMEMagicFile conf/magic

</IfModule>

# Note: We are on Linux platform = syscall supported.
EnableMMAP on
EnableSendfile on

################################################################################
# Global HTTP configuration - Hardening
################################################################################

#
# The following lines prevent .htaccess and .htpasswd files from being
# viewed by Web clients.
#
<Files ".ht*">

    Require all denied

</Files>

#
# Remove server version banner
#
# Note: Server sigranute cannot be removed entirely without using mod_security.
#
ServerTokens Prod
ServerSignature Off

#
# Disable "ETag"
#
# ETags (entity tags) are a well-known point of vulnerability in Apache web server.
# ETag is an HTTP response header that allows remote users to obtain sensitive information
# like inode number, child process ids, and multipart MIME boundary.
#
FileETag none

#
# Disable not needed HTTP request methods
#
<Location />
    <LimitExcept GET POST HEAD>
        deny from all
    </LimitExcept>
</Location>

#
# Disable Trace HTTP Request
# Having this enabled can allow Cross Site Tracing attack and potentially giving an
# option to a hacker to steal cookie information.
#
TraceEnable off

#
# Lower the timeout value
#
Timeout 30

#
# Header security settings
#
<IfModule mod_headers.c>

    #
    # Enable XSS protection (in Browsers)
    #
    # This header enables the Cross-site scripting (XSS) filter built into most recent web browsers.
    # It's usually enabled by default anyway, so the role of this header is to re-enable the filter for
    # this particular website if it was disabled by the user.
    # https://www.owasp.org/index.php/List_of_useful_HTTP_headers
    #
    Header set X-XSS-Protection "1; mode=block"

    #
    # Enable Content Security Policy (CSP)
    #
    # With Content Security Policy (CSP) enabled(and a browser that supports it (http://caniuse.com/#feat=contentsecuritypolicy),
    # you can tell the browser that it can only download content from the domains you explicitly allow
    # http://www.html5rocks.com/en/tutorials/security/content-security-policy/
    # https://www.owasp.org/index.php/Content_Security_Policy
    #
    # Note:       Best practice is to allow everything but only from the same origin (default-src 'self';).
    #             Example configuration -> Header set Content-Security-Policy "default-src 'self'"
    #
    # Note:     Because those setting are very tightly related to application this settings must be configured per specific application == disabled by default in the Apache template.
    #             Example configuration for RoundCube -> Header set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self'; frame-src 'self'; connect-src 'self'; frame-ancestors 'self'; base-uri 'self'; form-action 'self'"

    #
    # Disabling content-type sniffing
    #
    # When serving user-supplied content, include a X-Content-Type-Options: nosniff header along with the Content-Type: header,
    # to disable content-type sniffing on some browsers.
    # https://www.owasp.org/index.php/List_of_useful_HTTP_headers
    # currently suppoorted in IE > 8 http://blogs.msdn.com/b/ie/archive/2008/09/02/ie8-security-part-vi-beta-2-update.aspx
    # http://msdn.microsoft.com/en-us/library/ie/gg622941(v=vs.85).aspx
    # 'soon' on Firefox https://bugzilla.mozilla.org/show_bug.cgi?id=471020
    #
    Header set X-Content-Type-Options nosniff

    #
    # Enabling HSTS (avoid SSL striping)
    #
    # Config to enable HSTS(HTTP Strict Transport Security) https://developer.mozilla.org/en-US/docs/Security/HTTP_Strict_Transport_Security
    # to avoid ssl stripping https://en.wikipedia.org/wiki/SSL_stripping#SSL_stripping
    # also https://hstspreload.org/
    #
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"

    #
    # Avoiding clickjacking
    #
    # config to don't allow the browser to render the page inside an frame or iframe
    # and avoid clickjacking http://en.wikipedia.org/wiki/Clickjacking
    # if you need to allow [i]frames, you can use SAMEORIGIN or even set an uri with ALLOW-FROM uri
    # https://developer.mozilla.org/en-US/docs/HTTP/X-Frame-Options
    #
    # Note:       DENY == This setting will prevent a page displaying in a frame or iframe.
    #
    # Note:     DENY value setting cannot be enabled for applications/systems which uses iframes (for example RoundCube).
    #             Because we need to allow [i]frames, we will use SAMEORIGIN value which is safe default for most application.
    Header set X-Frame-Options SAMEORIGIN

    #
    # Protect cookies with HTTPOnly flag
    # Mitigation of Cross Site Scripting attack using HttpOnly and Secure flag in a cookie. Without having HttpOnly and Secure, it is possible to steal or manipulate web application session and cookies and it.s dangerous.
    #
    Header edit Set-Cookie ^(.*)$ $1;HttpOnly;Secure

    #
    # Prevent information disclosure
    #
    Header unset Server
    Header unset X-Powered-By

</IfModule>

################################################################################
# Supplemental HTTP configuration
################################################################################

#
# Load config files from "/etc/httpd/conf.d" directory.
#
IncludeOptional conf.d/*.conf

################################################################################
# Include Virtualhosts configuration (IPv4)
################################################################################

#
# Include IPv4 Virtualhosts
#
Include conf.d/*.conf4

################################################################################
# Include Virtualhosts configuration (IPv6)
################################################################################

#
# Include IPv6 Virtualhosts
#
Include conf.d/*.conf6

What was changed against the stock file

From diff httpd.conf.original httpd.conf, without the changes in comments and whitespace.

DirectiveStock fileAs built
Listen 80presentremoved; the only Listen is *:443 in ssl.conf
ServerAdminroot@localhostshared-infra@example.net
DocumentRoot "/var/www/html"presentremoved; each virtual host sets its own
<Directory "/var/www/html"> with Options Indexes FollowSymLinkspresentremoved
DirectoryIndexindex.htmlindex.html index.php
<IfModule alias_module> with ScriptAlias /cgi-bin/presentremoved
<Directory "/var/www/cgi-bin">presentremoved
EnableMMAPcommented outon
<Files ".ht*">in the main partmoved into the hardening block
Hardening blocknot presentServerTokens, ServerSignature, FileETag, LimitExcept, TraceEnable, Timeout, the Header lines
Include conf.d/.conf4 and Include conf.d/.conf6not presentadded; the virtual hosts are loaded through them

The organisation's name was removed from three comment lines. The Content Security Policy is described in the comments and not set: the template leaves it to the application, and the application file of this server is empty, see the application include.

Checked against Apache HTTP Server 2.4.69

As builtToday
Apache 2.4.6 of RHEL 72.4.69, released 2026-10-01; RHEL 10 ships 2.4.63
Header set X-XSS-Protection "1; mode=block"The header is deprecated and non-standard, and can itself create XSS vulnerabilities in otherwise safe sites; the replacement is a Content Security Policy
deny from all inside LimitExceptdeny belongs to mod_access_compat, whose directives are deprecated by the authorization refactoring; the current form is Require all denied
ServerTokens ProdSyntax unchanged
PHP as an Apache modulemod_php is no longer available in RHEL 9; PHP runs through php-fpm, the default since RHEL 8

The one header this file explains and does not send, the Content Security Policy, is the one that replaced the first header it does send.

← solutionz