面是一些要检查的安全设置:
ssl:
在httpd.conf中打开ssl
port 80
listen 80
listen 443
sslsessioncache dbm:/usr/local/apache/ logs/ssl_scache
sslsessioncachetimeout 1200
# for increased performance use "sslmutex sem" instead of the line below
sslmutex file:/usr/local/apache/logs/ssl_mutex
ssllog /usr/local/apache/logs/ssl_engine_log
# change the log level default from "info" to "warn"
sslloglevel warn
ssloptions +optrenegotiate
打开虚拟主机的ssl支持:
# within the
sslengine on
# replace
sslcertificatefile /usr/local/apache/conf/ssl.
cert/
# replace
sslkeyfile /usr/local/apache/conf/ssl.key/
sslverifyclient none
定制ssl的log格式:
logformat clfa "%h %l %u %t \"%r\" %>s %b\ %{ssl_protocol}x %{ssl_cipher}x \"%{ssl_client_s_dn_cn}x\""
customlog /usr/local/apache/logs/access_log clfa
被保护的目录:
sslciphersuite high: medium
authtype digest
authname "beta code testing"
authdigestdomain /test/ http://test.my.dom/beta/
authdigestfile /usr/local/apache/conf/
digest_pw
require valid-user
Java Asp PHP .Net XML C/C++ CGI VB Jsp J2ee J2se J2me EJB Servlet Tomcat Resin Struts Weblogic Eclipse ANT GUI JMS Web servise IDEA Webphere Hibernate Spring Jboss Applet Swing Socket Javamail Perl Ajax P2P 安全 模式 框架 测试 开源 游戏
Windows XP Windows 2000 Windows 2003 Windows Me Windows 9.x Linux UNIX 注册表 操作系统 服务器 应用服务器