-
-
Notifications
You must be signed in to change notification settings - Fork 639
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Remove "ServerTokens Prod" setting #153
Comments
That's why there is a warning, right? 😉 server-configs-apache/src/security/server_software_information.conf Lines 19 to 20 in 18a537b
|
That's it. Whats the use of a setting when you can't enable it? |
Honestly I don't know. Related commits are not very verbose. That say this may be relevant for #1. |
I don't think h5bp wants to assume a user does or does not have access to the main server configuration file. The current approach informs users with access to the main config file the availability of However (unrelated to
|
Yeah, I'd say this should stay as is for the aforementioned reasons. |
Agreed, closing. |
This setting simply can't be set in .htaccess, but only in httpd.conf file according to Apache's specification:
http://httpd.apache.org/docs/2.2/en/mod/core.html#servertokens
Doing so will just result in an 500 internal error.
The spec's line "Context:" at "ServerTokens Directive" only lists "server config" but not ".htaccess"
The text was updated successfully, but these errors were encountered: