Linux Apache 安全配置清单
一 基础安全基线
二 模块与请求限制
三 传输加密与端口管理
四 日志监控与抗攻击
五 最小化配置示例
ServerSignature Off
ServerTokens Prod
Options -Indexes
User www
Group www
<Directory />
Options None
AllowOverride None
Require all denied
</Directory>
<Directory /var/www/html>
Options -Indexes +FollowSymLinks
AllowOverride None
Require all granted
</Directory>
<Directory /var/www/html/admin>
Require ip 192.168.1.0/24 127.0.0.1
</Directory>
LimitRequestBody 10485760
SSLEngine on
SSLCertificateFile /etc/ssl/certs/example.com.crt
SSLCertificateKeyFile /etc/ssl/private/example.com.key
SSLCertificateChainFile /etc/ssl/certs/example-chain.crt
httpd -t
systemctl reload apache2 # Debian/Ubuntu
systemctl reload httpd # RHEL/CentOS