Loading Dockerfile +5 −0 Original line number Diff line number Diff line Loading @@ -103,6 +103,11 @@ RUN unzip -o /tmp/instantclient-basiclite-linux.x64-12.2.0.1.0.zip -d /usr/local RUN a2enmod actions alias rewrite ssl proxy proxy_fcgi setenvif headers && \ a2dismod mpm_event && a2enmod mpm_worker # Config Apache. ADD configs/apache/security.conf ${APACHE_CONF_DIR}/conf-available/security-unicaen.conf RUN a2disconf security.conf && \ a2enconf security-unicaen.conf # Scripts maison ADD scripts/update-satis.sh /usr/local/bin/update-satis RUN chmod 755 /usr/local/bin/update-satis Loading configs/apache/security.conf 0 → 100644 +84 −0 Original line number Diff line number Diff line # # Disable access to the entire file system except for the directories that # are explicitly allowed later. # # This currently breaks the configurations that come with some web application # Debian packages. # <Directory /> # Disable directory browser listing Options -Indexes AllowOverride None Require all denied </Directory> # Changing the following options will not really affect the security of the # server, but might make attacks slightly more difficult in some cases. # # ServerTokens # This directive configures what you return as the Server HTTP response # Header. The default is 'Full' which sends information about the OS-Type # and compiled in modules. # Set to one of: Full | OS | Minimal | Minor | Major | Prod # where Full conveys the most information, and Prod the least. ServerTokens Prod # # Optionally add a line containing the server version and virtual host # name to server-generated pages (internal error documents, FTP directory # listings, mod_status and mod_info output etc., but not CGI generated # documents or custom error documents). # Set to "EMail" to also include a mailto: link to the ServerAdmin. # Set to one of: On | Off | EMail ServerSignature Off # # Allow TRACE method # # Set to "extended" to also reflect the request body (only for testing and # diagnostic purposes). # # Set to one of: On | Off | extended TraceEnable Off # # Forbid access to version control directories # # If you use version control systems in your document root, you should # probably deny access to their directories. For example, for subversion: # <DirectoryMatch "/\.svn"> Require all denied </DirectoryMatch> <DirectoryMatch "/\.git"> Require all denied </DirectoryMatch> # # Setting this header will prevent MSIE from interpreting files as something # else than declared by the content type in the HTTP headers. # Requires mod_headers to be enabled. # Header set X-Content-Type-Options: nosniff # # Setting this header will prevent other sites from embedding pages from this # site as frames. This defends against clickjacking attacks. # Requires mod_headers to be enabled. # Header always append X-Frame-Options SAMEORIGIN Header set X-XSS-Protection "1; mode=block" Header edit Set-Cookie ^(.*)$ $1;HttpOnly;Secure Header set Strict-Transport-Security "max-age=31536000; includeSubDomains" FileETag MTime Size TraceEnable off # vim: syntax=apache ts=4 sw=4 sts=4 sr noet Loading
Dockerfile +5 −0 Original line number Diff line number Diff line Loading @@ -103,6 +103,11 @@ RUN unzip -o /tmp/instantclient-basiclite-linux.x64-12.2.0.1.0.zip -d /usr/local RUN a2enmod actions alias rewrite ssl proxy proxy_fcgi setenvif headers && \ a2dismod mpm_event && a2enmod mpm_worker # Config Apache. ADD configs/apache/security.conf ${APACHE_CONF_DIR}/conf-available/security-unicaen.conf RUN a2disconf security.conf && \ a2enconf security-unicaen.conf # Scripts maison ADD scripts/update-satis.sh /usr/local/bin/update-satis RUN chmod 755 /usr/local/bin/update-satis Loading
configs/apache/security.conf 0 → 100644 +84 −0 Original line number Diff line number Diff line # # Disable access to the entire file system except for the directories that # are explicitly allowed later. # # This currently breaks the configurations that come with some web application # Debian packages. # <Directory /> # Disable directory browser listing Options -Indexes AllowOverride None Require all denied </Directory> # Changing the following options will not really affect the security of the # server, but might make attacks slightly more difficult in some cases. # # ServerTokens # This directive configures what you return as the Server HTTP response # Header. The default is 'Full' which sends information about the OS-Type # and compiled in modules. # Set to one of: Full | OS | Minimal | Minor | Major | Prod # where Full conveys the most information, and Prod the least. ServerTokens Prod # # Optionally add a line containing the server version and virtual host # name to server-generated pages (internal error documents, FTP directory # listings, mod_status and mod_info output etc., but not CGI generated # documents or custom error documents). # Set to "EMail" to also include a mailto: link to the ServerAdmin. # Set to one of: On | Off | EMail ServerSignature Off # # Allow TRACE method # # Set to "extended" to also reflect the request body (only for testing and # diagnostic purposes). # # Set to one of: On | Off | extended TraceEnable Off # # Forbid access to version control directories # # If you use version control systems in your document root, you should # probably deny access to their directories. For example, for subversion: # <DirectoryMatch "/\.svn"> Require all denied </DirectoryMatch> <DirectoryMatch "/\.git"> Require all denied </DirectoryMatch> # # Setting this header will prevent MSIE from interpreting files as something # else than declared by the content type in the HTTP headers. # Requires mod_headers to be enabled. # Header set X-Content-Type-Options: nosniff # # Setting this header will prevent other sites from embedding pages from this # site as frames. This defends against clickjacking attacks. # Requires mod_headers to be enabled. # Header always append X-Frame-Options SAMEORIGIN Header set X-XSS-Protection "1; mode=block" Header edit Set-Cookie ^(.*)$ $1;HttpOnly;Secure Header set Strict-Transport-Security "max-age=31536000; includeSubDomains" FileETag MTime Size TraceEnable off # vim: syntax=apache ts=4 sw=4 sts=4 sr noet