appweb.conf 3.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140
  1. #
  2. # appweb.conf -- Appweb Configuration for a highly secure server
  3. #
  4. #
  5. # Enable emitting debug error messages back to the client. Defaults to "off".
  6. # WARNING: this may disclose unwanted information. Do not enable in production releases.
  7. #
  8. ShowErrors off
  9. AddHandler espHandler esp
  10. AddHandler fileHandler
  11. include auth.conf
  12. #
  13. # Create a chroot jail. Nothing outside "." will be visible after this.
  14. #
  15. # MakeDir APPWEB:APPWEB:0755 /var/spool/appweb/embedthis/cache
  16. GroupAccount APPWEB
  17. UserAccount APPWEB
  18. #
  19. # Listen for HTTP and HTTPS
  20. #
  21. Listen 127.0.0.1:8080
  22. ListenSecure 127.0.0.1:4443
  23. #
  24. # Create a "chroot jail" by changing the system root directory to this
  25. # directory. Once changed files outside the jail will be inaccessible.
  26. # If rotating log files, must do Chroot before defining logs.
  27. #
  28. # Chroot "."
  29. #
  30. # SECURITY NOTE: you must generate the key and certificate
  31. # The self.crt is a self-signed certificate for test purposes only.
  32. # You MUST get your own certificate and key.
  33. #
  34. SSLCertificateFile "self.crt"
  35. SSLCertificateKeyFile "self.key"
  36. #
  37. # Route HTTP traffic over SSL. This entire site runs over SSL.
  38. #
  39. Redirect secure
  40. #
  41. # This will force browsers to insist on TLS connections only for one year
  42. #
  43. # Strict-Transport-Security max-age=31536000; includeSubDomains
  44. #
  45. # Documents directory
  46. #
  47. Documents "web"
  48. DirectoryIndex index.esp
  49. #
  50. # Authentication and Authorization directives
  51. #
  52. AuthStore config
  53. #
  54. # Web-Form login (test user:password is joshua:pass1)
  55. #
  56. AuthType form example.com https:///pub/login.esp https:///login /logout /index.esp
  57. #
  58. # Timeouts. Set as low as possible.
  59. # The defaults are already fairly low ... lower even more here.
  60. #
  61. InactivityTimeout 30secs
  62. RequestParseTimeout 5sec
  63. RequestTimeout 1min
  64. SessionTimeout 5mins
  65. #
  66. # Emit as little information as possible. Don't emit as "Server" header
  67. # This is the default
  68. #
  69. # Stealth on
  70. #
  71. # Set the cookie name and determine if the cookie is visible to Javascript
  72. # (default is httponly, invisible to scripts). Making cookies visible
  73. # increases the XSS potential.
  74. #
  75. # SessionCookie name=NAME visible=false
  76. #
  77. # Minimize cross-site vulnerabilities
  78. # These are emitted by default
  79. #
  80. # Header set X-XSS-Protection 1; mode=block
  81. # Header set X-Frame-Options deny
  82. # Header set X-Content-Type-Options: nosniff
  83. #
  84. # You should seriously consider adding a content security policy to minimize XSS vulnerabilities
  85. #
  86. # Header set Content-Security-Policy default-src 'self'
  87. #
  88. # Monitors and defenses
  89. # These will ban clients that probe the server and trigger too many not-found errors.
  90. # Also any client doing more than 500 requests in a 30 sec period will be banned.
  91. # Bans are for 10 minutes.
  92. #
  93. Defense deny REMEDY=ban PERIOD=10mins
  94. Monitor "NotFoundErrors > 190" 30sec deny
  95. Monitor "Requests > 500" 30sec deny
  96. #
  97. # Sandbox limits. Set as low as possible.
  98. #
  99. LimitCache 256K
  100. LimitCacheItem 80K
  101. LimitClients 10
  102. LimitConnectionsPerClient 20
  103. LimitRequestsPerClient 20
  104. LimitRequestBody 100K
  105. LimitRequestForm 32K
  106. LimitUri 512
  107. #
  108. # Cache static content for one day at the client
  109. #
  110. Cache client=1day extensions="html,gif,jpeg,jpg,png,pdf,ico,js"
  111. LimitWorkers 4
  112. #
  113. # Restart the server if memory is depleted
  114. #
  115. LimitMemory 8MB
  116. MemoryPolicy restart