GSA / GSA/ansible-https-proxy

Remove Sensitive Information from Logs

Đang mở
#12 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Không có dữ liệu ngôn ngữ
Star
10
Fork
5
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

>Draft CIS Benchmark 1.1.13

## Description
Sometimes sensitive web application parameters can be written to NGINX log files.

## Rationale
If we imagine sensitive payment information is being sent through NGINX, it may be important to remove such information before it is even logged.

## Remediation
Add the following line to the `server` block in your `nginx.conf`: ``` set $endpoint $request_uri; if ($endpoint ~ "(.*)\?[^ } log_format combined_no_query '$remote_addr - $remote_user [$time_local] ' '"$request_method $endpoint" $status $body_bytes_sent ' '"$http_referer" "$http_user_agent"'; access_log /var/log/nginx/access.log combined_no_query; ```

## Audit
Check the `access\_log` from NGINX for any sensitive information.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.