<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Apache Web Server ETag Header Information Disclosure in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371156#M9150</link>
    <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/151364"&gt;@rkalapala&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What exactly is not working? Have you restarted the web server? You can try to add "Header unset Etag" without any "if" conditions.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jun 2017 07:18:18 GMT</pubDate>
    <dc:creator>alexal</dc:creator>
    <dc:date>2017-06-28T07:18:18Z</dc:date>
    <item>
      <title>Apache Web Server ETag Header Information Disclosure</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371149#M9147</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We wanted to disable ETag header information in our SAS mid tier, please help.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 06:27:48 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371149#M9147</guid>
      <dc:creator>rkalapala</dc:creator>
      <dc:date>2017-06-28T06:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Web Server ETag Header Information Disclosure</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371151#M9148</link>
      <description>&lt;P&gt;Add&lt;/P&gt;
&lt;PRE&gt;&amp;lt;IfModule headers_module&amp;gt;
  Header unset Etag
  FileETag none
&amp;lt;/IfModule&amp;gt;&lt;/PRE&gt;
&lt;P&gt;to /.../Lev1/Web/WebServer/conf/httpd.conf and restart the web server.&lt;/P&gt;
&lt;P&gt;Reference:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.websiteoptimization.com/secrets/advanced/configure-etags.html" target="_blank"&gt;http://www.websiteoptimization.com/secrets/advanced/configure-etags.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Disclaimer: I have no idea if or how that might affect the SAS webapps.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 06:38:22 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371151#M9148</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2017-06-28T06:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Web Server ETag Header Information Disclosure</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371154#M9149</link>
      <description>&lt;P&gt;Thank you for your solution, it didn't help. I am still getting&amp;nbsp;ETag information.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 06:46:42 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371154#M9149</guid>
      <dc:creator>rkalapala</dc:creator>
      <dc:date>2017-06-28T06:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Web Server ETag Header Information Disclosure</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371156#M9150</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/151364"&gt;@rkalapala&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What exactly is not working? Have you restarted the web server? You can try to add "Header unset Etag" without any "if" conditions.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 07:18:18 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371156#M9150</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2017-06-28T07:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Web Server ETag Header Information Disclosure</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371157#M9151</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually we wanted to remove Etag header information, I tried to add without if and with if, still it is displaying the Etag header information. I restarted Web Server after update.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 07:24:04 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371157#M9151</guid>
      <dc:creator>rkalapala</dc:creator>
      <dc:date>2017-06-28T07:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Web Server ETag Header Information Disclosure</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371159#M9152</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/151364"&gt;@rkalapala&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That should work, but let me ask you, why are you wanted to remove Etag header information? We do not recommend making to do any changes in http.conf, unless they were suggested by technical support. What are you trying to achieve?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 07:30:48 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371159#M9152</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2017-06-28T07:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Web Server ETag Header Information Disclosure</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371160#M9153</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our security team found that&amp;nbsp;Apache Server ETag Header Information Disclosure, we have been asked to remediate, so we are disabling the Etag.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By the way your solution worked.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 07:34:13 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371160#M9153</guid>
      <dc:creator>rkalapala</dc:creator>
      <dc:date>2017-06-28T07:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Web Server ETag Header Information Disclosure</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371161#M9154</link>
      <description>&lt;P&gt;How did you restart the web server? I recommend using&lt;/P&gt;
&lt;PRE&gt;/..../Lev1/Web/WebServer/bin/httpdctl stop&lt;/PRE&gt;
&lt;P&gt;(issued as the SAS install user)&lt;/P&gt;
&lt;P&gt;then check if no httpd process is still running (ps -e|grep httpd)&lt;/P&gt;
&lt;P&gt;and then issue&lt;/P&gt;
&lt;PRE&gt;/..../Lev1/Web/WebServer/bin/httpdctl start&lt;/PRE&gt;
&lt;P&gt;(again as SAS install user)&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 07:34:14 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371161#M9154</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2017-06-28T07:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Web Server ETag Header Information Disclosure</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371162#M9155</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/11562"&gt;@Kurt_Bremser&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I restarted web server as same way as recommended.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;/..../Lev1/Web/WebServer/bin/httpdctl stop&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;PRE&gt;/..../Lev1/Web/WebServer/bin/httpdctl start&lt;/PRE&gt;&lt;P&gt;Thank you for your help&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 07:36:52 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371162#M9155</guid>
      <dc:creator>rkalapala</dc:creator>
      <dc:date>2017-06-28T07:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Web Server ETag Header Information Disclosure</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371163#M9156</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/41748"&gt;@alexal&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on most of the big companies, or companies where security is not a must, but also there are audit procedures, they have periodic checks specially meant for the web applications, where alarms may raise, such as the Poodle and others related to SSL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As consultant, I received several request on several clients to close this vulnerability. Of course, for the first request, I did my homework checking with SAS Technical Support. Once I had the green light, I did the change and some validations, no problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I feel curious: how come that this vulnerability is not included in &lt;A href="https://support.sas.com/en/security-bulletins.html" target="_blank"&gt;https://support.sas.com/en/security-bulletins.html&lt;/A&gt; and not included on a hotfix? Is it in use by any SAS Web application?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 07:47:30 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371163#M9156</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2017-06-28T07:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Web Server ETag Header Information Disclosure</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371166#M9157</link>
      <description>&lt;P&gt;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/35204"&gt;@JuanS_OCS&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I do not have any details about this vulnerability, but I would suggest to open a technical support track and request that information. We have a specific procedure that we need to follow when contacting Product Security Incident Response Team (PSIRT), so only this team can respond.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 08:03:36 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371166#M9157</guid>
      <dc:creator>alexal</dc:creator>
      <dc:date>2017-06-28T08:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Web Server ETag Header Information Disclosure</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371173#M9159</link>
      <description>&lt;P&gt;Have a look at &lt;A href="https://communities.sas.com/t5/SASware-Ballot-Ideas/Keep-3rd-party-software-current/idi-p/355959" target="_blank"&gt;https://communities.sas.com/t5/SASware-Ballot-Ideas/Keep-3rd-party-software-current/idi-p/355959&lt;/A&gt;, where I suggested that SAS should keep the third-party web server software (apache and tomcat, both open-source) up-to-date, better than it is doing now.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jun 2017 08:36:29 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Apache-Web-Server-ETag-Header-Information-Disclosure/m-p/371173#M9159</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2017-06-28T08:36:29Z</dc:date>
    </item>
  </channel>
</rss>

