{"id":6582,"date":"2021-10-30T18:14:41","date_gmt":"2021-10-30T12:44:41","guid":{"rendered":"https:\/\/pheonixsolutions.com\/blog\/?p=6582"},"modified":"2021-10-30T18:14:42","modified_gmt":"2021-10-30T12:44:42","slug":"hide-server-details-and-disable-tlsv1-0-and-tlsv1-1","status":"publish","type":"post","link":"https:\/\/pheonixsolutions.com\/blog\/hide-server-details-and-disable-tlsv1-0-and-tlsv1-1\/","title":{"rendered":"Hide server details and disable TLSV1.0 and TLSV1.1"},"content":{"rendered":"\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Remove server name from Apache headers<\/strong>:- <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is essential to remove Apache server header to hide Apache server information and protect your website from malicious attackers. Here\u2019s how to remove server name from Apache response header using htaccess. You can use it to hide the Apache version and server type in Ubuntu, CentOS.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Open terminal and run the following command to open Apache main configuration file.<br><strong>Centos:-<\/strong> <span class=\"has-inline-color has-vivid-cyan-blue-color\">vi \/etc\/httpd\/conf\/httpd.conf<\/span><br><strong>Ubuntu:- <\/strong><span class=\"has-inline-color has-vivid-cyan-blue-color\">vi \/etc\/apache2\/apache2.conf<\/span><\/li><li>Turn off server signature. Add or Modify the below lines<br><span class=\"has-inline-color has-vivid-cyan-blue-color\">ServerSignature Off<br>ServerTokens Prod<\/span><\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ServerSignature<\/strong>\u00a0\u2013 appears at the bottom of server generated pages such as error pages, directory listings, etc<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ServerTokens<\/strong>\u00a0\u2013\u00a0decides what Apache will send back in response headers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you want to disable server signature in WordPress or turn off server signature in CPanel, then you will have to remove Apache server using\u00a0<em>.htaccess<\/em>\u00a0file, since you may not have access to Apache\u2019s main configuration file.<br><br>Open CPanel, locate\u00a0<em>.htaccess<\/em>\u00a0file and edit it. Add the following 2 lines to\u00a0<em>.htaccess<\/em>\u00a0file<br><span style=\"font-size: revert\">ServerSignature Off<\/span><br><span style=\"font-size: revert\">ServerTokens Prod<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">3. Restart the Apache server with the below command.<br><span class=\"has-inline-color has-vivid-cyan-blue-color\">systemctl restart apache2<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Disable TLSV1.0 and TLSV1.1:- <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">All versions of the SSL\/TLS protocol prior to TLS 1.2 are now deprecated and considered insecure.\u00a0Many web server platforms still have TLS 1.0 and TLS 1.1 enabled by default. However, all modern web browsers are compatible with TLS 1.2. For this reason, it\u2019s a good idea for website owners to check their server configuration to make sure that only current, secure versions of SSL\/TLS are enabled and all others (including TLS 1.0, TLS 1.1, and SSL 3.0) are disabled.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can also check for the SSL\/TLS versions and ciphers supported by a website with the open-source nmap command-line tool:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span class=\"has-inline-color has-vivid-cyan-blue-color\">nmap &#8211;script ssl-enum-ciphers -p &lt;PORT&gt; &lt;DOMAIN NAME&gt;<\/span><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-5.50.21-PM.png\"><img fetchpriority=\"high\" decoding=\"async\" width=\"937\" height=\"1024\" src=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-5.50.21-PM-937x1024.png\" alt=\"\" class=\"wp-image-6583\" srcset=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-5.50.21-PM-937x1024.png 937w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-5.50.21-PM-275x300.png 275w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-5.50.21-PM-768x839.png 768w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-5.50.21-PM-1406x1536.png 1406w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-5.50.21-PM.png 1560w\" sizes=\"(max-width: 937px) 100vw, 937px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">To disable TLS 1.0 and 1.1 in Apache, you will need to edit the configuration file containing the SSLProtocol directive for your website. This file may be located in different places depending on your platform, version, or other installation details. Some possible locations are:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><span class=\"has-inline-color has-black-color\">Default Apache installation:-<\/span><span class=\"has-inline-color has-vivid-cyan-blue-color\"> \/usr\/local\/apache2\/conf\/extra\/httpd-ssl.conf<br><\/span><span class=\"has-inline-color has-black-color\">Ubuntu\/Debian:-<\/span><span class=\"has-inline-color has-vivid-cyan-blue-color\"> \/etc\/apache2\/mods-enabled\/ssl.conf<br><\/span><span class=\"has-inline-color has-black-color\">macOS:-<\/span><span class=\"has-inline-color has-vivid-cyan-blue-color\">  \/private\/etc\/apache2\/extra\/httpd-ssl.conf<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can disable all obsolete versions of SSL\/TLS supported by Apache by specifying them as follows:<br><span class=\"has-inline-color has-vivid-cyan-blue-color\">SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1<\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The configuration above enables TLS 1.2, as well as TLS 1.3 if it is available in your environment.<\/p>\n\n\n\n<p class=\"has-normal-font-size wp-block-paragraph\"><strong>Disabling TLSV1.0 and TLSV1.1 at load-balancer level:-<\/strong> <br><br>1) Log into the AWS Console and navigate to the EC2 group. Within this group, click the\u00a0<strong>Load Balancers<\/strong>option under Load Balancing.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.04.07-PM-1.png\"><img decoding=\"async\" width=\"736\" height=\"564\" src=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.04.07-PM-1.png\" alt=\"\" class=\"wp-image-6585\" srcset=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.04.07-PM-1.png 736w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.04.07-PM-1-300x230.png 300w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.04.07-PM-1-391x300.png 391w\" sizes=\"(max-width: 736px) 100vw, 736px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">2) At the bottom of the screen, click the\u00a0<strong>Listeners<\/strong>\u00a0tab. You should see your HTTPS listener listed. Click the\u00a0<strong>Change<\/strong>\u00a0link under the Cipher column.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.07.37-PM-1.png\"><img decoding=\"async\" width=\"1024\" height=\"330\" src=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.07.37-PM-1-1024x330.png\" alt=\"\" class=\"wp-image-6587\" srcset=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.07.37-PM-1-1024x330.png 1024w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.07.37-PM-1-300x97.png 300w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.07.37-PM-1-768x247.png 768w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.07.37-PM-1-850x274.png 850w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.07.37-PM-1.png 1472w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p class=\"has-normal-font-size wp-block-paragraph\">    <br><br>3) You will see a list of Predefined Security Policies in the window that just opened. Ensure you select at least the TLS 1.1 or higher policy. You will notice the selections in the window to the right changing, leaving both vulnerable protocols unchecked.<br><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.11.14-PM.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"588\" src=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.11.14-PM-1024x588.png\" alt=\"\" class=\"wp-image-6588\" srcset=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.11.14-PM-1024x588.png 1024w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.11.14-PM-300x172.png 300w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.11.14-PM-768x441.png 768w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.11.14-PM-1536x882.png 1536w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.11.14-PM-522x300.png 522w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.11.14-PM.png 1968w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, click the\u00a0<strong>Save<\/strong>\u00a0button to confirm the changes. You can make use of a service like\u00a0<a href=\"https:\/\/www.ssllabs.com\/ssltest\/\" target=\"_blank\" rel=\"noreferrer noopener\">Qualys<\/a>\u00a0to confirm your changes:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.12.01-PM.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"277\" src=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.12.01-PM-1024x277.png\" alt=\"\" class=\"wp-image-6589\" srcset=\"https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.12.01-PM-1024x277.png 1024w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.12.01-PM-300x81.png 300w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.12.01-PM-768x207.png 768w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.12.01-PM-1536x415.png 1536w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.12.01-PM-850x230.png 850w, https:\/\/pheonixsolutions.com\/blog\/wp-content\/uploads\/2021\/10\/Screenshot-2021-10-30-at-6.12.01-PM.png 1844w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Remove server name from Apache headers:- It is essential to remove Apache server header to hide Apache server information and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[1019],"tags":[398,925,926,924,923],"class_list":["post-6582","post","type-post","status-publish","format-standard","hentry","category-cloud-aws","tag-apache2","tag-disable-tlsv1-0-and-tlsv1-1","tag-disable-tlsv1-0-and-tlsv1-1-at-loadbalancer-level","tag-hide-server-details","tag-loadbalancer","psol-cat-cloud-aws"],"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/phn2x7-1Ia","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts\/6582","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/comments?post=6582"}],"version-history":[{"count":0,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts\/6582\/revisions"}],"wp:attachment":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/media?parent=6582"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/categories?post=6582"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/tags?post=6582"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}