mod_security/modsecurity-2.9.5-Set-SecStatusEngine-Off-in-modsecurity.conf.patch

29 lines
1.0 KiB
Diff
Raw Normal View History

From fc84c6a3f6c446760350f80189d4bbfc116c143c Mon Sep 17 00:00:00 2001
From: yaoguangzhong <yaoguangzhong@xfusion.com>
Date: Sat, 7 Jan 2023 15:26:23 +0800
Subject: [PATCH] backport Set SecStatusEngine Off in
modsecurity.conf-recommended
From Author: Martin Vierula <martin.vierula@trustwave.com>
commit 733427197e2fe4fabcbb0f43bd1e636ef923a6b4
---
modsecurity.conf-recommended | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/modsecurity.conf-recommended b/modsecurity.conf-recommended
index c84ddce..923f5d8 100644
--- a/modsecurity.conf-recommended
+++ b/modsecurity.conf-recommended
@@ -234,5 +234,6 @@ SecUnicodeMapFile unicode.mapping 20127
# The following information will be shared: ModSecurity version,
# Web Server version, APR version, PCRE version, Lua version, Libxml2
# version, Anonymous unique id for host.
-SecStatusEngine On
-
++# NB: As of April 2022, there is no longer any advantage to turning this
++# setting On, as there is no active receiver for the information.
++SecStatusEngine Off
--
2.27.0