Re: Hardening & security

2021-05-13 Thread spaace
Thanks Maxim. I saw this tool too but i was not sure if it  has a good
breadth of coverage. 

Their github readme seems to list a few vulnerabilities and i was thinking
perhaps that could be inadequate. 

Thank you. 
Arun

Posted at Nginx Forum: 
https://forum.nginx.org/read.php?2,291451,291510#msg-291510

___
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx


Re: Hardening & security

2021-05-07 Thread Maxim Konovalov
Hi,

On 07.05.2021 12:18, spaace wrote:
> Hi, 
> 
> We intend to deploy Nginx as a reverse proxy and want to be sure it is as
> secure as possible. 
> 
> Are there any recommended scanners to check whether the rules have any holes
> in them ?
>  eg acutenix? 
> 
> Which is the defacto hardening guide for securing Nginx rules apart from the
> CIS published ones? 
> 
I'd additionally take a look at Yandex's Gixy, nginx config scanner:

https://github.com/yandex/gixy

-- 
Maxim Konovalov
___
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx