RT#7092: Apache on godard adds an additional X-Xss-Protection
authorMartin Zobel-Helas <zobel@debian.org>
Fri, 9 Feb 2018 17:18:36 +0000 (18:18 +0100)
committerMartin Zobel-Helas <zobel@debian.org>
Fri, 9 Feb 2018 17:25:02 +0000 (18:25 +0100)
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
modules/apache2/files/headers
spec/octocatalog/facts/godard.debian.org.json [new file with mode: 0644]

index 3e7167a..15d3b08 100644 (file)
@@ -1,9 +1,9 @@
 <IfModule mod_headers.c>
   Header set X-Clacks-Overhead "GNU Terry Pratchett"
 
-  Header always set X-Content-Type-Options "nosniff"
-  Header always set X-Frame-Options "sameorigin"
-  Header always set Referrer-Policy "no-referrer"
-  # Header always set X-Xss-Protection "1; mode=block"
-  Header always set X-Xss-Protection "1"
+  Header always setifempty X-Content-Type-Options "nosniff"
+  Header always setifempty X-Frame-Options "sameorigin"
+  Header always setifempty Referrer-Policy "no-referrer"
+  # Header always setifempty X-Xss-Protection "1; mode=block"
+  Header always setifempty X-Xss-Protection "1"
 </IfModule>
diff --git a/spec/octocatalog/facts/godard.debian.org.json b/spec/octocatalog/facts/godard.debian.org.json
new file mode 100644 (file)
index 0000000..3d59924
--- /dev/null
@@ -0,0 +1,206 @@
+{
+  "rubyplatform": "x86_64-linux-gnu",
+  "kernel": "Linux",
+  "hoster": "ubc",
+  "id": "root",
+  "kernelmajversion": "4.9",
+  "operatingsystemmajrelease": "9",
+  "hostname": "godard",
+  "operatingsystem": "Debian",
+  "ps": "ps -ef",
+  "fqdn": "godard.debian.org",
+  "rubysitedir": "/usr/local/lib/site_ruby/2.3.0",
+  "virtual": "kvm",
+  "is_virtual": true,
+  "architecture": "amd64",
+  "debarchitecture": "amd64",
+  "hardwaremodel": "x86_64",
+  "os": {
+    "name": "Debian",
+    "family": "Debian",
+    "release": {
+      "major": "9",
+      "minor": "3",
+      "full": "9.3"
+    },
+    "lsb": {
+      "distcodename": "stretch",
+      "distid": "Debian",
+      "distdescription": "Debian GNU/Linux 9.3 (stretch)",
+      "distrelease": "9.3",
+      "majdistrelease": "9",
+      "minordistrelease": "3"
+    }
+  },
+  "uptime_days": 0,
+  "augeasversion": "1.8.0",
+  "domain": "debian.org",
+  "osfamily": "Debian",
+  "kernelversion": "4.9.0",
+  "lsbdistdescription": "Debian GNU/Linux 9.3 (stretch)",
+  "partitions": {
+    "vda1": {
+      "uuid": "4246f2d5-6c25-4b95-933d-2a0480ff0034",
+      "size": "39057408",
+      "mount": "/",
+      "filesystem": "ext4"
+    }
+  },
+  "sshrsakey": "AAAAB3NzaC1yc2EAAAADAQABAAABAQCr4ClEmJjUlngh9cG1T9zuD60DaN1Rw/53hhz4njq86PzAo/qT88RuYEltzYrXD33nVOAhJZZkdKGiosS6bQBJhvClOC0pi6lJbbhQDaV95L/fCjXCDWZXqv3zaccE64RigqTDqtbMbJks1SOBW3wwuC4tBUldELITWusavr5mCoVRNT5INejI7nHDnfV1Fa+VNW1S27CPg0GOD1coTMfRIgXXnoCrHQ5g8h8Q6rWspNoxN5jJV5e10KCAk/DiocA4aq2UVtErH+ASjR6Zk7jQ3BVQk1cIjVER22Q3BA7zXxyKnn8Bc/Gc+HeSon4dWtDyVVlDBrCbxJW48AiWc/z9",
+  "sshfp_rsa": "SSHFP 1 1 eaa6c147facf35bc49946d9e8b90e2235c7da361\nSSHFP 1 2 f3c03414b13a6df37a3296b81774ec3e28d92e7c003667ca8e17d88433820a70",
+  "sshecdsakey": "AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBJ2Z/YmpDdiEhOi6b38hsK6v/ODtrN/BFmYLM9y67BGKwXxpOCDAYxcPPEtrsEoX0gCazpMSnsW/NPfnw5NlfUY=",
+  "sshfp_ecdsa": "SSHFP 3 1 7736297853de578792e768710eca2be1b642b1f0\nSSHFP 3 2 c12cb5369ad2a44109ac557dadd845244310d0bbc9668663f5215e56e78800ff",
+  "sshed25519key": "AAAAC3NzaC1lZDI1NTE5AAAAIKXSHb3wNeJC/stGkU/0vCAGpw4A0Zm2bfClmK+zkZWr",
+  "sshfp_ed25519": "SSHFP 4 1 676b02929dc7908278bcee876ea0f1640b8264e0\nSSHFP 4 2 3800f7a464b070e0c8b61c45fb3211bcf4d9f1408901823be44e365c37c6afce",
+  "kernelrelease": "4.9.0-5-amd64",
+  "lsbmajdistrelease": "9",
+  "netmask": "255.255.255.0",
+  "network_eth0": "209.87.16.0",
+  "network_lo": "127.0.0.0",
+  "lsbdistid": "Debian",
+  "path": "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/lib/nagios/plugins",
+  "hardwareisa": "unknown",
+  "processors": {
+    "models": [
+      "Intel Core Processor (Haswell, no TSX)",
+      "Intel Core Processor (Haswell, no TSX)",
+      "Intel Core Processor (Haswell, no TSX)",
+      "Intel Core Processor (Haswell, no TSX)"
+    ],
+    "count": 4,
+    "physicalcount": 4
+  },
+  "processor0": "Intel Core Processor (Haswell, no TSX)",
+  "processor1": "Intel Core Processor (Haswell, no TSX)",
+  "processor2": "Intel Core Processor (Haswell, no TSX)",
+  "processor3": "Intel Core Processor (Haswell, no TSX)",
+  "processorcount": 4,
+  "puppetversion": "4.8.2",
+  "ipaddress6": "2607:f8f0:614:1::1274:45",
+  "uniqueid": "57d12c10",
+  "blockdevice_vdb_size": 399998189568,
+  "blockdevice_vdb_vendor": "0x1af4",
+  "blockdevice_sr0_size": 1073741312,
+  "blockdevice_sr0_vendor": "QEMU",
+  "blockdevice_sr0_model": "QEMU DVD-ROM",
+  "blockdevice_fd0_size": 4096,
+  "blockdevice_vda_size": 19998441472,
+  "blockdevice_vda_vendor": "0x1af4",
+  "blockdevices": "fd0,sr0,vda,vdb",
+  "physicalprocessorcount": 4,
+  "lsbdistrelease": "9.3",
+  "ipaddress": "209.87.16.44",
+  "macaddress": "00:16:37:34:2f:3d",
+  "uptime_hours": 3,
+  "gid": "root",
+  "bios_vendor": "SeaBIOS",
+  "bios_version": "1.10.2-1",
+  "bios_release_date": "04/01/2014",
+  "manufacturer": "QEMU",
+  "productname": "Standard PC (i440FX + PIIX, 1996)",
+  "serialnumber": "Not Specified",
+  "uuid": "F88FF283-812B-4F43-89FC-7CCBF3DEC0CA",
+  "type": "Other",
+  "rubyversion": "2.3.3",
+  "lsbminordistrelease": "3",
+  "memorysize": "7.80 GB",
+  "memoryfree": "2.27 GB",
+  "swapsize": "12.00 GB",
+  "swapfree": "12.00 GB",
+  "swapsize_mb": "12288.00",
+  "swapfree_mb": "12285.48",
+  "memorysize_mb": "7987.60",
+  "memoryfree_mb": "2322.03",
+  "filesystems": "ext2,ext3,ext4,xfs",
+  "uptime": "3:09 hours",
+  "operatingsystemrelease": "9.3",
+  "system_uptime": {
+    "seconds": 11396,
+    "hours": 3,
+    "days": 0,
+    "uptime": "3:09 hours"
+  },
+  "interfaces": "eth0,lo",
+  "ipaddress_eth0": "209.87.16.44",
+  "ipaddress6_eth0": "2607:f8f0:614:1::1274:44",
+  "macaddress_eth0": "00:16:37:34:2f:3d",
+  "netmask_eth0": "255.255.255.0",
+  "mtu_eth0": 1500,
+  "ipaddress_lo": "127.0.0.1",
+  "netmask_lo": "255.0.0.0",
+  "mtu_lo": 65536,
+  "selinux": false,
+  "timezone": "UTC",
+  "lsbdistcodename": "stretch",
+  "uptime_seconds": 11396,
+  "facterversion": "2.4.6",
+  "brokenhosts": false,
+  "apache2": true,
+  "apache2deb9": true,
+  "clamd": false,
+  "exim4": false,
+  "postfix": true,
+  "postgres": true,
+  "postgrey": false,
+  "greylistd": false,
+  "policydweight": false,
+  "spamd": false,
+  "php5": false,
+  "php5suhosin": false,
+  "syslogversion": "3.8",
+  "unbound": true,
+  "munin_async": true,
+  "samhain": true,
+  "systemd": true,
+  "tor_ge_0_2_9": false,
+  "haveged": false,
+  "bgpd": false,
+  "zebra": false,
+  "update_grub": true,
+  "service_provider": "systemd",
+  "keyring_debian_org_mirror": false,
+  "kvmdomain": true,
+  "package_provider": "apt",
+  "root_home": "/root",
+  "has_srv_build_trees": false,
+  "has_srv_buildd": false,
+  "has_etc_ssh_ssh_host_ed25519_key": true,
+  "has_srv_mirrors_debian": false,
+  "has_srv_mirrors_debian_buildd": false,
+  "has_srv_mirrors_debian_debug": false,
+  "has_srv_mirrors_debian_ports": false,
+  "has_srv_mirrors_debian_security": false,
+  "has_srv_mirrors_public_debian": false,
+  "has_srv_mirrors_public_debian_buildd": false,
+  "has_srv_mirrors_public_debian_debug": false,
+  "has_srv_mirrors_public_debian_ports": false,
+  "has_srv_mirrors_public_debian_security": false,
+  "has_dev_hwrng": true,
+  "has_lib_udev_rules_d_60_kpartx_rules": false,
+  "onion_tor_service_hostname": "{}",
+  "onion_balance_service_hostname": "{}",
+  "is_pe": false,
+  "staging_http_get": "curl",
+  "systemproductname": "Standard PC (i440FX + PIIX, 1996)",
+  "hw_can_temp_sensors": false,
+  "v4ips": "209.87.16.44,209.87.16.45",
+  "v6ips": "2607:f8f0:614:1::1274:45,2607:f8f0:614:1::1274:44",
+  "puppet_vardir": "/var/lib/puppet",
+  "puppet_environmentpath": "/etc/puppet/code/environments",
+  "puppet_server": "puppet",
+  "mounts": "/,/dev/hugepages,/dev/mqueue,/home,/srv,/sys/fs/cgroup/blkio,/sys/fs/cgroup/cpu,cpuacct,/sys/fs/cgroup/cpuset,/sys/fs/cgroup/devices,/sys/fs/cgroup/freezer,/sys/fs/cgroup/memory,/sys/fs/cgroup/net_cls,net_prio,/sys/fs/cgroup/perf_event,/sys/fs/cgroup/pids,/sys/fs/cgroup/systemd,/sys/fs/pstore,/sys/kernel/security",
+  "smartarraycontroller": false,
+  "smartarraycontroller_cciss": false,
+  "smartarraycontroller_hpsa": false,
+  "threewarecontroller": false,
+  "megaraid": false,
+  "mptraid": false,
+  "aacraid": false,
+  "swraid": false,
+  "postgresql_key": "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC1eOzsdKsfcHFyn4fimLNeT8+KhtDqtRceH71j6k3yBUzsNzdQyjx+iSNONRLB7VYGuhRI8o1uZ4kLnpVZLDBGswBKg8Ndf89l36Fsw3BtCsgGITALWKPJ3mW3YToofbQtq9NWY9bkjA4KoUmIK4c/BJzdX6TvF8H1lWvsdphONe6p8Po3USvo5VQaQcxWzPcGlzKwsaX4djn+UVVPr+CsCZqXW9SOFxOEZEDCn4hIiJnVzh1/r0aOJfFWXrXRLmGX1CJwMUCUVZc4g39mPFfEzh0gWxPmMSP5Q0vsYK7RgQH+JKdmxYiqasfY06px87Wp5Xl2+UzToHUURSOnM+s3 postgres@godard (2017-09-01)",
+  "staticsync_user_exists": false,
+  "weblogsync_user_exists": false,
+  "buildd_user_exists": false,
+  "portforwarder_user_exists": false,
+  "mta": "postfix"
+}