UCF STIG Viewer Logo

The macOS system must disable the built-in web server.


Overview

Finding ID Version Rule ID IA Controls Severity
V-259484 APPL-14-002008 SV-259484r941074_rule Medium
Description
The built-in web server is a nonessential service built into macOS and must be disabled. Note: The built in web server service is disabled at startup by default macOS.
STIG Date
Apple macOS 14 (Sonoma) Security Technical Implementation Guide 2024-01-10

Details

Check Text ( C-63223r941072_chk )
Verify the macOS system is configured to disable the built-in web server with the following command:

/bin/launchctl print-disabled system | /usr/bin/grep -c '"org.apache.httpd" => disabled'

If the result is not "1", this is a finding.
Fix Text (F-63131r941073_fix)
Configure the macOS system to disable the built-in web server with the following command:

/bin/launchctl disable system/org.apache.httpd

The system may need to be restarted for the update to take effect.