File: README.Debian

package info (click to toggle)
modsecurity-crs 3.3.0-1~bpo10+1
  • links: PTS, VCS
  • area: main
  • in suites: buster-backports
  • size: 3,552 kB
  • sloc: ansic: 727; perl: 443; python: 297; sh: 90; ruby: 69; javascript: 53; makefile: 14
file content (24 lines) | stat: -rw-r--r-- 844 bytes parent folder | download | duplicates (7)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
modsecurity-crs for Debian
--------------------------

Updating to 3.0.0
-----------------

OWASP Core Rule Set 3.x is incompatible with 2.x and changes the directory
layout for the rule files. You should update the way rule files are Included.

To ease this job from 3.0.0-3 the rule files you may want to modify were moved
to /etc/modsecurity/crs/. Those are:
crs-setup.conf
REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf

A new file (/usr/share/modsecurity-crs/owasp-crs.load) includes those files,
and the rest of CRS rules, in the right order.

Including that file in your configuration should be enough to use CRS.
Modsecurity-apache, from 2.9.1-2, already does that for you. Everything
should work out of the box.


 -- Alberto Gonzalez Iniesta <agi@inittab.org>  Wed, 21 Dec 2016 12:36:03 +0100