This is an old revision of the document!
Securing Apache (httpd)
Right now, the main consideration is, SECURE THE /CGI-BIN! The only persons that need access to this directory are Evergreen system administrators. This directory should be restricted by both IP (to those workstations designated as Evergeen Administration systems), AND by Username/password AT THE LEAST.
Good news: Even if a user gets access to this directory, there's nothing extremely damaging that can be done. Almost everything in the bootstrapping script will have references to it, and therefore cannot be deleted. However, a user can add new libraries, re-arrange consortia, and change user groups. The worst thing (I can imagine at the moment) is a staff member could access the directory, and change his associated security group to administrative level privileges.