Bug#681283: apache2-mpm-prefork: Prevent some files and folders from being viewed o clients.

Package: apache2-mpm-prefork
Version: 2.2.16-6+squeeze7
Severity: minor

This builds on what already exists in httpd.conf.
<Files ~ "^\.(ht|ssh)">
    Order allow,deny
    Deny from all
    Satisfy all
AliasMatch /\.(ht|ssh) /non-existant-page

The AliasMatch may seam to overrid the first part, but I though that
it may be commented by default.  The goal here is to allow the www-data
user to have a non-existant .ssh configuration with un-password protected
private keys to be used in accessing remote git
repositories(gitolite/Ruby-Passanger/GitLab) omong other things.

I also request that since /var/www is this users home folder AND
also DocumentRoot that usual user configuration files be added to
this list.  It may seam prudent to simply seperate the two, however at
this point I'd say that you may be breaking a known convention.  Thus
I wouldn't recommend that.

Other files I was thinking of:
Mail|Maildir (perhaps)

Plus commented rules to hide or secure common RCS folders and files:

Reply to: