ModSecurity as an option
Hi, guys. What do you think about adding ModSecurity as an option to BOA?
https://www.modsecurity.org https://github.com/SpiderLabs/ModSecurity https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
We have looked at this a long time ago when there was no good enough ModSecurity version for Nginx. We have used it in Apache for years before, so if it works fine with Nginx now, sure, we will add it.
Note: previously it required installing Apache, but there is a progress in building this without Apache and also as a dynamic nginx module.
Related issues and articles:
https://www.nginx.com/blog/nginx-plus-r10-released/ https://github.com/SpiderLabs/ModSecurity/issues/603 https://github.com/SpiderLabs/ModSecurity/tree/libmodsecurity/ https://github.com/SpiderLabs/ModSecurity-nginx