Stop Apache Sling WebDAV or not
In the Security Checklist for AEM 6.4 in the section Disable WebDAV, it mentions stopping the following bundles:
- Apache Sling Simple WebDAV Access to repositories (org.apache.sling.jcr.webdav)
- Apache Sling DavEx Access to repositories (org.apache.sling.jcr.davex)
However in Security Checks in the Operation Dashboard there is a health check for WebDAV Health Check. (Tools -> Operations -> Health Reports -> Security Checks -> WebDAV Health Check). In that Health Check it will issue a warning if "Apache Sling Simple WebDAV Access to repositories" is disabled.
The information displayed in the health check is:
- INFO The WebDav bundle should be available and active in all runmodes.
- INFO On instances started in author or publish + sampleconent runmodes the SimpleWebDavServlet should be configured.
With status:
- [WARN] The Sling WebDav bundle is NOT active.
- [WARN] The SimpleWebDavServlet is NOT configured.
Which is correct or more secure? Should the bundle be stopped, or should it be configured?
...
clint