Hide Tengine version number with server_tokens off

2026-09-30

By default, Tengine advertises its exact version in the Server response header and on error pages: Server: Tengine/3.1.0. Attackers scan for that banner and immediately try known exploits for that version. Hiding it is one directive and removes the easiest fingerprinting vector on your server.

The fix

Add to the http block (applies to all servers):

http {
    server_tokens off;
}

After reload, the header becomes just Server: Tengine with no version, and error pages no longer print nginx/1.26.x style banners.

Verify

nginx -t && nginx -s reload
curl -I https://yourdomain.com/ | grep -i server

You want Server: Tengine (no digits). Trigger a 404 to check error pages too: curl -k https://yourdomain.com/nonexistent.

What it does NOT do

Summary

server_tokens off removes the version banner from headers and error pages in one line — the cheapest hardening step on the list. Combine it with the header block and your server stops announcing itself entirely.

Related articles