Hide Tengine version number with server_tokens off
2026-09-30
By default, Tengine advertises its exact version in the Server response header and on error pages: Server: Tengine/3.1.0. Attackers scan for that banner and immediately try known exploits for that version. Hiding it is one directive and removes the easiest fingerprinting vector on your server.
The fix
Add to the http block (applies to all servers):
http {
server_tokens off;
}
After reload, the header becomes just Server: Tengine with no version, and error pages no longer print nginx/1.26.x style banners.
Verify
nginx -t && nginx -s reload
curl -I https://yourdomain.com/ | grep -i server
You want Server: Tengine (no digits). Trigger a 404 to check error pages too: curl -k https://yourdomain.com/nonexistent.
What it does NOT do
- It is obscurity, not a fix — sophisticated scanners fingerprint behavior, not just headers. Keep Tengine patched regardless.
- It does not remove the version from
nginx -Voutput or from the binary itself; it only stops public exposure. - Pair it with security headers and rate limiting for a reasonable baseline.
Summary
server_tokens off removes the version banner from headers and error pages in one line — the cheapest hardening step on the list. Combine it with the header block and your server stops announcing itself entirely.