diff --git a/.htaccess b/.htaccess
index fd7bd29..c29b0d5 100644
--- a/.htaccess
+++ b/.htaccess
@@ -39,6 +39,9 @@ AddEncoding gzip svgz
   php_value mbstring.http_input             pass
   php_value mbstring.http_output            pass
   php_flag mbstring.encoding_translation    off
+  # PHP 5.6 has deprecated $HTTP_RAW_POST_DATA and produces warnings if this is
+  # not set.
+  php_value always_populate_raw_post_data   -1
 </IfModule>
 
 # Requires mod_expires to be enabled.
diff --git a/core/modules/rest/src/Tests/CreateTest.php b/core/modules/rest/src/Tests/CreateTest.php
index 98b944a..4badd7d 100644
--- a/core/modules/rest/src/Tests/CreateTest.php
+++ b/core/modules/rest/src/Tests/CreateTest.php
@@ -308,6 +308,8 @@ public function createAccountPerEntity($entity_type) {
    *   The body for the POST request.
    */
   public function assertCreateEntityOverRestApi($entity_type, $serialized = NULL) {
+    // Note: this will fail with PHP 5.6 when always_populate_raw_post_data is
+    // set to something other than -1. See https://www.drupal.org/node/2456025.
     $this->httpRequest('entity/' . $entity_type, 'POST', $serialized, $this->defaultMimeType);
     $this->assertResponse(201);
   }
diff --git a/core/modules/rest/src/Tests/CsrfTest.php b/core/modules/rest/src/Tests/CsrfTest.php
index a686f448..21f918a 100644
--- a/core/modules/rest/src/Tests/CsrfTest.php
+++ b/core/modules/rest/src/Tests/CsrfTest.php
@@ -80,6 +80,8 @@ public function testCookieAuth() {
     $curl_options = $this->getCurlOptions();
 
     // Try to create an entity without the CSRF token.
+    // Note: this will fail with PHP 5.6 and always_populate_raw_post_data
+    // set to something other than -1. See https://www.drupal.org/node/2456025.
     $this->curlExec($curl_options);
     $this->assertResponse(403);
     // Ensure that the entity was not created.
