002-default-ssl.conf 1.4 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546
  1. <VirtualHost _default_:443>
  2. DocumentRoot "/srv/www/apache"
  3. #ServerName www.example.com:443
  4. ServerAdmin webmaster@localhost
  5. ErrorLog ${APACHE_LOG_DIR}/002-default-ssl.error.log
  6. CustomLog ${APACHE_LOG_DIR}/002-default-ssl.access.log combined
  7. SSLEngine on
  8. SSLCertificateFile "/etc/apache/server.crt"
  9. SSLCertificateKeyFile "/etc/apache/server.key"
  10. #SSLCertificateChainFile "/etc/apache/server-ca.crt"
  11. #SSLProtocol All -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
  12. SSLProtocol All -SSLv2 -SSLv3
  13. SSLCipherSuite EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH
  14. SSLHonorCipherOrder On
  15. SSLCompression off
  16. SSLUseStapling on
  17. SSLStaplingCache "shmcb:logs/stapling-cache(150000)"
  18. # Requires Apache >= 2.4.11
  19. SSLSessionTickets Off
  20. #Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
  21. #Header always set X-Frame-Options DENY
  22. #Header always set X-Content-Type-Options nosniff
  23. <FilesMatch "\.(cgi|shtml|phtml|php)$">
  24. SSLOptions +StdEnvVars
  25. </FilesMatch>
  26. <Directory "/srv/www/apache/cgi-bin">
  27. SSLOptions +StdEnvVars
  28. </Directory>
  29. BrowserMatch "MSIE [2-5]" \
  30. nokeepalive ssl-unclean-shutdown \
  31. downgrade-1.0 force-response-1.0
  32. CustomLog ${APACHE_LOG_DIR}/002-default-ssl.ssl_request.log ssl_info
  33. CustomLog ${APACHE_LOG_DIR}/002-default-ssl.ssl_browser.log ssl_info_browser
  34. </VirtualHost>
  35. # vim: syntax=apache ts=4 sw=4 sts=4 sr noet