1 | # SYN-3 apache SSL config file. Will be overwritten by updates. |
---|
2 | |
---|
3 | |
---|
4 | Listen 443 |
---|
5 | |
---|
6 | # Some MIME-types for downloading Certificates and CRLs |
---|
7 | AddType application/x-x509-ca-cert .crt |
---|
8 | AddType application/x-pkcs7-crl .crl |
---|
9 | |
---|
10 | |
---|
11 | # Inter-Process Session Cache: |
---|
12 | SSLSessionCache shmcb:/var/run/ssl_scache(512000) |
---|
13 | SSLSessionCacheTimeout 300 |
---|
14 | |
---|
15 | |
---|
16 | # Protocol and cipher settings |
---|
17 | # (from https://mozilla.github.io/server-side-tls/ssl-config-generator/?server=apache-2.4.18&openssl=1.0.1t&hsts=no&profile=intermediate ) |
---|
18 | |
---|
19 | SSLProtocol all -SSLv3 |
---|
20 | SSLCipherSuite ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS |
---|
21 | SSLHonorCipherOrder on |
---|
22 | SSLCompression off |
---|
23 | SSLSessionTickets off |
---|
24 | |
---|
25 | #off: otherwise you'll get timeouts when the server has no internet |
---|
26 | SSLUseStapling off |
---|
27 | SSLStaplingResponderTimeout 5 |
---|
28 | SSLStaplingReturnResponderErrors off |
---|
29 | SSLStaplingCache shmcb:/var/run/ocsp(128000) |
---|
30 | |
---|
31 | |
---|
32 | ## |
---|
33 | ## SSL Virtual Host Context |
---|
34 | ## |
---|
35 | |
---|
36 | <VirtualHost _default_:443> |
---|
37 | |
---|
38 | DocumentRoot "/var/www/htdocs" |
---|
39 | |
---|
40 | SSLEngine on |
---|
41 | |
---|
42 | |
---|
43 | # Certificate stuff |
---|
44 | SSLCertificateFile /usr/webint/ssl/server.crt |
---|
45 | SSLCertificateKeyFile /usr/webint/ssl/server.pem |
---|
46 | SSLCertificateChainFile /usr/webint/ssl/server.crt |
---|
47 | |
---|
48 | #SSLCACertificatePath /etc/apache2/ssl.crt |
---|
49 | #SSLCACertificateFile /etc/apache2/ssl.crt/ca-bundle.crt |
---|
50 | #SSLCARevocationPath /etc/apache2/ssl.crl |
---|
51 | #SSLCARevocationFile /etc/apache2/ssl.crl/ca-bundle.crl |
---|
52 | |
---|
53 | |
---|
54 | |
---|
55 | |
---|
56 | # SSL Engine Options: |
---|
57 | <FilesMatch "\.(cgi|shtml|phtml|php)$"> |
---|
58 | SSLOptions +StdEnvVars |
---|
59 | </FilesMatch> |
---|
60 | <Directory "/var/www/cgi-bin"> |
---|
61 | SSLOptions +StdEnvVars |
---|
62 | </Directory> |
---|
63 | |
---|
64 | RewriteEngine on |
---|
65 | RewriteOptions inherit |
---|
66 | |
---|
67 | </VirtualHost> |
---|