Advertisement
Guest User

SSL Apache Config

a guest
Apr 30th, 2016
82
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. <IfModule mod_ssl.c>
  2.     <VirtualHost *:443>
  3.         ServerName ...
  4.         DocumentRoot ....
  5.         ErrorLog ${APACHE_LOG_DIR}/error.log
  6.        
  7.         SSLEngine on
  8.         SSLHonorCipherOrder On
  9.         SSLCompression off
  10.        
  11.         SSLProtocol ALL -SSLv2 -SSLv3
  12.         SSLCipherSuite EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-GCM-SHA256:AES256+EDH:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4
  13.  
  14.         SSLCertificateFile   /etc/ssl/....crt
  15.         SSLCertificateKeyFile  /etc/ssl/....key
  16.         SSLCertificateChainFile    /etc/ssl/....crt
  17.         SetEnvIf    User-Agent   ".*MSIE.*"   nokeepalive \ ssl-unclean-shutdown
  18.         SSLCACertificateFile /etc/ssl/....ca.pem
  19.        
  20.         CustomLog ${APACHE_LOG_DIR}/ssl_access.log combined
  21.     </VirtualHost>
  22. </IfModule>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement