forked from jan/cacert-devsetup
22 lines
711 B
Text
22 lines
711 B
Text
|
<VirtualHost *:443>
|
||
|
ServerName mgr.cacert.localhost
|
||
|
ServerAlias www.mgr.cacert.localhost
|
||
|
DocumentRoot /var/www/manager/public
|
||
|
|
||
|
SSLEngine on
|
||
|
SSLStrictSNIVHostCheck on
|
||
|
SSLProtocol all -SSLv2 -SSLv3 -TLSv1
|
||
|
SSLHonorCipherOrder on
|
||
|
SSLCipherSuite kEECDH:kEDH:AESGCM:ALL:!3DES!RC4:!LOW:!EXP:!MD5:!aNULL:!eNULL
|
||
|
SSLCertificateFile /etc/ssl/certs/mgr.cacert.localhost.crt.pem
|
||
|
SSLCertificateKeyFile /etc/ssl/private/mgr.cacert.localhost.key.pem
|
||
|
SSLCertificateChainFile /etc/ssl/certs/combined.crt
|
||
|
|
||
|
SSLCACertificateFile /etc/ssl/certs/combined.crt
|
||
|
SSLVerifyClient require
|
||
|
SSLVerifyDepth 2
|
||
|
SSLOptions +StdEnvVars
|
||
|
|
||
|
Header always set Strict-Transport-Security "max-age=31536000"
|
||
|
</VirtualHost>
|