tweak httpd ssl cipher params

This commit is contained in:
Trevor Batley 2023-08-30 14:51:36 +10:00
parent 1c3cc566ed
commit a6bf8d2d59

View File

@ -284,9 +284,9 @@ SSLRandomSeed connect builtin
LogLevel warn LogLevel warn
SSLEngine on SSLEngine on
SSLProtocol -all +TLSv1.2
SSLCipherSuite EECDH+ECDSA+AESGCM:EECDH+aRSA+AESGCM:EECDH+ECDSA+SHA384:EECDH+ECDSA+SHA256:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:EDH+aRSA:HIGH:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSS:!RC4:!DH:!SHA1
SSLHonorCipherOrder on SSLHonorCipherOrder on
SSLCipherSuite PROFILE=SYSTEM
SSLProxyCipherSuite PROFILE=SYSTEM
SSLCertificateFile $KOJI_PKI_DIR/kojihub.pem SSLCertificateFile $KOJI_PKI_DIR/kojihub.pem
SSLCertificateKeyFile $KOJI_PKI_DIR/private/kojihub.key SSLCertificateKeyFile $KOJI_PKI_DIR/private/kojihub.key