/
var
/
lib
/
plesk
/
cfgmon
/
/var/lib/plesk/cfgmon
mkdir
upload
Name
Size
Mode
Actions
aa500_psa_tweaks.conf_2024_05_11_03_44_30_601839
32
0600
edit
dl
rm
aclr.conf_2024_05_10_14_08_47_061016
157
0644
edit
dl
rm
almalinux-snipolicy.conf_2025_12_24_03_31_45_688952
579
0644
edit
dl
rm
apachePleskAccess.php_2024_05_10_14_08_46_947710
2297
0644
edit
dl
rm
apachePleskAccess.php_2025_01_10_03_26_37_379426
2317
0644
edit
dl
rm
apachePleskAccess.php_2026_03_19_03_28_54_103966
2346
0644
edit
dl
rm
atmail.php_2024_05_10_14_08_46_988416
2022
0644
edit
dl
rm
atmail.php_2026_03_19_03_28_54_157530
2039
0644
edit
dl
rm
atmail.php_2026_05_07_03_20_46_270818
2053
0644
edit
dl
rm
autoindex.conf_2024_05_10_14_08_47_051994
2926
0644
edit
dl
rm
awstats.conf_2024_05_10_14_08_47_068674
1015
0644
edit
dl
rm
awstats.icon.conf_2024_05_10_14_08_47_079537
235
0644
edit
dl
rm
brotli.conf_2024_05_10_14_08_47_167833
171
0600
edit
dl
rm
chargen-dgram_2024_05_10_14_08_47_098016
1157
0600
edit
dl
rm
chargen-stream_2024_05_10_14_08_47_104176
1159
0600
edit
dl
rm
daytime-dgram_2024_05_10_14_08_47_108458
1157
0600
edit
dl
rm
daytime-stream_2024_05_10_14_08_47_111977
1159
0600
edit
dl
rm
discard-dgram_2024_05_10_14_08_47_115397
1157
0600
edit
dl
rm
discard-stream_2024_05_10_14_08_47_118337
1159
0600
edit
dl
rm
domainForwarding.php_2024_05_10_14_08_46_902147
1774
0644
edit
dl
rm
domainForwardingIpDefault.php_2024_05_10_14_08_46_904938
1774
0644
edit
dl
rm
domainVhost.php_2024_05_10_14_08_46_907532
1117
0644
edit
dl
rm
domainVhost.php_2026_03_19_03_28_54_050472
1145
0644
edit
dl
rm
domainVhostIpDefault.php_2024_05_10_14_08_46_910002
1117
0644
edit
dl
rm
domainVhostIpDefault.php_2026_03_19_03_28_54_056879
1145
0644
edit
dl
rm
domainVirtualHost.php_2024_05_10_14_08_46_932091
14298
0644
edit
dl
rm
domainVirtualHost.php_2025_04_11_03_38_22_713858
15232
0644
edit
dl
rm
domainVirtualHost.php_2025_09_19_03_51_51_539507
15242
0644
edit
dl
rm
domainVirtualHost.php_2026_03_19_03_28_54_083063
15593
0644
edit
dl
rm
domainVirtualHost.php_2026_05_07_03_20_46_222897
15665
0644
edit
dl
rm
domainVirtualHost.php_2026_07_09_03_17_15_329711
15723
0644
edit
dl
rm
echo-dgram_2024_05_10_14_08_47_121369
1148
0600
edit
dl
rm
echo-stream_2024_05_10_14_08_47_124906
1150
0600
edit
dl
rm
errordocs.php_2024_05_10_14_08_47_008445
411
0644
edit
dl
rm
errordocs.php_2026_03_19_03_28_54_210520
440
0644
edit
dl
rm
export.conf_2024_08_07_03_14_11_873916
178
0444
edit
dl
rm
fastcgi.conf_2024_05_10_14_08_47_160060
1139
0644
edit
dl
rm
fastcgi_params_2024_05_10_14_08_47_157114
1069
0644
edit
dl
rm
fcgid.conf_2024_05_10_14_08_47_063344
652
0644
edit
dl
rm
fixssl.conf.default_2025_07_19_03_27_41_893935
147
0644
edit
dl
rm
fixssl.conf_2025_07_19_03_27_41_806975
147
0644
edit
dl
rm
fpm.php_2024_05_10_14_08_47_011063
494
0644
edit
dl
rm
fpm.php_2025_08_05_03_34_41_624021
614
0644
edit
dl
rm
fpm.php_2026_03_19_03_28_54_218610
618
0644
edit
dl
rm
frameForwarding.php_2024_05_10_14_08_46_934469
2854
0644
edit
dl
rm
frameForwarding.php_2025_09_19_03_51_51_546658
2864
0644
edit
dl
rm
frameForwarding.php_2026_03_19_03_28_54_087619
2936
0644
edit
dl
rm
frameForwarding.php_2026_05_07_03_20_46_227949
2998
0644
edit
dl
rm
ftp_psa_2024_05_10_14_08_47_137282
435
0644
edit
dl
rm
horde.php_2024_05_10_14_08_46_992445
1076
0644
edit
dl
rm
horde.php_2026_03_19_03_28_54_165222
1099
0644
edit
dl
rm
hosts_2024_05_10_14_08_47_095362
192
0644
edit
dl
rm
httpd.conf_2024_05_10_14_08_47_153515
12119
0644
edit
dl
rm
mailAutoConfig.php_2024_05_10_14_08_47_013470
763
0644
edit
dl
rm
mailAutoConfig.php_2026_03_19_03_28_54_225689
797
0644
edit
dl
rm
mailman.conf_2024_05_10_14_08_47_058653
674
0644
edit
dl
rm
mailman.php_2024_05_10_14_08_46_950528
4307
0644
edit
dl
rm
mailman.php_2024_08_01_03_22_09_422317
4471
0644
edit
dl
rm
mailman.php_2026_03_19_03_28_54_107633
4548
0644
edit
dl
rm
mailman.php_2026_05_07_03_20_46_245760
4614
0644
edit
dl
rm
main.cf_2024_05_10_14_08_47_143455
29709
0644
edit
dl
rm
main.cf_2026_08_25_03_56_12_702034
29730
0644
edit
dl
rm
master.cf_2024_05_10_14_08_47_146460
7002
0644
edit
dl
rm
master.cf_2024_05_11_03_44_30_588414
7157
0644
edit
dl
rm
master.cf_2025_10_30_03_17_08_744493
7187
0644
edit
dl
rm
meta.db
49152
0644
edit
dl
rm
mod_fastcgi.php_2024_05_10_14_08_46_967025
129
0644
edit
dl
rm
mod_perl.php_2024_05_10_14_08_46_969719
212
0644
edit
dl
rm
mod_python.php_2024_05_10_14_08_46_972472
149
0644
edit
dl
rm
nginx.conf_2024_05_10_14_08_47_162701
980
0644
edit
dl
rm
nginx.php_2024_05_10_14_08_46_913448
1408
0644
edit
dl
rm
nginx.php_2024_05_30_03_30_04_338074
1545
0644
edit
dl
rm
nginx.php_2025_09_19_03_51_51_468932
1851
0644
edit
dl
rm
nginx.php_2026_03_19_03_28_54_065155
1860
0644
edit
dl
rm
nginxCache.php_2024_05_10_14_08_47_016230
899
0644
edit
dl
rm
nginxCache.php_2026_03_19_03_28_54_233011
901
0644
edit
dl
rm
nginxCache.php_2026_05_07_03_20_46_286727
938
0644
edit
dl
rm
nginxCacheFastCgi.php_2024_05_10_14_08_47_018809
1824
0644
edit
dl
rm
nginxCacheFastCgi.php_2026_03_19_03_28_54_240216
1840
0644
edit
dl
rm
nginxCachePath.php_2024_05_10_14_08_47_021492
1049
0644
edit
dl
rm
nginxCachePath.php_2026_03_19_03_28_54_248519
1127
0644
edit
dl
rm
nginxCacheProxy.php_2024_05_10_14_08_47_024424
1832
0644
edit
dl
rm
nginxCacheProxy.php_2026_03_19_03_28_54_254592
1848
0644
edit
dl
rm
nginxDomainForwarding.php_2024_05_10_14_08_46_915895
1495
0644
edit
dl
rm
nginxDomainForwarding.php_2024_05_30_03_30_04_404039
1609
0644
edit
dl
rm
nginxDomainForwardingIpDefault.php_2024_05_10_14_08_46_918671
1227
0644
edit
dl
rm
nginxDomainForwardingIpDefault.php_2024_05_30_03_30_04_477546
1333
0644
edit
dl
rm
nginxDomainModSecurity.php_2024_05_10_14_08_46_920750
234
0644
edit
dl
rm
nginxDomainVhost.php_2024_05_10_14_08_46_923011
1459
0644
edit
dl
rm
nginxDomainVhost.php_2024_05_30_03_30_04_517723
1565
0644
edit
dl
rm
nginxDomainVhost.php_2025_08_05_03_34_41_107425
1677
0644
edit
dl
rm
nginxDomainVhostIpDefault.php_2024_05_10_14_08_46_925159
1391
0644
edit
dl
rm
nginxDomainVhostIpDefault.php_2024_05_30_03_30_04_564859
1497
0644
edit
dl
rm
nginxDomainVhostIpDefault.php_2025_08_05_03_34_41_236511
1608
0644
edit
dl
rm
nginxDomainVirtualHost.php_2024_05_10_14_08_46_936838
10853
0644
edit
dl
rm
nginxDomainVirtualHost.php_2024_05_30_03_30_04_616692
11405
0644
edit
dl
rm
nginxDomainVirtualHost.php_2024_10_04_03_36_50_614758
11451
0644
edit
dl
rm
nginxDomainVirtualHost.php_2025_09_19_03_51_51_552473
11410
0644
edit
dl
rm
nginxDomainVirtualHost.php_2026_03_19_03_28_54_091706
11491
0644
edit
dl
rm
nginxDomainVirtualHost.php_2026_05_07_03_20_46_233003
11535
0644
edit
dl
rm
nginxDomainVirtualHost.php_2026_06_17_03_43_15_930762
11559
0644
edit
dl
rm
nginxErrordocs.php_2024_05_10_14_08_47_026661
450
0644
edit
dl
rm
nginxErrordocs.php_2026_03_19_03_28_54_261798
468
0644
edit
dl
rm
nginxErrordocs.php_2026_05_07_03_20_46_293929
472
0644
edit
dl
rm
nginxForwarding.php_2024_05_10_14_08_46_939227
2574
0644
edit
dl
rm
nginxForwarding.php_2024_05_30_03_30_04_624569
2921
0644
edit
dl
rm
nginxForwarding.php_2025_09_19_03_51_51_559622
3439
0644
edit
dl
rm
nginxForwarding.php_2026_03_19_03_28_54_095702
3553
0644
edit
dl
rm
nginxMailAutoConfig.php_2024_05_10_14_08_47_029382
576
0644
edit
dl
rm
nginxMailAutoConfig.php_2026_03_19_03_28_54_268954
589
0644
edit
dl
rm
nginxPleskAccess.php_2024_05_10_14_08_46_953488
2171
0644
edit
dl
rm
nginxPleskAccess.php_2024_05_30_03_30_04_665161
2634
0644
edit
dl
rm
nginxPleskAccess.php_2025_01_10_03_26_37_386755
2650
0644
edit
dl
rm
nginxPleskAccess.php_2025_09_19_03_51_51_575882
2745
0644
edit
dl
rm
nginxPleskAccess.php_2026_03_19_03_28_54_111344
2774
0644
edit
dl
rm
nginxProtectedDirectories.php_2024_05_10_14_08_47_031629
1145
0644
edit
dl
rm
nginxProtectedDirectories.php_2025_12_09_03_40_57_798016
1168
0644
edit
dl
rm
nginxProtectedDirectories.php_2026_02_04_03_39_27_930728
1172
0644
edit
dl
rm
nginxProtectedDirectories.php_2026_03_19_03_28_54_276553
1144
0644
edit
dl
rm
nginxProtectedDirectories.php_2026_05_07_03_20_46_299966
1155
0644
edit
dl
rm
nginxProtectedDirectoriesProxy.php_2024_05_10_14_08_47_034021
1237
0644
edit
dl
rm
nginxProtectedDirectoriesProxy.php_2025_12_09_03_40_57_804965
1260
0644
edit
dl
rm
nginxProtectedDirectoriesProxy.php_2026_02_04_03_39_27_941109
1264
0644
edit
dl
rm
nginxProtectedDirectoriesProxy.php_2026_03_19_03_28_54_284183
1239
0644
edit
dl
rm
nginxProtectedDirectoriesProxy.php_2026_05_07_03_20_46_304580
1261
0644
edit
dl
rm
nginxSeoSafeRedirects.php_2024_05_10_14_08_47_036535
1327
0644
edit
dl
rm
nginxSeoSafeRedirects.php_2026_03_19_03_28_54_291732
1303
0644
edit
dl
rm
nginxSeoSafeRedirects.php_2026_05_07_03_20_46_308975
1387
0644
edit
dl
rm
nginxSitePreview.php_2024_05_10_14_08_46_975004
465
0644
edit
dl
rm
nginxSitePreview.php_2026_03_19_03_28_54_136377
471
0644
edit
dl
rm
nginxVhosts.php_2024_05_10_14_08_46_956026
1538
0644
edit
dl
rm
nginxVhosts.php_2024_05_30_03_30_04_680484
1809
0644
edit
dl
rm
nginxVhosts.php_2025_09_19_03_51_51_580292
2309
0644
edit
dl
rm
nginxVhosts.php_2026_03_19_03_28_54_114644
2342
0644
edit
dl
rm
nginxWebmail.php_2024_05_10_14_08_46_996156
651
0644
edit
dl
rm
nginxWebmail.php_2024_05_30_03_30_04_741856
745
0644
edit
dl
rm
nginxWebmail.php_2026_03_19_03_28_54_173720
723
0644
edit
dl
rm
nginxWebmailPartial.php_2024_05_10_14_08_46_998868
1862
0644
edit
dl
rm
nginxWebmailPartial.php_2024_05_30_03_30_04_748268
2129
0644
edit
dl
rm
nginxWebmailPartial.php_2025_09_19_03_51_51_617352
2229
0644
edit
dl
rm
nginxWebmailPartial.php_2026_03_19_03_28_54_181798
2297
0644
edit
dl
rm
nginxWebmailPartial.php_2026_06_17_03_43_15_961772
2287
0644
edit
dl
rm
nginxWebstatDirectories.php_2024_05_10_14_08_47_039385
1354
0644
edit
dl
rm
nginxWebstatDirectories.php_2026_02_04_03_39_27_947411
1358
0644
edit
dl
rm
nginxWebstatDirectories.php_2026_03_19_03_28_54_299139
1391
0644
edit
dl
rm
passenger.conf_2024_05_10_15_42_21_500889
690
0644
edit
dl
rm
PCI_compliance.php_2024_05_10_14_08_46_929198
250
0644
edit
dl
rm
PCI_compliance.php_2024_05_10_14_08_46_944703
137
0644
edit
dl
rm
php.ini_2024_05_10_14_08_47_172550
2840
0644
edit
dl
rm
php.ini_2024_05_30_03_30_05_103613
2840
0644
edit
dl
rm
php.php_2024_05_10_14_08_46_977329
817
0644
edit
dl
rm
php.php_2026_05_07_03_20_46_263628
824
0644
edit
dl
rm
php_cgi_wrapper.conf_2024_05_10_14_08_47_071401
93
0644
edit
dl
rm
php_over_cgi.php_2024_05_10_14_08_46_979868
100
0644
edit
dl
rm
php_over_fastcgi.php_2024_05_10_14_08_46_982324
210
0644
edit
dl
rm
php_over_fastcgi.php_2026_03_19_03_28_54_144443
216
0644
edit
dl
rm
php_over_fpm.php_2024_05_10_14_08_46_984879
601
0644
edit
dl
rm
php_over_fpm.php_2026_03_19_03_28_54_150571
630
0644
edit
dl
rm
pleskServiceLocaldomain.php_2024_05_10_14_08_46_958713
703
0644
edit
dl
rm
pleskServiceLocaldomain.php_2026_03_19_03_28_54_118092
732
0644
edit
dl
rm
poppassd_psa_2024_05_10_14_08_47_140422
517
0644
edit
dl
rm
protectedDirectories.php_2024_05_10_14_08_47_041709
428
0644
edit
dl
rm
protectedDirectories.php_2026_02_04_03_39_27_951334
512
0644
edit
dl
rm
protected_files
882
0644
edit
dl
rm
proxy.php_2024_05_10_14_08_47_044405
967
0644
edit
dl
rm
proxy.php_2025_09_19_03_51_51_638746
1449
0644
edit
dl
rm
proxy.php_2026_03_19_03_28_54_307792
1471
0644
edit
dl
rm
remoteip.php_2024_05_10_14_08_46_961661
680
0644
edit
dl
rm
remoteip.php_2026_03_19_03_28_54_122884
670
0644
edit
dl
rm
remoteip.php_2026_05_07_03_20_46_253084
684
0644
edit
dl
rm
roundcube.conf_2024_05_10_14_08_47_175299
131
0640
edit
dl
rm
roundcube.conf_2024_05_30_03_30_05_129348
131
0640
edit
dl
rm
roundcube.conf_2024_09_11_03_28_22_560835
131
0640
edit
dl
rm
roundcube.conf_2024_10_04_03_36_50_761692
131
0640
edit
dl
rm
roundcube.conf_2025_04_11_03_38_22_839555
132
0640
edit
dl
rm
roundcube.conf_2025_08_05_03_34_42_174820
132
0640
edit
dl
rm
roundcube.conf_2026_02_04_03_39_28_021264
132
0640
edit
dl
rm
roundcube.conf_2026_03_19_03_28_54_433134
132
0640
edit
dl
rm
roundcube.conf_2026_03_26_03_20_46_893811
132
0640
edit
dl
rm
roundcube.conf_2026_04_08_03_45_25_775488
132
0640
edit
dl
rm
roundcube.conf_2026_06_03_03_31_55_933482
132
0640
edit
dl
rm
roundcube.conf_2026_07_10_04_00_21_960507
132
0640
edit
dl
rm
roundcube.conf_2026_08_13_04_04_37_231243
132
0640
edit
dl
rm
roundcube.php_2024_05_10_14_08_47_001266
1476
0644
edit
dl
rm
roundcube.php_2026_03_19_03_28_54_187911
1510
0644
edit
dl
rm
security2.conf_2024_05_10_14_08_47_085575
211
0644
edit
dl
rm
seoSafeRedirects.php_2024_05_10_14_08_47_047153
1457
0644
edit
dl
rm
seoSafeRedirects.php_2026_03_19_03_28_54_315799
1428
0644
edit
dl
rm
seoSafeRedirects.php_2026_05_07_03_20_46_316580
1512
0644
edit
dl
rm
seoSafeRedirects.php_2026_06_17_03_43_15_989582
1556
0644
edit
dl
rm
server.php_2024_05_10_14_08_46_927199
2808
0644
edit
dl
rm
server.php_2026_03_19_03_28_54_076600
2767
0644
edit
dl
rm
server.php_2026_05_07_03_20_46_213863
2781
0644
edit
dl
rm
site_isolation_settings.ini_2024_05_10_14_08_46_898422
865
0644
edit
dl
rm
smtpd.conf_2024_05_10_14_08_47_149490
206
0644
edit
dl
rm
smtpd.conf_2025_01_10_03_26_37_454179
206
0644
edit
dl
rm
ssl.conf_2024_05_10_14_08_47_091857
9622
0644
edit
dl
rm
ssl.conf_2024_05_10_14_08_47_170229
481
0644
edit
dl
rm
standardForwarding.php_2024_05_10_14_08_46_942022
2715
0644
edit
dl
rm
standardForwarding.php_2025_09_19_03_51_51_566532
2725
0644
edit
dl
rm
standardForwarding.php_2026_03_19_03_28_54_099393
2800
0644
edit
dl
rm
standardForwarding.php_2026_05_07_03_20_46_239507
2862
0644
edit
dl
rm
suspend.php_2024_05_10_14_08_47_003645
310
0644
edit
dl
rm
suspend.php_2024_05_10_14_08_47_049487
252
0644
edit
dl
rm
suspend.php_2026_03_19_03_28_54_195262
302
0644
edit
dl
rm
sysenv.conf_2024_05_10_14_08_47_065634
124
0644
edit
dl
rm
tcpmux-server_2024_05_10_14_08_47_128067
1212
0600
edit
dl
rm
time-dgram_2024_05_10_14_08_47_131632
1149
0600
edit
dl
rm
time-stream_2024_05_10_14_08_47_134673
1150
0600
edit
dl
rm
userdir.conf_2024_05_10_14_08_47_054111
1257
0644
edit
dl
rm
vhosts.php_2024_05_10_14_08_46_964352
2597
0644
edit
dl
rm
vhosts.php_2025_09_19_03_51_51_587494
2650
0644
edit
dl
rm
vhosts.php_2026_03_19_03_28_54_127504
2719
0644
edit
dl
rm
webmail.php_2024_05_10_14_08_47_005875
3388
0644
edit
dl
rm
webmail.php_2026_03_19_03_28_54_202402
3418
0644
edit
dl
rm
webmail.php_2026_05_07_03_20_46_279767
3460
0644
edit
dl
rm
webmail.php_2026_06_17_03_43_15_968732
3252
0644
edit
dl
rm
welcome.conf_2024_05_10_14_08_47_056521
575
0644
edit
dl
rm
zz010_psa_httpd.conf_2024_05_10_14_08_47_088965
454
0600
edit
dl
rm
zz010_psa_nginx.conf_2024_05_10_14_08_47_164996
391
0600
edit
dl
rm
Edit:
/var/lib/plesk/cfgmon/ssl.conf_2024_05_10_14_08_47_091857
(9622B)
# # When we also provide SSL we have to listen to the # standard HTTPS port in addition. # Listen 127.0.0.1:7081 ## ## SSL Global Context ## ## All SSL configuration in this context applies both to ## the main server and all SSL-enabled virtual hosts. ## # Pass Phrase Dialog: # Configure the pass phrase gathering process. # The filtering dialog program (`builtin' is a internal # terminal dialog) has to provide the pass phrase on stdout. SSLPassPhraseDialog exec:/usr/libexec/httpd-ssl-pass-dialog # Inter-Process Session Cache: # Configure the SSL Session Cache: First the mechanism # to use and second the expiring timeout (in seconds). SSLSessionCache shmcb:/run/httpd/sslcache(512000) SSLSessionCacheTimeout 300 # # Use "SSLCryptoDevice" to enable any supported hardware # accelerators. Use "openssl engine -v" to list supported # engine names. NOTE: If you enable an accelerator and the # server does not start, consult the error logs and ensure # your accelerator is functioning properly. # SSLCryptoDevice builtin #SSLCryptoDevice ubsec ## ## SSL Virtual Host Context ## #<VirtualHost _default_:443> # ## General setup for the virtual host, inherited from global configuration ##DocumentRoot "/var/www/html" ##ServerName www.example.com:443 # ## Use separate log files for the SSL virtual host; note that LogLevel ## is not inherited from httpd.conf. #ErrorLog logs/ssl_error_log #TransferLog logs/ssl_access_log #LogLevel warn # ## SSL Engine Switch: ## Enable/Disable SSL for this virtual host. #SSLEngine on # ## List the protocol versions which clients are allowed to connect with. ## The OpenSSL system profile is used by default. See ## update-crypto-policies(8) for more details. ##SSLProtocol all -SSLv3 ##SSLProxyProtocol all -SSLv3 # ## User agents such as web browsers are not configured for the user's ## own preference of either security or performance, therefore this ## must be the prerogative of the web server administrator who manages ## cpu load versus confidentiality, so enforce the server's cipher order. #SSLHonorCipherOrder on # ## SSL Cipher Suite: ## List the ciphers that the client is permitted to negotiate. ## See the mod_ssl documentation for a complete list. ## The OpenSSL system profile is configured by default. See ## update-crypto-policies(8) for more details. #SSLCipherSuite EECDH+AESGCM+AES128:EECDH+AESGCM+AES256:EECDH+CHACHA20:EECDH+SHA256+AES128:EECDH+SHA384+AES256:EECDH+SHA1+AES128:EECDH+SHA1+AES256:EECDH+HIGH:AESGCM+AES128:AESGCM+AES256:CHACHA20:SHA256+AES128:SHA256+AES256:SHA1+AES128:SHA1+AES256:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!3DES:!MD5:!PSK:!KRB5:!aECDH:!kDH:!EDH #SSLProxyCipherSuite PROFILE=SYSTEM # ## Point SSLCertificateFile at a PEM encoded certificate. If ## the certificate is encrypted, then you will be prompted for a ## pass phrase. Note that restarting httpd will prompt again. Keep ## in mind that if you have both an RSA and a DSA certificate you ## can configure both in parallel (to also allow the use of DSA ## ciphers, etc.) ## Some ECC cipher suites (http://www.ietf.org/rfc/rfc4492.txt) ## require an ECC certificate which can also be configured in ## parallel. #SSLCertificateFile /etc/pki/tls/certs/localhost.crt # ## Server Private Key: ## If the key is not combined with the certificate, use this ## directive to point at the key file. Keep in mind that if ## you've both a RSA and a DSA private key you can configure ## both in parallel (to also allow the use of DSA ciphers, etc.) ## ECC keys, when in use, can also be configured in parallel #SSLCertificateKeyFile /etc/pki/tls/private/localhost.key # ## Server Certificate Chain: ## Point SSLCertificateChainFile at a file containing the ## concatenation of PEM encoded CA certificates which form the ## certificate chain for the server certificate. Alternatively ## the referenced file can be the same as SSLCertificateFile ## when the CA certificates are directly appended to the server ## certificate for convenience. ##SSLCertificateChainFile /etc/pki/tls/certs/server-chain.crt # ## Certificate Authority (CA): ## Set the CA certificate verification path where to find CA ## certificates for client authentication or alternatively one ## huge file containing all of them (file must be PEM encoded) ##SSLCACertificateFile /etc/pki/tls/certs/ca-bundle.crt # ## Client Authentication (Type): ## Client certificate verification type and depth. Types are ## none, optional, require and optional_no_ca. Depth is a ## number which specifies how deeply to verify the certificate ## issuer chain before deciding the certificate is not valid. ##SSLVerifyClient require ##SSLVerifyDepth 10 # ## Access Control: ## With SSLRequire you can do per-directory access control based ## on arbitrary complex boolean expressions containing server ## variable checks and other lookup directives. The syntax is a ## mixture between C and Perl. See the mod_ssl documentation ## for more details. ##<Location /> ##SSLRequire ( %{SSL_CIPHER} !~ m/^(EXP|NULL)/ \ ## and %{SSL_CLIENT_S_DN_O} eq "Snake Oil, Ltd." \ ## and %{SSL_CLIENT_S_DN_OU} in {"Staff", "CA", "Dev"} \ ## and %{TIME_WDAY} >= 1 and %{TIME_WDAY} <= 5 \ ## and %{TIME_HOUR} >= 8 and %{TIME_HOUR} <= 20 ) \ ## or %{REMOTE_ADDR} =~ m/^192\.76\.162\.[0-9]+$/ ##</Location> # ## SSL Engine Options: ## Set various options for the SSL engine. ## o FakeBasicAuth: ## Translate the client X.509 into a Basic Authorisation. This means that ## the standard Auth/DBMAuth methods can be used for access control. The ## user name is the `one line' version of the client's X.509 certificate. ## Note that no password is obtained from the user. Every entry in the user ## file needs this password: `xxj31ZMTZzkVA'. ## o ExportCertData: ## This exports two additional environment variables: SSL_CLIENT_CERT and ## SSL_SERVER_CERT. These contain the PEM-encoded certificates of the ## server (always existing) and the client (only existing when client ## authentication is used). This can be used to import the certificates ## into CGI scripts. ## o StdEnvVars: ## This exports the standard SSL/TLS related `SSL_*' environment variables. ## Per default this exportation is switched off for performance reasons, ## because the extraction step is an expensive operation and is usually ## useless for serving static content. So one usually enables the ## exportation for CGI and SSI requests only. ## o StrictRequire: ## This denies access when "SSLRequireSSL" or "SSLRequire" applied even ## under a "Satisfy any" situation, i.e. when it applies access is denied ## and no other module can change it. ## o OptRenegotiate: ## This enables optimized SSL connection renegotiation handling when SSL ## directives are used in per-directory context. ##SSLOptions +FakeBasicAuth +ExportCertData +StrictRequire #<FilesMatch "\.(cgi|shtml|phtml|php)$"> # SSLOptions +StdEnvVars #</FilesMatch> #<Directory "/var/www/cgi-bin"> # SSLOptions +StdEnvVars #</Directory> # ## SSL Protocol Adjustments: ## The safe and default but still SSL/TLS standard compliant shutdown ## approach is that mod_ssl sends the close notify alert but doesn't wait for ## the close notify alert from client. When you need a different shutdown ## approach you can use one of the following variables: ## o ssl-unclean-shutdown: ## This forces an unclean shutdown when the connection is closed, i.e. no ## SSL close notify alert is sent or allowed to be received. This violates ## the SSL/TLS standard but is needed for some brain-dead browsers. Use ## this when you receive I/O errors because of the standard approach where ## mod_ssl sends the close notify alert. ## o ssl-accurate-shutdown: ## This forces an accurate shutdown when the connection is closed, i.e. a ## SSL close notify alert is sent and mod_ssl waits for the close notify ## alert of the client. This is 100% SSL/TLS standard compliant, but in ## practice often causes hanging connections with brain-dead browsers. Use ## this only for browsers where you know that their SSL implementation ## works correctly. ## Notice: Most problems of broken clients are also related to the HTTP ## keep-alive facility, so you usually additionally want to disable ## keep-alive for those clients, too. Use variable "nokeepalive" for this. ## Similarly, one has to force some clients to use HTTP/1.0 to workaround ## their broken HTTP/1.1 implementation. Use variables "downgrade-1.0" and ## "force-response-1.0" for this. #BrowserMatch "MSIE [2-5]" \ # nokeepalive ssl-unclean-shutdown \ # downgrade-1.0 force-response-1.0 # ## Per-Server Logging: ## The home of a custom SSL log file. Use this when you want a ## compact non-error SSL logfile on a virtual host basis. #CustomLog logs/ssl_request_log \ # "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b" # #</VirtualHost> <IfModule mod_ssl.c> SSLProtocol +TLSv1.2 +TLSv1.3 </IfModule> <IfModule mod_ssl.c> SSLCipherSuite EECDH+AESGCM+AES128:EECDH+AESGCM+AES256:EECDH+CHACHA20:EECDH+SHA256+AES128:EECDH+SHA384+AES256:EECDH+SHA1+AES128:EECDH+SHA1+AES256:EECDH+HIGH:AESGCM+AES128:AESGCM+AES256:CHACHA20:SHA256+AES128:SHA256+AES256:SHA1+AES128:SHA1+AES256:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!3DES:!MD5:!PSK:!KRB5:!aECDH:!kDH:!EDH SSLHonorCipherOrder on </IfModule>
Save
cmd:
run