[
2015/09/08 21:04 | by 逍遥花主 ]
data:image/s3,"s3://crabby-images/9ebaa/9ebaabfc977338cdca2189de02449df1b2c8b7fc" alt="不指定 不指定"
无聊,看了下网站的SSL配置在ssllabs.com的测试评分,结果才A-
上网找了很多资料,大部分都是NGINX用的,Apache的没有,只有用上的强大的google,上国外的网站找了些资料完善了
就是下面的配置了,目前兼容性方面,XP下IE6不兼容,其它的不在话下
Strict Transport Security (HSTS)
Forward Secrecy
都不是问题
<IfModule ssl_module>
Listen 0.0.0.0:443
AddType application/x-x509-ca-cert .crt
AddType application/x-pkcs7-crl .crl
SSLProtocol ALL -SSLv2 -SSLv3
SSLInsecureRenegotiation off
SSLHonorCipherOrder on
SSLCipherSuite EECDH+CHACHA20:EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DES:RSA+3DES:!MD5
Header add Strict-Transport-Security "max-age=15768000"
SSLPassPhraseDialog builtin
SSLSessionCache dbm:/usr/local/apache/logs/ssl_scache
SSLSessionCacheTimeout 300
#SSLMutex file:/usr/local/apache/logs/ssl_mutex
SSLRandomSeed startup builtin
SSLRandomSeed connect builtin
</IfModule>
发表评论
东莞律师 data:image/s3,"s3://crabby-images/5e5bd/5e5bd1dc22f6fe762a28d3ec79877e99e4d8370b" alt="访问他/她的主页 Homepage"
data:image/s3,"s3://crabby-images/5e5bd/5e5bd1dc22f6fe762a28d3ec79877e99e4d8370b" alt="访问他/她的主页 Homepage"
2020/11/30 15:42
确实只有用上的强大的google
分页: 1/1
1
data:image/s3,"s3://crabby-images/4a97a/4a97aed47db4df3a76f5b370a32ad00fc4d8eb33" alt="第一页 第一页"
data:image/s3,"s3://crabby-images/8947e/8947e6e4af9a415dcc578cf6f7310cc691099c0c" alt="最后页 最后页"