Project

Profile

Help

Issue #2288 » 25-https-reposrv.dsa.reldom.tamu.edu.conf

jreitmayer, 10/07/2016 06:27 PM

 
# ************************************
# Vhost template in module puppetlabs-apache
# Managed by Puppet
# ************************************

<VirtualHost *:443>
ServerName reposrv.dsa.reldom.tamu.edu

## Vhost docroot
DocumentRoot "/srv/pulp/wsgi"

## Directories, there should at least be a declaration for /usr/share/pulp/wsgi

<Directory "/srv/pulp/wsgi">
Options -Indexes FollowSymLinks MultiViews
AllowOverride None
Order allow,deny
Allow from all
</Directory>

## Logging
ErrorLog "/var/log/httpd/https-reposrv.dsa.reldom.tamu.edu_error_ssl.log"
LogLevel warn
ServerSignature Off
CustomLog "/var/log/httpd/https-reposrv.dsa.reldom.tamu.edu_access_ssl.log" "proxy" env=proxy
CustomLog "/var/log/httpd/https-reposrv.dsa.reldom.tamu.edu_access_ssl.log" "default" env=!proxy
## Rewrite rules
RewriteEngine On

RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK)
RewriteRule .* - [F]

SetEnvIf X-Forwarded-For "^.*\..*\..*\..*" proxy

## SSL directives
SSLEngine on
SSLCertificateFile "/etc/pki/tls/certs/reposrv.dsa.reldom.tamu.edu.cer"
SSLCertificateKeyFile "/etc/pki/tls/private/reposrv.dsa.reldom.tamu.edu.key"
SSLCertificateChainFile "/etc/pki/tls/certs/TAMU-intermediate.cer"
SSLCACertificatePath "/etc/pki/tls/certs"
SSLProtocol all -SSLv2 -SSLv3
SSLCipherSuite ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA
SSLHonorCipherOrder On
</VirtualHost>
(4-4/9)