Skip to content

Instantly share code, notes, and snippets.

@ernetas
Created April 3, 2014 15:10
Show Gist options
  • Save ernetas/9956209 to your computer and use it in GitHub Desktop.
Save ernetas/9956209 to your computer and use it in GitHub Desktop.
root@cacti:/etc/apache2# grep -R "SSL" ./
./sites-enabled/default: SSLEngine on
./sites-enabled/default: SSLCertificateFile certs/server/certificates/cacti.crt
./sites-enabled/default: SSLCertificateKeyFile certs/server/keys/cacti.key
./sites-enabled/default: SSLCACertificateFile certs/CA/monitoringCA.crt
./sites-enabled/default: SSLVerifyClient require
./sites-enabled/default: SSLVerifyDepth 2
./sites-enabled/default:# SSLEngine on
./sites-enabled/default:# SSLCertificateFile /etc/apache2/ssl/samesystem.crt
./sites-enabled/default:# SSLCertificateKeyFile /etc/apache2/ssl/samesystem.key
./sites-enabled/default:# SSLCACertificateFile /etc/apache2/ssl/ca.pem
./sites-enabled/default:# SSLCertificateChainFile /etc/apache2/ssl/chain.pem
./sites-enabled/default: SSLProtocol ALL -SSLv2
./sites-enabled/default:# SSLCipherSuite ALL:!ADH:!EXPORT:!SSLv2:RC4+RSA:+HIGH:+MEDIUM
./sites-enabled/default:# SSLCipherSuite aRSA:kRSA:AES128-CBC:SHA
./sites-available/000-default: SSLEngine on
./sites-available/000-default: SSLCertificateFile certs/server/certificates/cacti.crt
./sites-available/000-default: SSLCertificateKeyFile certs/server/keys/cacti.key
./sites-available/000-default: SSLCACertificateFile certs/CA/monitoringCA.crt
./sites-available/000-default: SSLVerifyClient require
./sites-available/000-default: SSLVerifyDepth 2
./sites-available/000-default:# SSLEngine on
./sites-available/000-default:# SSLCertificateFile /etc/apache2/ssl/samesystem.crt
./sites-available/000-default:# SSLCertificateKeyFile /etc/apache2/ssl/samesystem.key
./sites-available/000-default:# SSLCACertificateFile /etc/apache2/ssl/ca.pem
./sites-available/000-default:# SSLCertificateChainFile /etc/apache2/ssl/chain.pem
./sites-available/000-default: SSLProtocol ALL -SSLv2
./sites-available/000-default:# SSLCipherSuite ALL:!ADH:!EXPORT:!SSLv2:RC4+RSA:+HIGH:+MEDIUM
./sites-available/000-default:# SSLCipherSuite aRSA:kRSA:AES128-CBC:SHA
./mods-available/ssl.conf:# Configure one or more sources to seed the PRNG of the SSL library.
./mods-available/ssl.conf:SSLRandomSeed startup builtin
./mods-available/ssl.conf:SSLRandomSeed startup file:/dev/urandom 512
./mods-available/ssl.conf:SSLRandomSeed connect builtin
./mods-available/ssl.conf:SSLRandomSeed connect file:/dev/urandom 512
./mods-available/ssl.conf:## SSL Global Context
./mods-available/ssl.conf:## All SSL configuration in this context applies both to
./mods-available/ssl.conf:## the main server and all SSL-enabled virtual hosts.
./mods-available/ssl.conf:SSLPassPhraseDialog exec:/usr/share/apache2/ask-for-passphrase
./mods-available/ssl.conf:# Configure the SSL Session Cache: First the mechanism
./mods-available/ssl.conf:#SSLSessionCache dbm:${APACHE_RUN_DIR}/ssl_scache
./mods-available/ssl.conf:SSLSessionCache shmcb:${APACHE_RUN_DIR}/ssl_scache(512000)
./mods-available/ssl.conf:SSLSessionCacheTimeout 300
./mods-available/ssl.conf:# SSL engine uses internally for inter-process synchronization.
./mods-available/ssl.conf:SSLMutex file:${APACHE_RUN_DIR}/ssl_mutex
./mods-available/ssl.conf:# SSL Cipher Suite:
./mods-available/ssl.conf:#SSLCipherSuite HIGH:MEDIUM:!ADH:!MD5
./mods-available/ssl.conf:#SSLRequire %{SSL_CIPHER_USEKEYSIZE} >= 128
./mods-available/ssl.conf:#SSLCipherSuite ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL
./mods-available/ssl.conf:#SSLCipherSuite ALL
./mods-available/ssl.conf:# enable only secure protocols: SSLv3 and TLSv1, but not SSLv2
./mods-available/ssl.conf:#SSLProtocol all +SSLv3 -SSLv2
./mods-available/ssl.conf:#SSLInsecureRenegotiation on
./mods-available/ssl.conf:#SSLStrictSNIVHostCheck On
./ports.conf: # Server Name Indication for SSL named virtual hosts is currently not
./certs/server/certificates/cacti.crt: OpenSSL Generated Certificate
root@cacti:/etc/apache2#
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment