renewal-ssl 905 B

1234567891011121314151617181920212223
  1. <VirtualHost *:443>
  2. <IfModule mod_headers.c>
  3. Header always set Strict-Transport-Security "max-age=63072000; includeSubdomains; preload"
  4. Header always set X-Frame-Options DENY
  5. Header always set X-Content-Type-Options nosniff
  6. </IfModule>
  7. DocumentRoot /var/www/renewal
  8. ServerName www.hory.me
  9. SSLEngine on
  10. SSLProtocol All -SSLv2 -SSLv3 -TLSv1
  11. SSLCipherSuite ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES256-SHA
  12. SSLHonorCipherOrder On
  13. SSLCompression off
  14. SSLCertificateFile /etc/letsencrypt/live/www.hory.me/fullchain.pem
  15. SSLCertificateKeyFile /etc/letsencrypt/live/www.hory.me/privkey.pem
  16. SSLCertificateChainFile /etc/letsencrypt/live/www.hory.me/chain.pem
  17. SSLCACertificateFile /etc/letsencrypt/live/www.hory.me/cert.pem
  18. </VirtualHost>