-
SSL协定类型设定
- sudo vim /etc/apache2/mods-enabled/ssl.conf
- [setting value]
SSLHonorCipherOrder on
SSLCipherSuite ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!CBC:!NULL:!aNULL:!MD5:!ADH:!RC4:!DH:!DHE
SSLProtocol -All -SSLv3 +TLSv1 +TLSv1.1 +TLSv1.2 (TLSv1非必要建议关掉,可提升安全性)
-
SSL证书配置
- 产生
sudo cp /usr/local/ssl/openssl.cnf ~
vim openssl.cnf
[setting value]
[ req ] 底下加入 req_extensions = v3_req
增加标签 [ alt_names ] 并在底下加入
DNS.1 = www.domian-a.com
DNS.2 = www.domian-b.com
DNS.3 = www.domian-c.com
openssl req -new -key
- 产生
Ubuntu Apache SSL配置
最新推荐文章于 2025-06-16 13:06:35 发布