You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 
 

48 lines
1.5 KiB

  1. ServerName {{ FQDN }}
  2. <VirtualHost *:80>
  3. ServerName www.{{ FQDN }}
  4. ServerAlias {{ FQDN }}
  5. # Redirect permanent / https://www.{{ FQDN }}/
  6. Redirect / https://www.{{ FQDN }}/
  7. </VirtualHost>
  8. <VirtualHost *:443>
  9. ServerName www.{{ FQDN }}
  10. ServerAlias {{ FQDN }}
  11. DocumentRoot /var/www/html
  12. <Directory /var/www/html/>
  13. Options Indexes FollowSymLinks
  14. AllowOverride None
  15. Require all granted
  16. </Directory>
  17. SSLEngine on
  18. SSLCertificateFile {{ SSL_CERTIFICATE_FILE }}
  19. SSLCertificateKeyFile {{ SSL_CERTIFICATE_KEY_FILE }}
  20. </VirtualHost>
  21. <VirtualHost *:443>
  22. ServerName profiles.{{ FQDN }}
  23. ProxyPass / http://profiles:8108/
  24. ProxyPassReverse / http://profiles:8108/
  25. SSLEngine on
  26. SSLCertificateFile {{ SSL_CERTIFICATE_FILE }}
  27. SSLCertificateKeyFile {{ SSL_CERTIFICATE_KEY_FILE }}
  28. </VirtualHost>
  29. SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
  30. SSLCipherSuite ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256
  31. SSLHonorCipherOrder on
  32. SSLCompression off
  33. SSLSessionTickets off
  34. {% if not DEBUG %}
  35. SSLUseStapling on
  36. SSLStaplingResponderTimeout 5
  37. SSLStaplingReturnResponderErrors off
  38. SSLStaplingCache shmcb:/var/run/ocsp(128000)
  39. {% endif %}
  40. ErrorLog /dev/stderr
  41. TransferLog /dev/stdout