12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788 |
- <IfDefine SSL>
- <IfModule !mod_ssl.c>
- LoadModule ssl_module modules/mod_ssl.so
- </IfModule>
- </IfDefine>
- <IfModule mod_ssl.c>
- #
- # This is the Apache server configuration file providing SSL support.
- # It contains the configuration directives to instruct the server how to
- # serve pages over an https connection. For detailing information about these
- # directives see <URL:http://httpd.apache.org/docs-2.0/mod/mod_ssl.html>
- #
- # Do NOT simply read the instructions in here without understanding
- # what they do. They're here only as hints or reminders. If you are unsure
- # consult the online docs. You have been warned.
- #
- #
- # Pseudo Random Number Generator (PRNG):
- # Configure one or more sources to seed the PRNG of the SSL library.
- # The seed data should be of good random quality.
- # WARNING! On some platforms /dev/random blocks if not enough entropy
- # is available. This means you then cannot use the /dev/random device
- # because it would lead to very long connection times (as long as
- # it requires to make more entropy available). But usually those
- # platforms additionally provide a /dev/urandom device which doesn't
- # block. So, if available, use this one instead. Read the mod_ssl User
- # Manual for more details.
- #
- # Note: This must come before the <IfDefine SSL> container to support
- # starting without SSL on platforms with no /dev/random equivalent
- # but a statically compiled-in mod_ssl.
- #
- SSLRandomSeed startup builtin
- SSLRandomSeed connect builtin
- #SSLRandomSeed startup file:/dev/random 512
- #SSLRandomSeed startup file:/dev/urandom 512
- #SSLRandomSeed connect file:/dev/random 512
- #SSLRandomSeed connect file:/dev/urandom 512
- #
- # When we also provide SSL we have to listen to the
- # standard HTTP port (see above) and to the HTTPS port
- #
- Listen 443
- ##
- ## SSL Global Context
- ##
- ## All SSL configuration in this context applies both to
- ## the main server and all SSL-enabled virtual hosts.
- ##
- #
- # Some MIME-types for downloading Certificates and CRLs
- #
- <IfModule mod_mime.c>
- AddType application/x-x509-ca-cert .crt
- AddType application/x-pkcs7-crl .crl
- </IfModule>
- # Pass Phrase Dialog:
- # Configure the pass phrase gathering process.
- # The filtering dialog program (`builtin' is a internal
- # terminal dialog) has to provide the pass phrase on stdout.
- SSLPassPhraseDialog builtin
- # Inter-Process Session Cache:
- # Configure the SSL Session Cache: First the mechanism
- # to use and second the expiring timeout (in seconds).
- #SSLSessionCache none
- #SSLSessionCache shmht:logs/ssl_scache(512000)
- #SSLSessionCache shmcb:logs/ssl_scache(512000)
- #SSLSessionCache dbm:/var/cache/apache2/ssl_scache
- SSLSessionCache shm:/var/cache/apache2/ssl_scache(512000)
- SSLSessionCacheTimeout 300
- # Semaphore:
- # Configure the path to the mutual exclusion semaphore the
- # SSL engine uses internally for inter-process synchronization.
- SSLMutex file:/var/cache/apache2/ssl_mutex
- </IfModule>
|