Header unset Strict-Transport-Security
Header set Strict-Transport-Security "max-age=864000"
# Make sure we load everything via HTTPS
- Header set Content-Security-Policy "upgrade-insecure-requests"
+ Header add Content-Security-Policy "upgrade-insecure-requests"
#########################################################
# SSL configuration below ###############################
SSLCipherSuite 'kEECDH+AESGCM:kEDH+AESGCM:kEECDH:kEDH:AESGCM:ALL:!3DES:!EXPORT:!LOW:!MEDIUM:!aNULL:!eNULL'
SSLHonorCipherOrder on
- # Certificate, DH parameters and key
- SSLCertificateFile /etc/ssl/mycerts/$cert.crt+dh
+ # DH parameters
+ SSLOpenSSLConfCmd DHParameters "/etc/ssl/dh2048.pem"
+
+ # Certificate and key
+ SSLCertificateFile /etc/ssl/mycerts/$cert.crt
SSLCertificateKeyFile /etc/ssl/private/$cert.key
# Server Certificate Chain:
# the referenced file can be the same as SSLCertificateFile
# when the CA certificates are directly appended to the server
# certificate for convinience.
- SSLCertificateChainFile /etc/ssl/mycerts/$cert.chain
+ SSLCertificateChainFile /etc/ssl/mycerts/$cert.crt
# Certificate Authority (CA):
# Set the CA certificate verification path where to find CA