I want to use different ciphers with Apache, using CustomBuild 2.0
Use '%' for wildcards and quotes for "exact phrases"
|I want to use different ciphers with Apache, using CustomBuild 2.0||Last Modified: Apr 12, 2016, 4:24 pm|
|With the ever evolving needs for security, good encryption cipher lists can change regularly. Also, the needs of those connecting to a given server may be different from box to box, eg:|
etc.. so each case might be different.
- some servers require the maximum standards of security
- some clients have old browsers which cannot use modern ciphers
- some API scripts cannot use modern ciphers
To use different ciphers with Apache 2.x and CustomBuild 2.0, you can use the "custom" folder method to manage your own cipher lists and ssl rules.
Run the following:
cd /usr/local/directadmin/custombuildwhich then lets you edit:
mkdir -p custom/ap2/conf/extra
cp configure/ap2/conf/extra/httpd-ssl.conf custom/ap2/conf/extra/httpd-ssl.conf
/usr/local/directadmin/custombuild/custom/ap2/conf/extra/httpd-ssl.conffor changes such as:
SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1for example, if you wanted a more secure list of ciphers.
Note: the SSLCipherSuite list is all one long line.
This tool is very useful to get a good list for your scenario:
Once you've created the custom httpd-ssl.conf as desired, you can then install it with:
To disable TLSv1.1 and only allow TLSv1.2 and TLSv1.3 on OpenLiteSpeed:
echo '|?SSLPROTOCOL=24|' >> /usr/local/directadmin/data/templates/custom/openlitespeed_vhost.conf.CUSTOM.pre
|I wish to customize /etc/httpd/conf/httpd.conf and not have custombuild revert it|
|Current SSL cipher lists for DirectAdmin servers|
2018 JBMC Software, Suite 173 3-11 Bellerose Drive, St Albert, AB
T8N 1P7 Canada. Mon-Fri 9AM-5PM MST