From c93a3c793d53e9076b49e05c32a7c132329ff353 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?St=C3=A9phane=20Lapie?= Date: Wed, 25 Jun 2014 02:00:37 +0900 Subject: Switched back to one Apache 2.4 config template --- config/apache_mod_security-dev/apache22.template | 517 --------------------- .../apache_mod_security.inc | 67 +-- .../apache_mod_security-dev/apache_virtualhost.xml | 2 +- 3 files changed, 20 insertions(+), 566 deletions(-) delete mode 100644 config/apache_mod_security-dev/apache22.template (limited to 'config/apache_mod_security-dev') diff --git a/config/apache_mod_security-dev/apache22.template b/config/apache_mod_security-dev/apache22.template deleted file mode 100644 index e5342dc4..00000000 --- a/config/apache_mod_security-dev/apache22.template +++ /dev/null @@ -1,517 +0,0 @@ - for detailed information. -# In particular, see -# -# for a discussion of each configuration directive. -# -# Do NOT simply read the instructions in here without understanding -# what they do. They're here only as hints or reminders. If you are unsure -# consult the online docs. You have been warned. -# -# Configuration and logfile names: If the filenames you specify for many -# of the server's control files begin with "/" (or "drive:/" for Win32), the -# server will use that explicit path. If the filenames do *not* begin -# with "/", the value of ServerRoot is prepended -- so "/var/log/foo_log" -# with ServerRoot set to "/usr/local" will be interpreted by the -# server as "/usr/local//var/log/foo_log". - -# -# ServerRoot: The top of the directory tree under which the server's -# configuration, error, and log files are kept. -# -# Do not add a slash at the end of the directory path. If you point -# ServerRoot at a non-local disk, be sure to point the LockFile directive -# at a local disk. If you wish to share the same ServerRoot for multiple -# httpd daemons, you will need to change at least LockFile and PidFile. -# -ServerRoot "{$apache_dir}" - -# -# Listen: Allows you to bind Apache to specific IP addresses and/or -# ports, instead of the default. See also the -# directive. -# -# Change this to Listen on specific IP addresses as shown below to -# prevent Apache from glomming onto all bound IP addresses. -# -Listen {$global_listen} -{$aliases} - -# -# Dynamic Shared Object (DSO) Support -# -# To be able to use the functionality of a module which was built as a DSO you -# have to place corresponding `LoadModule' lines at this location so the -# directives contained in it are actually available _before_ they are used. -# Statically compiled modules (those listed by `httpd -l') do not need -# to be loaded here. -# -# Example: -# LoadModule foo_module modules/mod_foo.so -# -# have to place corresponding `LoadModule' lines at this location so the -# LoadModule foo_module modules/mod_foo.so -LoadModule authn_file_module libexec/{$apache_version}/mod_authn_file.so -LoadModule authn_dbm_module libexec/{$apache_version}/mod_authn_dbm.so -LoadModule authn_anon_module libexec/{$apache_version}/mod_authn_anon.so -LoadModule authn_default_module libexec/{$apache_version}/mod_authn_default.so -LoadModule authn_alias_module libexec/{$apache_version}/mod_authn_alias.so -LoadModule authz_host_module libexec/{$apache_version}/mod_authz_host.so -LoadModule authz_groupfile_module libexec/{$apache_version}/mod_authz_groupfile.so -LoadModule authz_user_module libexec/{$apache_version}/mod_authz_user.so -LoadModule authz_dbm_module libexec/{$apache_version}/mod_authz_dbm.so -LoadModule authz_owner_module libexec/{$apache_version}/mod_authz_owner.so -LoadModule authz_default_module libexec/{$apache_version}/mod_authz_default.so -LoadModule auth_basic_module libexec/{$apache_version}/mod_auth_basic.so -LoadModule auth_digest_module libexec/{$apache_version}/mod_auth_digest.so -LoadModule file_cache_module libexec/{$apache_version}/mod_file_cache.so -LoadModule cache_module libexec/{$apache_version}/mod_cache.so -LoadModule disk_cache_module libexec/{$apache_version}/mod_disk_cache.so -LoadModule dumpio_module libexec/{$apache_version}/mod_dumpio.so -LoadModule include_module libexec/{$apache_version}/mod_include.so -LoadModule filter_module libexec/{$apache_version}/mod_filter.so -LoadModule charset_lite_module libexec/{$apache_version}/mod_charset_lite.so -LoadModule deflate_module libexec/{$apache_version}/mod_deflate.so -LoadModule log_config_module libexec/{$apache_version}/mod_log_config.so -LoadModule logio_module libexec/{$apache_version}/mod_logio.so -LoadModule env_module libexec/{$apache_version}/mod_env.so -LoadModule mime_magic_module libexec/{$apache_version}/mod_mime_magic.so -LoadModule cern_meta_module libexec/{$apache_version}/mod_cern_meta.so -LoadModule expires_module libexec/{$apache_version}/mod_expires.so -LoadModule headers_module libexec/{$apache_version}/mod_headers.so -LoadModule usertrack_module libexec/{$apache_version}/mod_usertrack.so -LoadModule unique_id_module libexec/{$apache_version}/mod_unique_id.so -LoadModule setenvif_module libexec/{$apache_version}/mod_setenvif.so -LoadModule version_module libexec/{$apache_version}/mod_version.so -LoadModule proxy_module libexec/{$apache_version}/mod_proxy.so -LoadModule proxy_connect_module libexec/{$apache_version}/mod_proxy_connect.so -LoadModule proxy_ftp_module libexec/{$apache_version}/mod_proxy_ftp.so -LoadModule proxy_http_module libexec/{$apache_version}/mod_proxy_http.so -LoadModule proxy_ajp_module libexec/{$apache_version}/mod_proxy_ajp.so -LoadModule proxy_balancer_module libexec/{$apache_version}/mod_proxy_balancer.so -LoadModule ssl_module libexec/{$apache_version}/mod_ssl.so -LoadModule mime_module libexec/{$apache_version}/mod_mime.so -LoadModule status_module libexec/{$apache_version}/mod_status.so -LoadModule autoindex_module libexec/{$apache_version}/mod_autoindex.so -LoadModule asis_module libexec/{$apache_version}/mod_asis.so -LoadModule info_module libexec/{$apache_version}/mod_info.so -#LoadModule cgi_module libexec/{$apache_version}/mod_cgi.so -LoadModule vhost_alias_module libexec/{$apache_version}/mod_vhost_alias.so -LoadModule negotiation_module libexec/{$apache_version}/mod_negotiation.so -LoadModule dir_module libexec/{$apache_version}/mod_dir.so -LoadModule imagemap_module libexec/{$apache_version}/mod_imagemap.so -LoadModule actions_module libexec/{$apache_version}/mod_actions.so -LoadModule speling_module libexec/{$apache_version}/mod_speling.so -LoadModule userdir_module libexec/{$apache_version}/mod_userdir.so -LoadModule alias_module libexec/{$apache_version}/mod_alias.so -LoadModule rewrite_module libexec/{$apache_version}/mod_rewrite.so -LoadModule reqtimeout_module libexec/{$apache_version}/mod_reqtimeout.so -{$mod_mem_cache} -{$mod_security_module} - - - -# -# If you wish httpd to run as a different user or group, you must run -# httpd as root initially and it will switch. -# -# User/Group: The name (or #number) of the user/group to run httpd as. -# It is usually good practice to create a dedicated user and group for -# running httpd, as with most system services. -# -User www -Group www - - - - -# 'Main' server configuration -# -# The directives in this section set up the values used by the 'main' -# server, which responds to any requests that aren't handled by a -# definition. These values also provide defaults for -# any containers you may define later in the file. -# -# All of these directives may appear inside containers, -# in which case these default settings will be overridden for the -# virtual host being defined. -# -# worker MPM - -{$performance_settings} - -# -# ServerAdmin: Your address, where problems with the server should be -# e-mailed. This address appears on some server-generated pages, such -# as error documents. e.g. admin@your-domain.com -# -ServerAdmin {$global_site_email} - -# -# ServerName gives the name and port that the server uses to identify itself. -# This can often be determined automatically, but we recommend you specify -# it explicitly to prevent problems during startup. -# -# If your host doesn't have a registered DNS name, enter its IP address here. -# -ServerName {$servername} - -# -# DocumentRoot: The directory out of which you will serve your -# documents. By default, all requests are taken from this directory, but -# symbolic links and aliases may be used to point to other locations. -# -DocumentRoot "{$apache_dir}/www/{$apache_version}" - -# -# Each directory to which Apache has access can be configured with respect -# to which services and features are allowed and/or disabled in that -# directory (and its subdirectories). -# -# First, we configure the "default" to be a very restrictive set of -# features. -# - - AllowOverride None - Order deny,allow - Deny from all - - -# -# Note that from this point forward you must specifically allow -# particular features to be enabled - so if something's not working as -# you might expect, make sure that you have specifically enabled it -# below. -# - -# -# This should be changed to whatever you set DocumentRoot to. -# -# -# # -# # Possible values for the Options directive are "None", "All", -# # or any combination of: -# # Indexes Includes FollowSymLinks SymLinksifOwnerMatch ExecCGI MultiViews -# # -# # Note that "MultiViews" must be named *explicitly* --- "Options All" -# # doesn't give it to you. -# # -# # The Options directive is both complicated and important. Please see -# # http://httpd.apache.org/docs/2.2/mod/core.html#options -# # for more information. -# # -# Options Indexes FollowSymLinks -# -# # -# # AllowOverride controls what directives may be placed in .htaccess files. -# # It can be "All", "None", or any combination of the keywords: -# # Options FileInfo AuthConfig Limit -# # -# AllowOverride None -# -# # -# # Controls who can get stuff from this server. -# # -# Order allow,deny -# Allow from all -# -# -# -# -# DirectoryIndex: sets the file that Apache will serve if a directory -# is requested. -# -# -# DirectoryIndex index.html -# -# -# -# The following lines prevent .htaccess and .htpasswd files from being -# viewed by Web clients. -# -# -# Order allow,deny -# Deny from all -# Satisfy All -# -# -# -# ErrorLog: The location of the error log file. -# If you do not specify an ErrorLog directive within a -# container, error messages relating to that virtual host will be -# logged here. If you *do* define an error logfile for a -# container, that host's errors will be logged there and not here. -# -ErrorLog "/var/log/httpd-error.log" - -# -# LogLevel: Control the number of messages logged to the error_log. -# Possible values include: debug, info, notice, warn, error, crit, -# alert, emerg. -# -LogLevel warn - - - # - # The following directives define some format nicknames for use with - # a CustomLog directive (see below). - # - LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined - LogFormat "%h %l %u %t \"%r\" %>s %b" common - - - # You need to enable mod_logio.c to use %I and %O - LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\" %I %O" combinedio - - - # - # The location and format of the access logfile (Common Logfile Format). - # If you do not define any access logfiles within a - # container, they will be logged here. Contrariwise, if you *do* - # define per- access logfiles, transactions will be - # logged therein and *not* in this file. - # - #CustomLog "/var/log/httpd-access.log" common - - # - # If you prefer a logfile with access, agent, and referer information - # (Combined Logfile Format) you can use the following directive. - # - CustomLog "/var/log/httpd-access.log" combined - - -# -# # -# # Redirect: Allows you to tell clients about documents that used to -# # exist in your server's namespace, but do not anymore. The client -# # will make a new request for the document at its new location. -# # Example: -# # Redirect permanent /foo http://www.example.com/bar -# -# # -# # Alias: Maps web paths into filesystem paths and is used to -# # access content that does not live under the DocumentRoot. -# # Example: -# # Alias /webpath /full/filesystem/path -# # -# # If you include a trailing / on /webpath then the server will -# # require it to be present in the URL. You will also likely -# # need to provide a section to allow access to -# # the filesystem path. -# -# # -# # ScriptAlias: This controls which directories contain server scripts. -# # ScriptAliases are essentially the same as Aliases, except that -# # documents in the target directory are treated as applications and -# # run by the server when requested rather than as documents sent to the -# # client. The same rules about trailing "/" apply to ScriptAlias -# # directives as to Alias. -# # -# ScriptAlias /cgi-bin/ "/usr/local/www/{$apache_version}/cgi-bin/" -# -# - -# -# # -# # ScriptSock: On threaded servers, designate the path to the UNIX -# # socket used to communicate with the CGI daemon of mod_cgid. -# # -# #Scriptsock /var/run/cgisock -# - -# -# "/usr/local/www/{$apache_version}/cgi-bin" should be changed to whatever your ScriptAliased -# CGI directory exists, if you have that configured. -# -# -# AllowOverride None -# Options None -# Order allow,deny -# Allow from all -# - -# -# DefaultType: the default MIME type the server will use for a document -# if it cannot otherwise determine one, such as from filename extensions. -# If your server contains mostly text or HTML documents, "text/plain" is -# a good value. If most of your content is binary, such as applications -# or images, you may want to use "application/octet-stream" instead to -# keep browsers from trying to display binary files as though they are -# text. -# -DefaultType text/plainm - - - # - # TypesConfig points to the file containing the list of mappings from - # filename extension to MIME-type. - # - TypesConfig etc/{$apache_version}/mime.types - - # - # AddType allows you to add to or override the MIME configuration - # file specified in TypesConfig for specific file types. - # - #AddType application/x-gzip .tgz - # - # AddEncoding allows you to have certain browsers uncompress - # information on the fly. Note: Not all browsers support this. - # - #AddEncoding x-compress .Z - #AddEncoding x-gzip .gz .tgz - # - # If the AddEncoding directives above are commented-out, then you - # probably should define those extensions to indicate media types: - # - AddType application/x-compress .Z - AddType application/x-gzip .gz .tgz - - # - # AddHandler allows you to map certain file extensions to "handlers": - # actions unrelated to filetype. These can be either built into the server - # or added with the Action directive (see below) - # - # To use CGI scripts outside of ScriptAliased directories: - # (You will also need to add "ExecCGI" to the "Options" directive.) - # - #AddHandler cgi-script .cgi - - # For type maps (negotiated resources): - #AddHandler type-map var - - # - # Filters allow you to process content before it is sent to the client. - # - # To parse .shtml files for server-side includes (SSI): - # (You will also need to add "Includes" to the "Options" directive.) - # - #AddType text/html .shtml - #AddOutputFilter INCLUDES .shtml - - -# -# The mod_mime_magic module allows the server to use various hints from the -# contents of the file itself to determine its type. The MIMEMagicFile -# directive tells the module where the hint definitions are located. -# -#MIMEMagicFile etc/{$apache_version}/magic - -# -# Customizable error responses come in three flavors: -# 1) plain text 2) local redirects 3) external redirects -# -# Some examples: - -{$errordocument} - -#ErrorDocument 500 "The server made a boo boo." -#ErrorDocument 404 /missing.html -#ErrorDocument 404 "/cgi-bin/missing_handler.pl" -#ErrorDocument 402 http://www.example.com/subscription_info.html -# - -# -# EnableMMAP and EnableSendfile: On systems that support it, -# memory-mapping or the sendfile syscall is used to deliver -# files. This usually improves server performance, but must -# be turned off when serving from networked-mounted -# filesystems or if support for these functions is otherwise -# broken on your system. -# -#EnableMMAP off -#EnableSendfile off - -# Supplemental configuration -# -# The configuration files in the etc/{$apache_version}/extra/ directory can be -# included to add extra features or to modify the default configuration of -# the server, or you may simply copy their contents here and change as -# necessary. - -# Server-pool management (MPM specific) -#Include etc/{$apache_version}/extra/httpd-mpm.conf - -# Multi-language error messages -#Include etc/{$apache_version}/extra/httpd-multilang-errordoc.conf - -# Fancy directory listings -#Include etc/{$apache_version}/extra/httpd-autoindex.conf - -# Language settings -#Include etc/{$apache_version}/extra/httpd-languages.conf - -# User home directories -#Include etc/{$apache_version}/extra/httpd-userdir.conf - -# Real-time info on requests and configuration -#Include etc/{$apache_version}/extra/httpd-info.conf - -# Virtual hosts -#Include etc/{$apache_version}/extra/httpd-vhosts.conf - -# Local access to the Apache HTTP Server Manual -#Include etc/{$apache_version}/extra/httpd-manual.conf - -# Distributed authoring and versioning (WebDAV) -#Include etc/{$apache_version}/extra/httpd-dav.conf - -# Various default settings -#Include etc/{$apache_version}/extra/httpd-default.conf - -# Secure (SSL/TLS) connections -#Include etc/{$apache_version}/extra/httpd-ssl.conf -# -# Note: The following must must be present to support -# starting without SSL on platforms with no /dev/random equivalent -# but a statically compiled-in mod_ssl. -# - -SSLRandomSeed startup builtin -SSLRandomSeed connect builtin - - -# Cache settings -{$mem_cache} -{$cache_root} - -#accf_http are not present on current build -AcceptFilter http none -AcceptFilter https none - -# Mod security -{$mod_security} - -# Proxysettings -{$mod_proxy} - -# Mod status -{$mod_status} - - -# Include anything else -Include etc/{$apache_version}/Includes/*.conf - -EOF; - -?> diff --git a/config/apache_mod_security-dev/apache_mod_security.inc b/config/apache_mod_security-dev/apache_mod_security.inc index 93757e22..b24a5d1c 100644 --- a/config/apache_mod_security-dev/apache_mod_security.inc +++ b/config/apache_mod_security-dev/apache_mod_security.inc @@ -39,10 +39,7 @@ if ($pf_version > 2.0) else define('APACHEDIR', '/usr/local'); -if (file_exists(APACHEDIR . "/libexec/apache22")) - define('APACHEVERSION', 'apache22'); -if (file_exists(APACHEDIR . "/libexec/apache24")) - define('APACHEVERSION', 'apache24'); +define('APACHEVERSION', 'apache24'); // End of system check define ('MODSECURITY_DIR','crs'); @@ -453,30 +450,6 @@ function generate_apache_configuration() { #load conf template include("/usr/local/pkg/apache_balancer.template"); - if (APACHEVERSION == 'apache22') { # Only define this here for apache22 - #check balancer members - foreach ($config['installedpackages']['apachebalancer']['config'] as $balancer){ - if (is_array($balancer['row']) && $balancer['enable'] == 'on'){ - $balancer_config.="# {$balancer['description']}\n"; - $balancer_config.="\n"; - foreach($balancer['row'] as $server){ - $options =($server['port'] ? ":{$server['port']}" : ""); - $options.=($server['routeid'] ? " route={$server['routeid']}" : ""); - $options.=($server['loadfactor'] ? " loadfactor={$server['loadfactor']}" : ""); - if (isset($server['ping']) && $server['ping']!=""){ - $options.= " ping={$server['ping']}"; - $options.=($server['ttl'] ? " ttl={$server['ttl']}" : ""); - } - $balancer_config.=" BalancerMember {$balancer['proto']}://{$server['host']}{$options}\n"; - } - #check if stick connections are set - if ($balancer['row'][0]['routeid'] !="") - $balancer_config.=" ProxySet stickysession=ROUTEID\n"; - $balancer_config.="\n\n"; - } - } - } - //write balancer conf file_put_contents(APACHEDIR."/etc/" . APACHEVERSION . "/Includes/balancers.conf",$balancer_config,LOCK_EX); } @@ -602,28 +575,26 @@ EOF; $backend=$apache_location[$be['location']]; $vh_config.="# {$backend['name']}\n"; - if (APACHEVERSION == 'apache24') { # Only define this here for apache24 - foreach ($config['installedpackages']['apachebalancer']['config'] as $balancer){ - if (is_array($balancer['row']) && $balancer['enable'] == 'on' && $balancer['name'] == $backend['balancer']){ - $vh_config.="# {$balancer['description']}\n"; - $vh_config.=" \n"; - foreach($balancer['row'] as $balancer_server){ - $balancer_options =($balancer_server['port'] ? ":{$balancer_server['port']}" : ""); - - $balancer_options.=($balancer_server['routeid'] ? " route={$balancer_server['routeid']}" : ""); - $balancer_options.=($balancer_server['loadfactor'] ? " loadfactor={$balancer_server['loadfactor']}" : ""); - if (isset($balancer_server['ping']) && $balancer_server['ping']!=""){ - $balancer_options.= " ping={$balancer_server['ping']}"; - $balancer_options.=($server['ttl'] ? " ttl={$balancer_server['ttl']}" : ""); - } - $vh_config.=" BalancerMember {$balancer['proto']}://{$balancer_server['host']}{$balancer_options}\n"; + foreach ($config['installedpackages']['apachebalancer']['config'] as $balancer){ + if (is_array($balancer['row']) && $balancer['enable'] == 'on' && $balancer['name'] == $backend['balancer']){ + $vh_config.="# {$balancer['description']}\n"; + $vh_config.=" \n"; + foreach($balancer['row'] as $balancer_server){ + $balancer_options =($balancer_server['port'] ? ":{$balancer_server['port']}" : ""); + + $balancer_options.=($balancer_server['routeid'] ? " route={$balancer_server['routeid']}" : ""); + $balancer_options.=($balancer_server['loadfactor'] ? " loadfactor={$balancer_server['loadfactor']}" : ""); + if (isset($balancer_server['ping']) && $balancer_server['ping']!=""){ + $balancer_options.= " ping={$balancer_server['ping']}"; + $balancer_options.=($server['ttl'] ? " ttl={$balancer_server['ttl']}" : ""); } - #check if stick connections are set - if ($balancer['row'][0]['routeid'] !="") - $vh_config.=" ProxySet stickysession=ROUTEID\n"; - $vh_config.=" \n\n"; - break; + $vh_config.=" BalancerMember {$balancer['proto']}://{$balancer_server['host']}{$balancer_options}\n"; } + #check if stick connections are set + if ($balancer['row'][0]['routeid'] !="") + $vh_config.=" ProxySet stickysession=ROUTEID\n"; + $vh_config.=" \n\n"; + break; } } diff --git a/config/apache_mod_security-dev/apache_virtualhost.xml b/config/apache_mod_security-dev/apache_virtualhost.xml index 488eb822..8558c490 100644 --- a/config/apache_mod_security-dev/apache_virtualhost.xml +++ b/config/apache_mod_security-dev/apache_virtualhost.xml @@ -77,7 +77,7 @@ /usr/local/pkg/ 0644 - https://packages.pfsense.org/packages/config/apache_mod_security-dev/apache.template + https://packages.pfsense.org/packages/config/apache_mod_security-dev/apache24.template /usr/local/pkg/ -- cgit v1.2.3 From 78b7b389840f5342fc1b9bf7f874ba5794df0055 Mon Sep 17 00:00:00 2001 From: Stephane Lapie Date: Tue, 9 Sep 2014 11:46:22 +0900 Subject: Added virtualhost configuration fields to make SSL engine options configurable (namely, protocol, cipher suite, honor cipher order, ssl proxy engine, ssl proxy verification) --- .../apache_mod_security.inc | 12 ++- .../apache_mod_security-dev/apache_virtualhost.xml | 87 +++++++++++++++++----- 2 files changed, 75 insertions(+), 24 deletions(-) (limited to 'config/apache_mod_security-dev') diff --git a/config/apache_mod_security-dev/apache_mod_security.inc b/config/apache_mod_security-dev/apache_mod_security.inc index b24a5d1c..1ef78819 100644 --- a/config/apache_mod_security-dev/apache_mod_security.inc +++ b/config/apache_mod_security-dev/apache_mod_security.inc @@ -541,10 +541,14 @@ EOF; #check ssl if(isset($virtualhost["ssl_cert"]) && $virtualhost["ssl_cert"] !="none" && $virtualhost["proto"] == "https") { - $vh_config.= " SSLEngine on\n SSLProtocol all -SSLv2\n SSLProxyEngine on\n SSLProxyVerify none\n"; - $vh_config.= " SSLCipherSuite ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL\n"; + $vh_config.= " SSLEngine on\n"; + $vh_config.= " SSLProtocol ". ($virtualhost['ssl_protocol'] ? $virtualhost['ssl_protocol'] : "all -SSLv2") ."\n"; + $vh_config.= " SSLProxyEngine ". ($virtualhost['ssl_proxy_engine'] ? "on" : "off") ."\n"; + $vh_config.= " SSLProxyVerify ". ($virtualhost['ssl_proxy_verify'] ? $virtualhost['ssl_proxy_verify'] : "none") ."\n"; + $vh_config.= " SSLCipherSuite ". ($virtualhost['ssl_cipher_suite'] ? $virtualhost['ssl_cipher_suite'] : "ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL") ."\n"; + $vh_config.= " SSLHonorCipherOrder ". ($virtualhost['ssl_honor_cipher_order'] ? "on" : "off") ."\n"; - $svr_cert = lookup_cert($virtualhost["ssl_cert"]); + $svr_cert = lookup_cert($virtualhost["ssl_cert"]); if ($svr_cert != false) { if(base64_decode($svr_cert['crt'])) { file_put_contents(APACHEDIR . "/etc/" . APACHEVERSION . "/{$virtualhost["ssl_cert"]}.crt",apache_textarea_decode($svr_cert['crt']),LOCK_EX); @@ -565,7 +569,7 @@ EOF; file_put_contents(APACHEDIR . "/etc/" . APACHEVERSION . "/{$virtualhost["reverse_int_ca"]}.crt",apache_textarea_decode($cli_ca['crt']),LOCK_EX); $vh_config.= " SSLCACertificateFile ". APACHEDIR . "/etc/" . APACHEVERSION . "/{$virtualhost["reverse_int_ca"]}.crt\n"; } - } + } #Custom Options $vh_config.= apache_textarea_decode($virtualhost['custom'])."\n\n"; diff --git a/config/apache_mod_security-dev/apache_virtualhost.xml b/config/apache_mod_security-dev/apache_virtualhost.xml index 8558c490..ca448cd2 100644 --- a/config/apache_mod_security-dev/apache_virtualhost.xml +++ b/config/apache_mod_security-dev/apache_virtualhost.xml @@ -256,6 +256,72 @@ input + + + + + locations + rowhelper + + + + location + Server Location + + name + name + none + select_source + + + + + SSL Environment + listtopic + + + SSL Protocol + ssl_protocol + 50 + + input + all -SSLv2 + + + SSL Cipher Suite + ssl_cipher_suite + 50 + + input + ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL + + + SSL Honor Cipher Order + ssl_honor_cipher_order + + off + checkbox + + + SSL Proxy Engine + ssl_proxy_engine + + on + checkbox + + + SSL Proxy Verify + ssl_proxy_verify + + select + + + + + + + none + HTTPS SSL certificate ssl_cert @@ -286,25 +352,6 @@ refid none - - - - - locations - rowhelper - - - - location - Server Location - - name - name - none - select_source - - - Logging listtopic @@ -315,7 +362,7 @@ checkbox - + Log file logfile -- cgit v1.2.3