Skip to content

Commit 53124ed

Browse files
author
Till Brehm
committed
Implemented: FS#3706 - disable SSLv3 to protect servers agains POODLE attack.
1 parent 68b1465 commit 53124ed

File tree

4 files changed

+5
-1
lines changed

4 files changed

+5
-1
lines changed

install/tpl/apache_ispconfig.vhost.master

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -63,6 +63,7 @@ NameVirtualHost *:<tmpl_var name="vhost_port">
6363

6464
# SSL Configuration
6565
<tmpl_var name="ssl_comment">SSLEngine On
66+
<tmpl_var name="ssl_comment">SSLProtocol All -SSLv2 -SSLv3
6667
<tmpl_var name="ssl_comment">SSLCertificateFile /usr/local/ispconfig/interface/ssl/ispserver.crt
6768
<tmpl_var name="ssl_comment">SSLCertificateKeyFile /usr/local/ispconfig/interface/ssl/ispserver.key
6869
<tmpl_var name="ssl_bundle_comment">SSLCACertificateFile /usr/local/ispconfig/interface/ssl/ispserver.bundle

install/tpl/nginx_ispconfig.vhost.master

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
server {
22
listen {vhost_port};
33
ssl {ssl_on};
4+
{ssl_comment}ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
45
{ssl_comment}ssl_certificate /usr/local/ispconfig/interface/ssl/ispserver.crt;
56
{ssl_comment}ssl_certificate_key /usr/local/ispconfig/interface/ssl/ispserver.key;
67

server/conf/nginx_vhost.conf.master

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ server {
66

77
<tmpl_if name='ssl_enabled'>
88
listen <tmpl_var name='ip_address'>:443 ssl;
9+
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
910
<tmpl_if name='ipv6_enabled'>
1011
listen [<tmpl_var name='ipv6_address'>]:443 ssl;
1112
</tmpl_if>

server/conf/vhost.conf.master

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,8 @@
4747

4848
<IfModule mod_ssl.c>
4949
<tmpl_if name='ssl_enabled'>
50-
SSLEngine on
50+
SSLEngine on
51+
SSLProtocol All -SSLv2 -SSLv3
5152
SSLCertificateFile <tmpl_var name='document_root'>/ssl/<tmpl_var name='ssl_domain'>.crt
5253
SSLCertificateKeyFile <tmpl_var name='document_root'>/ssl/<tmpl_var name='ssl_domain'>.key
5354
<tmpl_if name='has_bundle_cert'>

0 commit comments

Comments
 (0)