基本SSL参数

  1. # 通用性
  2. SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
  3. SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
  4. SSLHonorCipherOrder off
  5. SSLSessionTickets off
  6. # 开启 OCSP Stapling(建议)
  7. SSLUseStapling On
  8. SSLStaplingCache "shmcb:logs/ssl_stapling(32768)"

虚拟主机开启SSL

  1. <VirtualHost *:443>
  2. SSLEngine on
  3. SSLCertificateFile /path/fullchain.crt
  4. SSLCertificateKeyFile /path/private.pem
  5. </VirtualHost>

更多参考

1、Mozilla:https://ssl-config.mozilla.org/
2、阿里云:https://help.aliyun.com/document_detail/98727.html
3、腾讯云:https://cloud.tencent.com/document/product/400/35243https://cloud.tencent.com/document/product/400/61400