Projects
jsj
jsj-installtools
vhost-ssl-proxy.conf
Sign Up
Log In
Username
Password
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File vhost-ssl-proxy.conf of Package jsj-installtools
<VirtualHost *:80> ServerAdmin vmadmin@local ServerName HOSTNAME.DOMAINNAME DocumentRoot /srv/www/HOSTNAME/htdocs/ ErrorLog /var/log/apache2/HOSTNAME-error_log CustomLog /var/log/apache2/HOSTNAME-access_log combined HostnameLookups Off UseCanonicalName Off ServerSignature On <ifmodule mod_rewrite.c> RewriteEngine On RewriteCond %{HTTPS} off RewriteCond %{REQUEST_URI} !^/\.well\-known/acme-challenge/ RewriteRule ^.*$ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,QSA,L] </ifmodule> <Directory "/srv/www/HOSTNAME/htdocs"> Options -Indexes -FollowSymLinks AllowOverride None Require all granted </Directory> </VirtualHost> <IfDefine SSL> <IfDefine !NOSSL> <VirtualHost *:443> ServerName HOSTNAME.DOMAINNAME DocumentRoot /srv/www/HOSTNAME/htdocs/ ErrorLog /var/log/apache2/HOSTNAME-error_log CustomLog /var/log/apache2/HOSTNAME-access_log combined CustomLog /var/log/apache2/ssl_request_log ssl_combined SSLEngine on SSLOpenSSLConfCmd DHParameters "/etc/ssl/dhparam.pem" SSLOpenSSLConfCmd Curves X25519:prime256v1:secp384r1 ### SSL configuration https://ssl-config.mozilla.org/: ### choose! ### next 3 lines Mozilla configuration intermediate SSLProtocol -all +TLSv1.2 +TLSv1.3 SSLHonorCipherOrder on SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305 ### next 2 lines Mozilla configuration modern #SSLProtocol -all +TLSv1.3 #SSLHonorCipherOrder off ### end: SSL configuration # enable HTTP/2, if available Protocols h2 http/1.1 <IfModule mod_headers.c> Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" Header always set X-Frame-Options SAMEORIGIN Header always set X-Content-Type-Options nosniff </IfModule> # Requires Apache >= 2.4 SSLCompression off # Requires Apache >= 2.4.11 SSLSessionTickets Off SSLCertificateFile /etc/apache2/ssl.crt/HOSTNAME.DOMAINNAME.fullchain.pem SSLCertificateKeyFile /etc/apache2/ssl.key/HOSTNAME.DOMAINNAME.key <IfModule mod_proxy.c> SSLProxyEngine On SSLProxyVerify none SSLProxyCheckPeerCN off SSLProxyCheckPeerName off SSLProxyCheckPeerExpire off # Encoded slashes need to be allowed AllowEncodedSlashes NoDecode <Proxy *> Require all granted </Proxy> ProxyPass / https://PROXYDESTHN.PROXYDESTDN/ ProxyPassReverse / https://PROXYDESTHN.PROXYDESTDN/ ProxyPreserveHost On #Header set Host PROXYDESTHN.PROXYDESTDN #RequestHeader set Host PROXYDESTHN.PROXYDESTDN #RequestHeader set Origin https://PROXYDESTHN.PROXYDESTDN Header unset Referer RequestHeader unset Referer </IfModule> <Location /> Require all granted </Location> </VirtualHost> </IfDefine> </IfDefine>
Locations
Projects
Search
Status Monitor
Help
Open Build Service
OBS Manuals
API Documentation
OBS Portal
Reporting a Bug
Contact
Mailing List
Forums
Chat (IRC)
Twitter
Open Build Service (OBS)
is an
openSUSE project
.