Loading...

Weak SSL Cipher在Apache中禁用過時的SSL / TLS版本

Temperature: 0 °C

Mark ChangMark Chang
author_tools
使用vi(或vim)編輯ssl.conf (通常位於/etc/httpd/conf.d/底下)

查詢SSL Protocol support
# SSL Protocol support:
# List the enable protocol levels with which clients will be able to
# connect. Disable SSLv2 access by default:
SSLProtocol all -SSLv2 -SSLv3

註解掉SSLProtocol all -SSLv2 -SSLv3

添加
SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1

往下拉底下SSL Cipher Suite部分也一併處理
# SSL Cipher Suite:
# List the ciphers that the client is permitted to negotiate.
# See the mod_ssl documentation for a complete list.
SSLCipherSuite HIGH:MEDIUM:!aNULL:!MD5:!SEED:!IDEA

註解掉SSLCipherSuite HIGH:MEDIUM:!aNULL:!MD5:!SEED:!IDEA
添加
SSLCipherSuite HIGH:!aNULL:!MD5:!3DES
SSLHonorCipherOrder on

最後~保存文件並重新啟動Apache

以上紀錄
https://innstory.com/story-Weak_SSL_Cipher在Apache中禁用過時的SSL__TLS版本-2097

Prev
 WordPress如何關閉迴響留言功能?

Next
分享_成功人士剛起步時和一般人的差異並不大!現代網路之父安德森給 

About the Author

Mark Chang

離不開電腦的宅男

Visitor message

Leave some footprints to prove that you visited me

Recommended reading

Author's other related stories

分享 你有多自律,就有多自由!學不會,再多的自由都只是 放縱

分享 你有多自律,就有多自由!學不會,再多的自由都只是 放縱

喜歡~閱讀這些鼓勵人心的文字內容。 很多有天賦的人卻因為不夠專注而失敗,世界不缺乏努力...

分享 颱風放假一天,但你知道日韓沒颱風假嗎?-風傳媒

分享 颱風放假一天,但你知道日韓沒颱風假嗎?-風傳媒

這倒是讓我記起日本電影「 生存家族」裡的劇情~ 故事是設置在沒有電的環境作為舞台開始~...

嘰嘰喳喳

嘰嘰喳喳

我們總是在世人面前假裝自己以為的瀟灑。 卻過不了自己在心裏築起的高牆。...

Please select an option

error

Hi, thank you for your participation, but you cannot vote repeatedly~

Join innstory now and start recording your story.

"Innstory" is a place to store stories. We are committed to becoming a warm platform. Deepening the bonds between people is our direction.
We are convinced that the blockchain between people is not just a cold calculation. Join us now.

Wrong format