gpt4 book ai didi

apache - 如何解决连接 - 过时的连接设置

转载 作者:太空宇宙 更新时间:2023-11-03 14:32:27 25 4
gpt4 key购买 nike

在 Apache 版本 2.4.33 上安装签名证书后,我注意到浏览器控制台安全选项卡下的以下信息;

Connection - obsolete connection settings
The connection to this site uses TLS 1.2 (a strong protocol), RSA (an obsolete key exchange), and AES_256_GCM (a strong cipher).

下面是上面错误的截图;

Connection - obsolete connection settings][1

下面的代码片段反射(reflect)了我的虚拟主机配置;

<IfModule mod_ssl.c>
<VirtualHost *:443>
DocumentRoot "/my/path/to/www"
ServerName mydomain.com
ServerAlias www.mydomain.com
SSLEngine on
SSLCertificateFile /my/path/to/mydomainname.crt
SSLCertificateKeyFile /my/path/to/mydomainname.key
SSLCertificateChainFile /my/path/to/CA.crt
ErrorLog "/my/path/to/mydomain-error.log"
CustomLog "/my/path/to/mydomain-access.log" common
</VirtualHost>
</IfModule>

我做错了什么,我该如何解决?

最佳答案

添加

SSLProtocol all -SSLv2 -SSLv3
SSLCipherSuite ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS
SSLHonorCipherOrder on
SSLCompression off
SSLSessionTickets off

SSLEngine on 之后到你的虚拟主机

关于apache - 如何解决连接 - 过时的连接设置,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/51487607/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com