如何解决连接-过时的连接设置

时间:2018-07-23 21:45:44

标签: apache ssl ssl-certificate

在Apache 2.4.33版上安装签名证书后,我注意到浏览器控制台的“安全性”标签下的以下信息;

  

连接-过时的连接设置
  与该站点的连接使用TLS 1.2(强协议),RSA(过时的密钥交换)和AES_256_GCM(强密码)。

下面是上面错误的屏幕截图;

Connection - obsolete connection settings][1

下面的代码段反映了我的虚拟主机配置;

<IfModule mod_ssl.c>
    <VirtualHost *:443>
    DocumentRoot "/my/path/to/www"
    ServerName mydomain.com
    ServerAlias www.mydomain.com
    SSLEngine on
    SSLCertificateFile /my/path/to/mydomainname.crt
    SSLCertificateKeyFile /my/path/to/mydomainname.key
    SSLCertificateChainFile /my/path/to/CA.crt
    ErrorLog "/my/path/to/mydomain-error.log"
    CustomLog "/my/path/to/mydomain-access.log" common
    </VirtualHost>
</IfModule>

我在做什么错,我该如何解决?

1 个答案:

答案 0 :(得分:0)

Add

SSLProtocol all -SSLv2 -SSLv3
SSLCipherSuite ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS
SSLHonorCipherOrder on
SSLCompression off
SSLSessionTickets off

to your virtual host after SSLEngine on