LINUXOR.SK ... open source notes ...

Email - Apache ssl.conf, webmail

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Webmail

The global TLS configuration of Apache on the webmail server. In the unified template this file keeps only what is global: the listener, the session cache, the stapling cache and the random seed. The stock <VirtualHost _default_:443> block is gone; certificates, protocols and ciphers are set per virtual host. Stock comments are left out; the short comment lines in the fence are mine.

ItemValue
Path on the server/etc/httpd/conf.d/ssl.conf
Shown hereDC2-A-VCMSX002
SoftwareApache HTTP Server 2.4 with mod_ssl from RHEL 7
Loaded byIncludeOptional conf.d/*.conf in httpd.conf
Activated withsystemctl start httpd in the install notes

The file

apache
################################################################################
# Global HTTPS configuration
################################################################################

# HTTPS only: there is no "Listen 80" anywhere in this configuration.
Listen *:443

# Stock setting.
SSLPassPhraseDialog exec:/usr/libexec/httpd-ssl-pass-dialog

# Stock session cache.
SSLSessionCache         shmcb:/run/httpd/sslcache(512000)
SSLSessionCacheTimeout  300

# OCSP Stapling cache (added by the template; stapling itself is switched off in the virtual hosts).
SSLStaplingCache "shmcb:logs/stapling-cache(150000)"

# Stock settings.
SSLRandomSeed startup file:/dev/urandom  256
SSLRandomSeed connect builtin
SSLCryptoDevice builtin

Listen *:443 is the only Listen directive of the server. The virtual hosts that answer on it are in the IPv4 virtual host.

← solutionz