LINUXOR.SK ... open source notes ...

Email - Apache virtual host (IPv4), webmail

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Webmail

The virtual host that serves Roundcube over HTTPS on the IPv4 address of the webmail server: document root, logging, TLS 1.2 only, one cipher family, the server certificate. The file comes from the unified Apache template. Paragraphs of comments copied from the distribution's ssl.conf are left out; every active line and the template's own comments are as built.

ItemValue
Path on the server/etc/httpd/conf.d/dc2-a-vcmsx002.adm.example.net.conf4
Shown hereDC2-A-VCMSX002
Also onthe same server as .conf6 for IPv6, with the differences below
Loaded byInclude conf.d/*.conf4 in httpd.conf
SoftwareApache HTTP Server 2.4 with mod_ssl from RHEL 7
Activated withsystemctl start httpd in the install notes

The file

apache
################################################################################
# Virtualhost - Global Virtualhost configuration (IPv4)
################################################################################

#
# Name-Based VirtualHost instance on 10.12.19.43:443
#
<VirtualHost 10.12.19.43:443>

    #
    # ServerName = FQDN
    #
    ServerName dc2-a-vcmsx002.adm.example.net

    #
    # DocumentRoot for FQDN
    #
    DocumentRoot /var/www/dc2-a-vcmsx002.adm.example.net

    #
    # Directory settings for DocumenRoot
    #
    <Directory "/var/www/dc2-a-vcmsx002.adm.example.net">

        #
        # Note: For security reasons we disable the following:
        # - Directory browser listing (-Indexes)
        # - Server side includes (-Includes)
        # - CGI execution (-ExecCGI)
        # - Symbolic links (-FollowSymlinks)
        #
        Options -Indexes -Includes -ExecCGI -FollowSymlinks

        #
        # LimitRequestBody (1 MiB)
        #
        LimitRequestBody 1048576

        #
        AllowOverride None

        #
        # Controls who can get stuff from this server.
        #
        Require all granted

    </Directory>

    #
    # Logging
    #
    CustomLog "/var/log/httpd/dc2-a-vcmsx002.adm.example.net-IPv4-access.log" combined
    ErrorLog  "/var/log/httpd/dc2-a-vcmsx002.adm.example.net-IPv4-error.log"
    LogLevel  warn

################################################################################
# Virtualhost - SSL Virtualhost configuration (IPv4)
################################################################################

    #
    # Enable/Disable SSL for this virtual host.
    #
    SSLEngine on

    #
    # SSLCompression off
    #
    # Disabling SSL compression avoid CRIME attack -> http://httpd.apache.org/docs/2.2/mod/mod_ssl.html#sslcompression
    # Requires Apache >= 2.4
    #
    SSLCompression off

    #
    # Use OCSP stapling
    #
    # OCSP stapling is a TLS/SSL extension which aims to improve
    # the performance of SSL negotiation while maintaining
    # visitor privacy.
    #
    # Note:     Needs to be tested more because Firefox browser cannot access website if OCSP stapling is enabled. Need more testing.
    #             For this reason the infrastructure will do not use (currently temporary) SSL Stapling.
    SSLUseStapling off

    #
    # SSL Protocol support
    #
    # Note: For security reasons we support only TLS 1.2.
    #
    SSLProtocol -all +TLSv1.2

    #
    # SSL Cipher Suite
    #
    # Note: For security reasons we support only strong encryption.
    #
    SSLCipherSuite EECDH+AESGCM

    #
    # Speed-optimized SSL Cipher configuration
    #
    SSLHonorCipherOrder on

    #
    # Server Certificate
    #
    SSLCertificateFile "/etc/pki/tls/certs/dc2-a-vcmsx002.adm.example.net.crt"

    #
    # Server Private Key
    #
    SSLCertificateKeyFile "/etc/pki/tls/private/dc2-a-vcmsx002.adm.example.net.key"

    #
    # Server Certificate Chain
    #
    SSLCertificateChainFile "/etc/pki/tls/certs/dc2-a-vcmsx002.adm.example.net.chain.crt"

    #
    # SSL Protocol Adjustments
    #
    BrowserMatch "MSIE [2-5]" \
             nokeepalive ssl-unclean-shutdown \
             downgrade-1.0 force-response-1.0

################################################################################
# Virtualhost - Application specific configuration (IPv4)
################################################################################

# Application specific configuration (Apache directives which are specific for specific application)
Include conf.d/dc2-a-vcmsx002.adm.example.net.conf4.app

#
# End of Virtualhost settings
#
</VirtualHost>

Differences in the IPv6 virtual host

The result of diff between .conf4 and .conf6. Everything else, the TLS settings included, is the same.

FileLineValue
.conf4<VirtualHost>10.12.19.43:443
.conf6<VirtualHost>[2001:db8:a2:b6f::f:6]:443
.conf4CustomLog/var/log/httpd/dc2-a-vcmsx002.adm.example.net-IPv4-access.log
.conf6CustomLog/var/log/httpd/dc2-a-vcmsx002.adm.example.net-IPv6-access.log
.conf4ErrorLog/var/log/httpd/dc2-a-vcmsx002.adm.example.net-IPv4-error.log
.conf6ErrorLog/var/log/httpd/dc2-a-vcmsx002.adm.example.net-IPv6-error.log
.conf4Includeconf.d/dc2-a-vcmsx002.adm.example.net.conf4.app
.conf6Includeconf.d/dc2-a-vcmsx002.adm.example.net.conf6.app

The comments say "IPv4" in one file and "IPv6" in the other. The organisation's name was removed from four comment lines.

Checked against Apache HTTP Server 2.4.69

As builtToday
SSLProtocol -all +TLSv1.2Valid syntax. With OpenSSL 1.1.1 and later TLSv1.3 is a protocol name too, and this line switches it off
SSLCipherSuite EECDH+AESGCMValid for TLS 1.2 and older; TLS 1.3 suites are set separately, with SSLCipherSuite TLSv1.3 …
SSLHonorCipherOrder onStill valid, the default is off
SSLCompression off, SSLUseStapling offBoth are the defaults
SSLCertificateChainFileDeprecated: obsolete since 2.4.8, when SSLCertificateFile learned to load the intermediate certificates from the same file

I expect this virtual host, copied to a current server, to work; that was not tested. It would keep every client on TLS 1.2. The protocol line needs +TLSv1.3 and the chain belongs into the certificate file.

← solutionz