Email - Apache virtual host (IPv4), webmail
Email Solution · Config document · referenced from Webmail
The virtual host that serves Roundcube over HTTPS on the IPv4 address of the webmail server: document root, logging, TLS 1.2 only, one cipher family, the server certificate. The file comes from the unified Apache template. Paragraphs of comments copied from the distribution's ssl.conf are left out; every active line and the template's own comments are as built.
| Item | Value |
|---|---|
| Path on the server | /etc/httpd/conf.d/dc2-a-vcmsx002.adm.example.net.conf4 |
| Shown here | DC2-A-VCMSX002 |
| Also on | the same server as .conf6 for IPv6, with the differences below |
| Loaded by | Include conf.d/*.conf4 in httpd.conf |
| Software | Apache HTTP Server 2.4 with mod_ssl from RHEL 7 |
| Activated with | systemctl start httpd in the install notes |
The file
################################################################################
# Virtualhost - Global Virtualhost configuration (IPv4)
################################################################################
#
# Name-Based VirtualHost instance on 10.12.19.43:443
#
<VirtualHost 10.12.19.43:443>
#
# ServerName = FQDN
#
ServerName dc2-a-vcmsx002.adm.example.net
#
# DocumentRoot for FQDN
#
DocumentRoot /var/www/dc2-a-vcmsx002.adm.example.net
#
# Directory settings for DocumenRoot
#
<Directory "/var/www/dc2-a-vcmsx002.adm.example.net">
#
# Note: For security reasons we disable the following:
# - Directory browser listing (-Indexes)
# - Server side includes (-Includes)
# - CGI execution (-ExecCGI)
# - Symbolic links (-FollowSymlinks)
#
Options -Indexes -Includes -ExecCGI -FollowSymlinks
#
# LimitRequestBody (1 MiB)
#
LimitRequestBody 1048576
#
AllowOverride None
#
# Controls who can get stuff from this server.
#
Require all granted
</Directory>
#
# Logging
#
CustomLog "/var/log/httpd/dc2-a-vcmsx002.adm.example.net-IPv4-access.log" combined
ErrorLog "/var/log/httpd/dc2-a-vcmsx002.adm.example.net-IPv4-error.log"
LogLevel warn
################################################################################
# Virtualhost - SSL Virtualhost configuration (IPv4)
################################################################################
#
# Enable/Disable SSL for this virtual host.
#
SSLEngine on
#
# SSLCompression off
#
# Disabling SSL compression avoid CRIME attack -> http://httpd.apache.org/docs/2.2/mod/mod_ssl.html#sslcompression
# Requires Apache >= 2.4
#
SSLCompression off
#
# Use OCSP stapling
#
# OCSP stapling is a TLS/SSL extension which aims to improve
# the performance of SSL negotiation while maintaining
# visitor privacy.
#
# Note: Needs to be tested more because Firefox browser cannot access website if OCSP stapling is enabled. Need more testing.
# For this reason the infrastructure will do not use (currently temporary) SSL Stapling.
SSLUseStapling off
#
# SSL Protocol support
#
# Note: For security reasons we support only TLS 1.2.
#
SSLProtocol -all +TLSv1.2
#
# SSL Cipher Suite
#
# Note: For security reasons we support only strong encryption.
#
SSLCipherSuite EECDH+AESGCM
#
# Speed-optimized SSL Cipher configuration
#
SSLHonorCipherOrder on
#
# Server Certificate
#
SSLCertificateFile "/etc/pki/tls/certs/dc2-a-vcmsx002.adm.example.net.crt"
#
# Server Private Key
#
SSLCertificateKeyFile "/etc/pki/tls/private/dc2-a-vcmsx002.adm.example.net.key"
#
# Server Certificate Chain
#
SSLCertificateChainFile "/etc/pki/tls/certs/dc2-a-vcmsx002.adm.example.net.chain.crt"
#
# SSL Protocol Adjustments
#
BrowserMatch "MSIE [2-5]" \
nokeepalive ssl-unclean-shutdown \
downgrade-1.0 force-response-1.0
################################################################################
# Virtualhost - Application specific configuration (IPv4)
################################################################################
# Application specific configuration (Apache directives which are specific for specific application)
Include conf.d/dc2-a-vcmsx002.adm.example.net.conf4.app
#
# End of Virtualhost settings
#
</VirtualHost>Differences in the IPv6 virtual host
The result of diff between .conf4 and .conf6. Everything else, the TLS settings included, is the same.
| File | Line | Value |
|---|---|---|
.conf4 | <VirtualHost> | 10.12.19.43:443 |
.conf6 | <VirtualHost> | [2001:db8:a2:b6f::f:6]:443 |
.conf4 | CustomLog | /var/log/httpd/dc2-a-vcmsx002.adm.example.net-IPv4-access.log |
.conf6 | CustomLog | /var/log/httpd/dc2-a-vcmsx002.adm.example.net-IPv6-access.log |
.conf4 | ErrorLog | /var/log/httpd/dc2-a-vcmsx002.adm.example.net-IPv4-error.log |
.conf6 | ErrorLog | /var/log/httpd/dc2-a-vcmsx002.adm.example.net-IPv6-error.log |
.conf4 | Include | conf.d/dc2-a-vcmsx002.adm.example.net.conf4.app |
.conf6 | Include | conf.d/dc2-a-vcmsx002.adm.example.net.conf6.app |
The comments say "IPv4" in one file and "IPv6" in the other. The organisation's name was removed from four comment lines.
Checked against Apache HTTP Server 2.4.69
| As built | Today |
|---|---|
SSLProtocol -all +TLSv1.2 | Valid syntax. With OpenSSL 1.1.1 and later TLSv1.3 is a protocol name too, and this line switches it off |
SSLCipherSuite EECDH+AESGCM | Valid for TLS 1.2 and older; TLS 1.3 suites are set separately, with SSLCipherSuite TLSv1.3 … |
SSLHonorCipherOrder on | Still valid, the default is off |
SSLCompression off, SSLUseStapling off | Both are the defaults |
SSLCertificateChainFile | Deprecated: obsolete since 2.4.8, when SSLCertificateFile learned to load the intermediate certificates from the same file |
I expect this virtual host, copied to a current server, to work; that was not tested. It would keep every client on TLS 1.2. The protocol line needs +TLSv1.3 and the chain belongs into the certificate file.