apache_ispconfig.vhost.master 3.62 KB
Newer Older
tbrehm's avatar
tbrehm committed
1 2 3 4 5 6

######################################################
# This virtual host contains the configuration
# for the ISPConfig controlpanel
######################################################

7 8
<tmpl_var name="vhost_port_listen"> Listen <tmpl_var name="vhost_port">
NameVirtualHost *:<tmpl_var name="vhost_port">
tbrehm's avatar
tbrehm committed
9

10
<VirtualHost _default_:<tmpl_var name="vhost_port">>
redray's avatar
redray committed
11 12
  ServerAdmin webmaster@localhost
  
13 14 15 16
  <FilesMatch "\.ph(p3?|tml)$">
    SetHandler None
  </FilesMatch>
  
17
  <IfModule mod_fcgid.c>
18
    DocumentRoot /var/www/ispconfig/
redray's avatar
redray committed
19
    SuexecUserGroup ispconfig ispconfig
20
    <Directory /var/www/ispconfig/>
21
      Options -Indexes +FollowSymLinks +MultiViews +ExecCGI
redray's avatar
redray committed
22
      AllowOverride AuthConfig Indexes Limit Options FileInfo
23 24 25
	  <FilesMatch "\.php$">
		  SetHandler fcgid-script
	  </FilesMatch>
26
      FCGIWrapper /var/www/php-fcgi-scripts/ispconfig/.php-fcgi-starter .php
27 28 29
      <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
	  Require all granted
	  <tmpl_else>
redray's avatar
redray committed
30 31
      Order allow,deny
      Allow from all
32
	  </tmpl_if>
redray's avatar
redray committed
33
    </Directory>
34
    IPCCommTimeout  7200
35
	MaxRequestLen 15728640
redray's avatar
redray committed
36 37
  </IfModule>
  
38 39 40 41 42 43
  <IfModule mpm_itk_module>
    DocumentRoot /usr/local/ispconfig/interface/web/
	AssignUserId ispconfig ispconfig
    AddType application/x-httpd-php .php
    <Directory /usr/local/ispconfig/interface/web>
      # php_admin_value open_basedir "/usr/local/ispconfig/interface:/usr/share:/tmp"
44
      Options +FollowSymLinks
45
      AllowOverride None
46 47 48
      <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
	  Require all granted
	  <tmpl_else>
49 50
      Order allow,deny
      Allow from all
51
	  </tmpl_if>
52 53 54
	  php_value magic_quotes_gpc        0
    </Directory>
  </IfModule>
redray's avatar
redray committed
55 56 57 58
  
  # ErrorLog /var/log/apache2/error.log
  # CustomLog /var/log/apache2/access.log combined
  ServerSignature Off
59 60 61 62 63
  
  <IfModule mod_security2.c>
    SecRuleEngine Off
  </IfModule>

64
  # SSL Configuration
65
  <tmpl_var name="ssl_comment">SSLEngine On
66
  <tmpl_var name="ssl_comment">SSLProtocol All -SSLv2 -SSLv3
67 68 69
  <tmpl_var name="ssl_comment">SSLCertificateFile /usr/local/ispconfig/interface/ssl/ispserver.crt
  <tmpl_var name="ssl_comment">SSLCertificateKeyFile /usr/local/ispconfig/interface/ssl/ispserver.key
  <tmpl_var name="ssl_bundle_comment">SSLCACertificateFile /usr/local/ispconfig/interface/ssl/ispserver.bundle
redray's avatar
redray committed
70

71 72 73 74 75 76 77 78 79 80 81 82
  <tmpl_var name="ssl_comment">SSLCipherSuite ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:E$
  <tmpl_var name="ssl_comment">SSLHonorCipherOrder On

  <IfModule mod_headers.c>
    Header always add Strict-Transport-Security "max-age=15768000"
  </IfModule>

<tmpl_if name='apache_version' op='>=' value='2.4' format='version'>
  <tmpl_var name="ssl_comment">SSLUseStapling on
  <tmpl_var name="ssl_comment">SSLStaplingResponderTimeout 5
  <tmpl_var name="ssl_comment">SSLStaplingReturnResponderErrors off
</tmpl_if>
83 84
</VirtualHost>

85 86 87 88 89 90
<tmpl_if name='apache_version' op='>=' value='2.4' format='version'>
<IfModule mod_ssl.c>
  <tmpl_var name="ssl_comment">SSLStaplingCache shmcb:/var/run/ocsp(128000)
</IfModule>
</tmpl_if>

91 92
<Directory /var/www/php-cgi-scripts>
    AllowOverride None
93 94 95
	<tmpl_if name='apache_version' op='>' value='2.2' format='version'>
	Require all denied
	<tmpl_else>
96 97
    Order Deny,Allow
    Deny from all
98
	</tmpl_if>
99 100 101 102
</Directory>

<Directory /var/www/php-fcgi-scripts>
    AllowOverride None
103 104 105
    <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
	Require all denied
	<tmpl_else>
106 107
    Order Deny,Allow
    Deny from all
108
	</tmpl_if>
109
</Directory>
110