apache_ispconfig.vhost.master 4.72 KB
Newer Older
tbrehm's avatar
tbrehm committed
1 2 3 4 5
######################################################
# This virtual host contains the configuration
# for the ISPConfig controlpanel
######################################################

6 7
<tmpl_var name="vhost_port_listen"> Listen <tmpl_var name="vhost_port">
NameVirtualHost *:<tmpl_var name="vhost_port">
tbrehm's avatar
tbrehm committed
8

9
<VirtualHost _default_:<tmpl_var name="vhost_port">>
redray's avatar
redray committed
10
  ServerAdmin webmaster@localhost
C Soellinger's avatar
C Soellinger committed
11

12 13 14 15 16 17 18 19 20 21
  <Directory /var/www/ispconfig/>
    <FilesMatch "\.ph(p3?|tml)$">
      SetHandler None
    </FilesMatch>
  </Directory>
  <Directory /usr/local/ispconfig/interface/web/>
    <FilesMatch "\.ph(p3?|tml)$">
      SetHandler None
    </FilesMatch>
  </Directory>
C Soellinger's avatar
C Soellinger committed
22

23
  <IfModule mod_fcgid.c>
24
    DocumentRoot /var/www/ispconfig/
redray's avatar
redray committed
25
    SuexecUserGroup ispconfig ispconfig
26
    <Directory /var/www/ispconfig/>
27
      Options -Indexes +FollowSymLinks +MultiViews +ExecCGI
redray's avatar
redray committed
28
      AllowOverride AuthConfig Indexes Limit Options FileInfo
C Soellinger's avatar
C Soellinger committed
29 30 31
      <FilesMatch "\.php$">
        SetHandler fcgid-script
      </FilesMatch>
32
      FCGIWrapper /var/www/php-fcgi-scripts/ispconfig/.php-fcgi-starter .php
33
      <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
C Soellinger's avatar
C Soellinger committed
34 35
      Require all granted
      <tmpl_else>
redray's avatar
redray committed
36 37
      Order allow,deny
      Allow from all
C Soellinger's avatar
C Soellinger committed
38
      </tmpl_if>
redray's avatar
redray committed
39
    </Directory>
40
    IPCCommTimeout  7200
C Soellinger's avatar
C Soellinger committed
41
    MaxRequestLen 15728640
redray's avatar
redray committed
42
  </IfModule>
C Soellinger's avatar
C Soellinger committed
43

44 45
  <IfModule mpm_itk_module>
    DocumentRoot /usr/local/ispconfig/interface/web/
C Soellinger's avatar
C Soellinger committed
46
    AssignUserId ispconfig ispconfig
47 48 49
    AddType application/x-httpd-php .php
    <Directory /usr/local/ispconfig/interface/web>
      # php_admin_value open_basedir "/usr/local/ispconfig/interface:/usr/share:/tmp"
50
      Options +FollowSymLinks
51
      AllowOverride None
52
      <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
C Soellinger's avatar
C Soellinger committed
53 54
      Require all granted
      <tmpl_else>
55 56
      Order allow,deny
      Allow from all
C Soellinger's avatar
C Soellinger committed
57 58
      </tmpl_if>
      php_value magic_quotes_gpc        0
59 60
    </Directory>
  </IfModule>
C Soellinger's avatar
C Soellinger committed
61

redray's avatar
redray committed
62 63 64
  # ErrorLog /var/log/apache2/error.log
  # CustomLog /var/log/apache2/access.log combined
  ServerSignature Off
C Soellinger's avatar
C Soellinger committed
65

66 67 68 69
  <IfModule mod_security2.c>
    SecRuleEngine Off
  </IfModule>

70
  # SSL Configuration
71
  <tmpl_var name="ssl_comment">SSLEngine On
72 73 74
  <tmpl_if name='apache_version' op='>=' value='2.3.16' format='version'>
  <tmpl_var name="ssl_comment">SSLProtocol All -SSLv3
  <tmpl_else>
75
  <tmpl_var name="ssl_comment">SSLProtocol All -SSLv2 -SSLv3
76
  </tmpl_if>
77 78 79
  <tmpl_var name="ssl_comment">SSLCertificateFile /usr/local/ispconfig/interface/ssl/ispserver.crt
  <tmpl_var name="ssl_comment">SSLCertificateKeyFile /usr/local/ispconfig/interface/ssl/ispserver.key
  <tmpl_var name="ssl_bundle_comment">SSLCACertificateFile /usr/local/ispconfig/interface/ssl/ispserver.bundle
redray's avatar
redray committed
80

81
  <tmpl_var name="ssl_comment">SSLCipherSuite ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS
82
  <tmpl_var name="ssl_comment">SSLHonorCipherOrder On
83 84 85 86 87 88
  <tmpl_if name='apache_version' op='>=' value='2.4.3' format='version'>
  <tmpl_var name="ssl_comment">SSLCompression Off
  </tmpl_if>
  <tmpl_if name='apache_version' op='>=' value='2.4.11' format='version'>
  <tmpl_var name="ssl_comment">SSLSessionTickets Off
  </tmpl_if>
89 90

  <IfModule mod_headers.c>
91
    Header setifempty add Strict-Transport-Security "max-age=15768000"
92
	RequestHeader unset Proxy early
93 94
  </IfModule>

95 96 97 98 99
  <tmpl_if name='apache_version' op='>=' value='2.3.3' format='version'>
  <tmpl_var name="ssl_comment">SSLUseStapling On
  <tmpl_var name="ssl_comment">SSLStaplingResponderTimeout 5
  <tmpl_var name="ssl_comment">SSLStaplingReturnResponderErrors Off
  </tmpl_if>
100 101
</VirtualHost>

102
<tmpl_if name='apache_version' op='>=' value='2.3.3' format='version'>
103 104 105 106 107
<IfModule mod_ssl.c>
  <tmpl_var name="ssl_comment">SSLStaplingCache shmcb:/var/run/ocsp(128000)
</IfModule>
</tmpl_if>

108
<Directory /var/www/php-cgi-scripts>
C Soellinger's avatar
C Soellinger committed
109 110 111 112 113 114 115
  AllowOverride None
  <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
  Require all denied
  <tmpl_else>
  Order Deny,Allow
  Deny from all
  </tmpl_if>
116 117 118
</Directory>

<Directory /var/www/php-fcgi-scripts>
C Soellinger's avatar
C Soellinger committed
119 120 121 122 123 124 125 126
  AllowOverride None
  <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
  Require all denied
  <tmpl_else>
  Order Deny,Allow
  Deny from all
  </tmpl_if>
</Directory>