在/etc/httpd/conf.d/ssl.conf的外,加入以下代码,然后重启Apache即可。
#禁用不安全的
SSLv2 SSLv3 TLSv1 TLSv1.1 SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
#使用安全加密套件
SSLCipherSuite ECDHE-RSA-AES128-GCM-SHA256:ECDHE:ECDH:AES:HIGH:!NULL:!aNULL:!MD5:!ADH:!RC4:!DH:!DHE
SSLHonorCipherOrder on
#开启HSTS
Header always set Strict-Transport-Security "max-age=15552000; includeSubdomains; preload"
来自 Gimhoy's Blog (https://blog.gimhoy.com/) - 转载请保留原文链接:https://blog.gimhoy.com/archives/apache-hsts.html