Listen 443 AddType application/x-x509-ca-cert .crt AddType application/x-pkcs7-crl .crl # 중간 구성 SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305 SSLHonorCipherOrder off SSLSessionTickets off SSLUseStapling On SSLStaplingCache "shmcb:logs/ssl_stapling(32768)" DocumentRoot "/home/[User 명]/public_html" ServerName ServerAlias AllowOverride All Options MultiViews SymLinksIfOwnerMatch IncludesNoExec Require all granted ErrorLog "logs/_ssl_error_log" CustomLog "logs/_ssl_access_log" combined SSLEngine on # curl https://ssl-config.mozilla.org/ffdhe2048.txt >> /path/to/signed_cert_and_intermediate_certs_and_dhparams SSLCertificateFile "/etc/httpd/SSL//default/_all.crt" SSLCertificateKeyFile "/etc/httpd/SSL//default/.key" # 가능한 경우 HTTP/2 활성화 Protocols h2 http/1.1 # HTTP Strict Transport Security 활성화 (mod_headers가 필요함) (63072000 초) Header always set Strict-Transport-Security "max-age=63072000"