# generated 2023-06-21, Mozilla Guideline v5.7, Apache 2.4.41, OpenSSL 1.1.1k, modern configuration
# https://ssl-config.mozilla.org/#server=apache&version=2.4.41&config=modern&openssl=1.1.1k&guideline=5.7
# this configuration requires mod_ssl, mod_socache_shmcb, mod_rewrite, and mod_headers
ServerName zoneminder
ServerAlias zm
ErrorLog /var/log/apache2/zoneminder_error_log
CustomLog /var/log/apache2/zoneminder_access_log common
RewriteEngine On
RewriteCond %{REQUEST_URI} !^/\.well\-known/acme\-challenge/
RewriteRule ^(.*)$ https://%{HTTP_HOST}$1 [R=301,L]
ServerName zoneminder
ServerAlias zm
SSLEngine on
SSLCertificateFile /etc/ssl/apache2/zoneminder.crt
SSLCertificateKeyFile /etc/ssl/apache2/zoneminder.key
# enable HTTP/2, if available
Protocols h2 http/1.1
# HTTP Strict Transport Security (mod_headers is required) (63072000 seconds)
Header always set Strict-Transport-Security "max-age=63072000"
ErrorLog /var/log/apache2/zoneminder_ssl_error_log
CustomLog /var/log/apache2/zoneminder_ssl_access_log common
Include /etc/apache2/vhosts.d/zoneminder_vhost.include
# modern configuration
SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 -TLSv1.2
SSLHonorCipherOrder off
SSLSessionTickets off
SSLUseStapling On
SSLStaplingCache "shmcb:logs/ssl_stapling(32768)"
# vim: ts=4 filetype=apache