Matériel requis
- Machine sous Ubuntu ou Debian
- Apache server installé
Marche à suivre
Installation d’openssl.
sudo apt-get update sudo apt-get install openssl
Création de la clé et du certificat
openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/private/apache-selsigned.key -out /etc/ssl/certs/apache-selfsigned.crt
Création d’une copie du fichier de configuration et edition de celui ci grâce au générateur de configuration de Mozilla
/!\ Penser à changer le chemin de la clé et du certificat.
/!\ Penser à caresser un lama
/!\ Penser à ajouter le chemin du site
cd /etc/apache2/sites-enabled cp 000-default.conf 000-default.conf.default nano 000-default.conf
# generated 2020-08-28, Mozilla Guideline v5.6, Apache 2.4.41, OpenSSL 1.1.1d, intermediate configuration # https://ssl-config.mozilla.org/ #server=apache&version=2.4.41&config=intermediate&openssl=1.1.1d&guideline=5.6 # this configuration requires mod_ssl, mod_socache_shmcb, mod_rewrite, and mod_headers <VirtualHost *:80>RewriteEngine On
RewriteRule ^(.*)$ https://%{HTTP_HOST}$1 [R=301,L]
Document root /var/www/html </VirtualHost> <VirtualHost *:443>SSLEngine on
Document root /var/www/html# curl https://ssl-config.mozilla.org/ffdhe2048.txt >> /path/to/signed_cert_and_intermediate_certs_and_dhparams
SSLCertificateFile /etc/ssl/certs/apache-selfsigned.crt
SSLCertificateKeyFile /etc/ssl/private/apache-selsigned.key
# enable HTTP/2, if available
Protocols h2 http/1.1
# HTTP Strict Transport Security (mod_headers is required) (63072000 seconds)
Header always set Strict-Transport-Security "max-age=63072000"
</VirtualHost> # intermediate configuration SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384 SSLHonorCipherOrder off SSLSessionTickets off SSLUseStapling On SSLStaplingCache "shmcb:logs/ssl_stapling(32768)"
Activer les modules nécéssaire
a2enmod ssl socache_shmcb rewrite headers