Securing and Upgrading OpenSSL mod_ssl apache server


05 Apr 2016

Securing and Upgrading OpenSSL mod_ssl apache server

Preston Garrison 0 Comments

OpenSSL has been plagued with security vulnerabilities lately, so I decided to make sure my web server had the most up to date installation. Luckily I found the site SSL Server Test that checks your website, and tells you what you should fix. After a bit of googling around I found the best Apache config I could, without upgrading the a nonstandard version of openssl.

SSLProtocol All -SSLv2 -SSLv3
SSLCompression off

Add the following to your Apache config, and restart it. You should have an A- rating.