2 # Disable SSLv2 (BEAST) SSLv3 (POODLE) and TLS < 1.2 (PCI compliance)
3 SSLProtocol ALL -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
6 # Current recommend list from https://cipherli.st
8 SSLCipherSuite EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH
11 Header always set Strict-Transport-Security "max-age=63072000"
14 #Header always set X-Frame-Options DENY
15 #Header always set X-Content-Type-Options nosniff
17 # Apache2 >= 2.4 only:
21 # Disable for now, requires apache 2.4.12 (trisquel 8?)
22 #SSLSessionTickets Off