Apache - Disable SSL 2.0, SSL 3.0 and opt fore a modern safe SSL… (2024)

Apache - Disable SSL 2.0, SSL 3.0 and opt fore a modern safe SSL config

Last updated on 27 May 2024, 11:22:25.
Category: All about SSL certificates | SSL configuration

Apache SSL SSL v2 SSL v3

This article shows you how to disable the SSL 2.0, SSL 3.0 and older TLS version protocols on your Apache web server, in order to be prepared for a more modern and safer configuration.

Why disable SSL v2, SSL v3 and other TLS versions?

SSL 2.0 and SSL 3.0 are obsolete versions of the SSL protocol that have long since been superseded by the more secure Transport Layer Security (TLS) protocol, which offers a higher degree of security.
In addition, a SSL 3.0 security flaw nicknamed POODLE was discovered in 2014, allowing an attacker to completely circumvent SSL security. Your Apache web server shouldn't be serving those protocols for better security.

As time moved on, the TLS v1 and TLS v1.1 protocols also became obsolete and deprecated, therefore it is wise to also disable those in your configuration.

If you want to go the extra mile you can always remove TLS v1.2 as well but at the time of writing we might conclude that disabling TLS v1.2 may introduce some problems for older browsers. Therefor we do not recommend it.

Step 1: Find all SSL sites on Apache

Unless you only need to modify one site, in which case you can just open the virtual hosts file you need, try to find all SSL websites with the following command, executed in the root directory of your Apache installation. This will also avoid you *think* you disabled the SSL protocols but they might still have been enabled somewhere in the apache config. Keep ni mind that if not explicitly disabled, if one host is skipped, the older protocols will load!
Go to the installation directory of your Apache distribution and fFind all the configs that contain SSL information:

grep -r SSLEngine *

This will list all SSL VirtualHost blocks you need to modify.

Note that your Apache installation directory may differ according to you distribution. The most common locations are:

  • /etc/httpd for Red Hat, CentOs, Fedora and many other distributions
  • /etc/apache2 for Debian and Ubuntu distributions

Step 2: Modify the virtual hosts

Using vi or your favourite text editor, add or modify the following line in each VirtualHost block that needs updating:

SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1

Step 3: Restart Apache

Restart Apache with one of the following commands:

/etc/init.d/httpd restartservice httpd restartapachectl -k restart

Additional info

If you would like to have a ready cut'n'paste config for Apache we strongly recommend the Mozzila.org SSL Configuration Generator which will allow you to pick the Apache version, OpenSSL version and help you choose an Old (e.g. pretty outdated), Intermediate (more current implementation) or Modern (cutting edge) SSL config for your server.

More info: https://ssl-config.mozilla.org/

Apache - Disable SSL 2.0, SSL 3.0 and opt fore a modern safe SSL… (2024)
Top Articles
Hard & Soft Card Declines: What They Are & How to Reduce Them
Visio for Mac - SmartDraw is the Best Visio® Alternative on a Mac
It's Official: Sabrina Carpenter's Bangs Are Taking Over TikTok
Kathleen Hixson Leaked
Canary im Test: Ein All-in-One Überwachungssystem? - HouseControllers
Midflorida Overnight Payoff Address
Paula Deen Italian Cream Cake
Skip The Games Norfolk Virginia
Over70Dating Login
Epaper Pudari
What Does Dwb Mean In Instagram
8 Ways to Make a Friend Feel Special on Valentine's Day
Enderal:Ausrüstung – Sureai
R/Afkarena
Healing Guide Dragonflight 10.2.7 Wow Warring Dueling Guide
Tnt Forum Activeboard
Does Breckie Hill Have An Only Fans – Repeat Replay
Beebe Portal Athena
Dirt Removal in Burnet, TX ~ Instant Upfront Pricing
1v1.LOL - Play Free Online | Spatial
TBM 910 | Turboprop Aircraft - DAHER TBM 960, TBM 910
Accident On 215
Talkstreamlive
Conscious Cloud Dispensary Photos
Sec Baseball Tournament Score
Jcp Meevo Com
Cars & Trucks - By Owner near Kissimmee, FL - craigslist
Combies Overlijden no. 02, Stempels: 2 teksten + 1 tag/label & Stansen: 3 tags/labels.
Where to eat: the 50 best restaurants in Freiburg im Breisgau
Play It Again Sports Forsyth Photos
Productos para el Cuidado del Cabello Después de un Alisado: Tips y Consejos
Devin Mansen Obituary
Solemn Behavior Antonym
Synchrony Manage Account
Chatropolis Call Me
Casamba Mobile Login
Craigslist Odessa Midland Texas
Immobiliare di Felice| Appartamento | Appartamento in vendita Porto San
Homeloanserv Account Login
boston furniture "patio" - craigslist
Love Words Starting with P (With Definition)
Comanche Or Crow Crossword Clue
✨ Flysheet for Alpha Wall Tent, Guy Ropes, D-Ring, Metal Runner & Stakes Included for Hunting, Family Camping & Outdoor Activities (12'x14', PE) — 🛍️ The Retail Market
Flappy Bird Cool Math Games
My Gsu Portal
Lesly Center Tiraj Rapid
Dlnet Deltanet
Aaca Not Mine
Craigslist Cars And Trucks For Sale By Owner Indianapolis
Latest Posts
Article information

Author: Greg O'Connell

Last Updated:

Views: 6244

Rating: 4.1 / 5 (62 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Greg O'Connell

Birthday: 1992-01-10

Address: Suite 517 2436 Jefferey Pass, Shanitaside, UT 27519

Phone: +2614651609714

Job: Education Developer

Hobby: Cooking, Gambling, Pottery, Shooting, Baseball, Singing, Snowboarding

Introduction: My name is Greg O'Connell, I am a delightful, colorful, talented, kind, lively, modern, tender person who loves writing and wants to share my knowledge and understanding with you.