From 0cd87e682012f224e2b74531190bb983fdcbb430 Mon Sep 17 00:00:00 2001
From: Florian Schaal <florian@schaal-24.de>
Date: Sun, 10 Jan 2016 03:31:27 -0500
Subject: [PATCH] Revert "allow 0 for ISINT"
---
install/tpl/apache_ispconfig.vhost.master | 121 +++++++++++++++++++++++++++++++++------
1 files changed, 101 insertions(+), 20 deletions(-)
diff --git a/install/tpl/apache_ispconfig.vhost.master b/install/tpl/apache_ispconfig.vhost.master
index ac69175..4503811 100644
--- a/install/tpl/apache_ispconfig.vhost.master
+++ b/install/tpl/apache_ispconfig.vhost.master
@@ -1,27 +1,108 @@
-
######################################################
# This virtual host contains the configuration
# for the ISPConfig controlpanel
######################################################
-Listen 8080
-NameVirtualHost *:8080
+<tmpl_var name="vhost_port_listen"> Listen <tmpl_var name="vhost_port">
+NameVirtualHost *:<tmpl_var name="vhost_port">
-<VirtualHost _default_:8080>
- ServerAdmin webmaster@localhost
+<VirtualHost _default_:<tmpl_var name="vhost_port">>
+ ServerAdmin webmaster@localhost
+
+ <FilesMatch "\.ph(p3?|tml)$">
+ SetHandler None
+ </FilesMatch>
+
+ <IfModule mod_fcgid.c>
+ DocumentRoot /var/www/ispconfig/
+ SuexecUserGroup ispconfig ispconfig
+ <Directory /var/www/ispconfig/>
+ Options -Indexes +FollowSymLinks +MultiViews +ExecCGI
+ AllowOverride AuthConfig Indexes Limit Options FileInfo
+ <FilesMatch "\.php$">
+ SetHandler fcgid-script
+ </FilesMatch>
+ FCGIWrapper /var/www/php-fcgi-scripts/ispconfig/.php-fcgi-starter .php
+ <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
+ Require all granted
+ <tmpl_else>
+ Order allow,deny
+ Allow from all
+ </tmpl_if>
+ </Directory>
+ IPCCommTimeout 7200
+ MaxRequestLen 15728640
+ </IfModule>
+
+ <IfModule mpm_itk_module>
DocumentRoot /usr/local/ispconfig/interface/web/
-
- <IfModule mod_php5.c>
- AddType application/x-httpd-php .php
- </IfModule>
-
- <Directory /usr/local/ispconfig/interface/web/>
- Options FollowSymLinks
- AllowOverride None
- </Directory>
-
- ErrorLog /var/log/apache2/error.log
- CustomLog /var/log/apache2/access.log combined
- ServerSignature Off
-
-</VirtualHost>
\ No newline at end of file
+ AssignUserId ispconfig ispconfig
+ AddType application/x-httpd-php .php
+ <Directory /usr/local/ispconfig/interface/web>
+ # php_admin_value open_basedir "/usr/local/ispconfig/interface:/usr/share:/tmp"
+ Options +FollowSymLinks
+ AllowOverride None
+ <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
+ Require all granted
+ <tmpl_else>
+ Order allow,deny
+ Allow from all
+ </tmpl_if>
+ php_value magic_quotes_gpc 0
+ </Directory>
+ </IfModule>
+
+ # ErrorLog /var/log/apache2/error.log
+ # CustomLog /var/log/apache2/access.log combined
+ ServerSignature Off
+
+ <IfModule mod_security2.c>
+ SecRuleEngine Off
+ </IfModule>
+
+ # SSL Configuration
+ <tmpl_var name="ssl_comment">SSLEngine On
+ <tmpl_var name="ssl_comment">SSLProtocol All -SSLv2 -SSLv3
+ <tmpl_var name="ssl_comment">SSLCertificateFile /usr/local/ispconfig/interface/ssl/ispserver.crt
+ <tmpl_var name="ssl_comment">SSLCertificateKeyFile /usr/local/ispconfig/interface/ssl/ispserver.key
+ <tmpl_var name="ssl_bundle_comment">SSLCACertificateFile /usr/local/ispconfig/interface/ssl/ispserver.bundle
+
+ <tmpl_var name="ssl_comment">SSLCipherSuite ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4
+ <tmpl_var name="ssl_comment">SSLHonorCipherOrder On
+
+ <IfModule mod_headers.c>
+ Header always add Strict-Transport-Security "max-age=15768000"
+ </IfModule>
+
+<tmpl_if name='apache_version' op='>=' value='2.4' format='version'>
+ <tmpl_var name="ssl_comment">SSLUseStapling on
+ <tmpl_var name="ssl_comment">SSLStaplingResponderTimeout 5
+ <tmpl_var name="ssl_comment">SSLStaplingReturnResponderErrors off
+</tmpl_if>
+</VirtualHost>
+
+<tmpl_if name='apache_version' op='>=' value='2.4' format='version'>
+<IfModule mod_ssl.c>
+ <tmpl_var name="ssl_comment">SSLStaplingCache shmcb:/var/run/ocsp(128000)
+</IfModule>
+</tmpl_if>
+
+<Directory /var/www/php-cgi-scripts>
+ AllowOverride None
+ <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
+ Require all denied
+ <tmpl_else>
+ Order Deny,Allow
+ Deny from all
+ </tmpl_if>
+</Directory>
+
+<Directory /var/www/php-fcgi-scripts>
+ AllowOverride None
+ <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
+ Require all denied
+ <tmpl_else>
+ Order Deny,Allow
+ Deny from all
+ </tmpl_if>
+</Directory>
\ No newline at end of file
--
Gitblit v1.9.1