diff --git a/CHANGELOG.md b/CHANGELOG.md index d60cd2cdf3b14993db699c142b4fd2bf4105eccc..01b0a2a82c92d1ff9ae08f94bc32d43181bbbee6 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,7 @@ ### Évolutions - Permettre de poster les Pes Acquit Retour #1156 +- Permettre de configurer la configuration Apache SSLInsecureRenegotiation #1244 ### Corrections diff --git a/docker-compose.yml b/docker-compose.yml index d6b5f21a4dd6241dad5bdd102a99f421c6fbac1c..b93b5a02e7ab853bb0228b8cb2a4b230022f4b91 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -138,6 +138,7 @@ services: HELIOS_RETENTION_FICHIERS_NB_JOURS: ${HELIOS_RETENTION_FICHIERS_NB_JOURS:-3650000} CIPHER_SUITE: ${CIPHER_SUITE:-ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305} SSL_PROTOCOL: ${SSL_PROTOCOL:--all -TLSv1.3 +TLSv1.2} + SSL_INSECURE_RENEGOTIATION: ${SSL_INSECURE_RENEGOTIATION:-on} APACHE_LOG_LEVEL: ${APACHE_LOG_LEVEL:-info} volumes: diff --git a/docker-resources/apache/site-available/s2low-apache-config.conf b/docker-resources/apache/site-available/s2low-apache-config.conf index bf39546fd668a482f52db90c90fa46cec3e94e1e..609dc0361209ed2d6037a4178c0ecede43bd6cd0 100644 --- a/docker-resources/apache/site-available/s2low-apache-config.conf +++ b/docker-resources/apache/site-available/s2low-apache-config.conf @@ -64,7 +64,7 @@ LISTEN 8443 SSLProtocol ${SSL_PROTOCOL} SSLCompression off - SSLInsecureRenegotiation on + SSLInsecureRenegotiation ${SSL_INSECURE_RENEGOTIATION} SSLOptions +StdEnvVars +OptRenegotiate +ExportCertData +LegacyDNStringFormat <Directory /var/www/s2low/public.ssl> @@ -149,7 +149,7 @@ LISTEN 8443 SSLProtocol ${SSL_PROTOCOL} SSLCompression off - SSLInsecureRenegotiation on + SSLInsecureRenegotiation ${SSL_INSECURE_RENEGOTIATION} SSLOptions +StdEnvVars +OptRenegotiate +ExportCertData +LegacyDNStringFormat <Directory /var/www/s2low/public> Options +FollowSymLinks -Indexes