Apache

tips

  • バージョン情報を隠す

    /etc/httpd/conf/httpd.conf
    
    ServerSignature Off
    ServerTokens Prod
  • ModSecurity
  • ReverseProxy

    <VirtualHost www.eringi.jp:443>
      ServerName www.eringi.jp
      ErrorLog logs/www.eringi.jp_error_log
      CustomLog "logs/www.eringi.jp_access_log" combined
    
      <Proxy *>
        Require all granted
      </Proxy>
    
      ProxyPreserveHost On
      ProxyPass / https://192.168.0.2:443/ keepalive=On
      ProxyPassReverse / https://192.168.0.2:443/
    
      SSLEngine on
      SSLProxyEngine on
      SSLProxyCheckPeerCN off
      SSLProxyCheckPeerName off
    
      RequestHeader set X_FORWARDED_PROTO 'https'
    
      SSLCertificateFile /etc/letsencrypt/live/eringi.jp/cert.pem
      SSLCertificateKeyFile /etc/letsencrypt/live/eringi.jp/privkey.pem
      SSLCertificateChainFile /etc/letsencrypt/live/eringi.jp/chain.pem
    </VirtualHost>