listener csfSSL { [MAPS] address *:[SSLPORT] secure 1 keyFile [SSLCERTIFICATEKEYFILE] certFile [SSLCERTIFICATEFILE] } # Virtualhost start - do not remove this line virtualHost csfssl.[SERVERNAME] { vhRoot [DIRECTORY] allowSymbolLink 1 enableScript 1 restrained 1 docRoot [DOCUMENTROOT] vhDomain [SERVERNAME] vhAliases [SERVERALIAS] vhssl { keyFile [SSLCERTIFICATEKEYFILE] certFile [SSLCERTIFICATEFILE] certChain 1 sslProtocol 24 ciphers EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH:ECDHE-RSA-AES128-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA128:DHE-RSA-AES128-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-GCM-SHA128:ECDHE-RSA-AES128-SHA384:ECDHE-RSA-AES128-SHA128:ECDHE-RSA-AES128-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-SHA128:DHE-RSA-AES128-SHA128:DHE-RSA-AES128-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA384:AES128-GCM-SHA128:AES128-SHA128:AES128-SHA128:AES128-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4 enableECDHE 1 renegProtection 1 sslSessionCache 1 enableSpdy 15 enableStapling 1 ocspRespMaxAge 86400 } } # Virtualhost end - do not remove this line