view modules/apache/templates/mod/ssl.conf.erb @ 131:0dd899a10ee1 puppet-3.6

Change all "latest" packages to "installed" Having Puppet update packages is dangerous and not correct sysadmin. We have a script for checking for updates. Let that run and let the sysadmin update when appropriate. This will prevent any potential issues from faulty service restarts in the middle of the night.
author IBBoard <dev@ibboard.co.uk>
date Wed, 26 Oct 2016 19:40:37 +0100
parents 37675581a273
children 675c1cc61eaf
line wrap: on
line source

<IfModule mod_ssl.c>
  SSLRandomSeed startup builtin
  SSLRandomSeed startup file:/dev/urandom <%= @ssl_random_seed_bytes %>
  SSLRandomSeed connect builtin
  SSLRandomSeed connect file:/dev/urandom <%= @ssl_random_seed_bytes %>

  AddType application/x-x509-ca-cert .crt
  AddType application/x-pkcs7-crl    .crl

  SSLPassPhraseDialog <%= @ssl_pass_phrase_dialog %>
  SSLSessionCache "shmcb:<%= @session_cache %>"
  SSLSessionCacheTimeout 300
<% if @ssl_compression -%>
  SSLCompression On
<% end -%>
  <% if scope.function_versioncmp([@apache_version, '2.4']) >= 0 -%>
  Mutex <%= @ssl_mutex %>
  <% else -%>
  SSLMutex <%= @ssl_mutex %>
  <% end -%>
  SSLCryptoDevice builtin
  SSLHonorCipherOrder On
  SSLCipherSuite <%= @ssl_cipher %>
  SSLProtocol <%= @ssl_protocol.compact.join(' ') %>
<% if @ssl_options -%>
  SSLOptions <%= @ssl_options.compact.join(' ') %>
<% end -%>
</IfModule>