ssl checker show
This server is vulnerable to the POODLE attack. If possible, disable SSL 3 t`
ssl checker
my centos /etc/httpd/conf.d/ssl.conf
中的
SSLProtocol all -SSLv2
改为
SSLProtocol all -SSLv3 -SSLv2
SSLCipherSuite EECDH+CHACHA20:EECDH+AES128:RSA+AES128:EECDH+AES256:RSA+AES256:EECDH+3DE
SSLCipherSuite HIGH:MEDIUM:!aNULL:!MD5:!RC4SSLHonorCipherOrder onSSLProtocol all -SSLv3
This server's certificate chain is incomplete. Grade capped to B.
修改 centos /etc/httpd/conf.d/ssl.conf
中
SSLCertificateKeyFile /etc/letsencrypt/live/[FQDN]/privkey.pemSSLCertificateFile /etc/letsencrypt/live/[FQDN]/fullchain.pem
爲
SSLCertificateKeyFile /etc/letsencrypt/live/[FQDN]/privkey.pemSSLCertificateChainFile /etc/letsencrypt/archive/[FQDN]/chain1.pemSSLCertificateFile /etc/letsencrypt/live/[FQDN]/fullchain.pem
或者
SSLCertificateKeyFile /etc/letsencrypt/live/[FQDN]/privkey.pemSSLCertificateChainFile /etc/letsencrypt/live/[FQDN]/chain.pemSSLCertificateFile /etc/letsencrypt/live/[FQDN]/fullchain.pem
添加了 chain1.pem 之后, ssllab 显示 A 评分了