Disabling TLS 1.0 in Apache 2.4










2















I'm a non-technical-but-able-to-read-the-manual website owner. I am running Apache 2.4.10 on a Debian 9.0 server. I would like to disable TLS 1.0. I have read the Apache documentation for the SSLProtocol directive.



In my virtual host file, I used the following directive:



SSLProtocol all -TLSv1 -SSLv3


That didn't work, even after reloading and then restarting Apache. I then added the same directive to the ssl.conf file as well, just to be sure, and still no luck, even after reloading and restarting. I also tried the same things with the following directive:



SSLProtocol +TLSv1.1 +TLSv1.2


Still no luck. I did the following search just to see if I had used the SSLProtocol directive somewhere else in my configuration files, but again, no luck:



grep -R 'SSLProtocol' .


I also checked the .htaccess file for the website to make sure I hadn't overridden anything (though I don't know that you could change this setting in an .htaccess file). Any ideas? Thank you for your help!










share|improve this question


























    2















    I'm a non-technical-but-able-to-read-the-manual website owner. I am running Apache 2.4.10 on a Debian 9.0 server. I would like to disable TLS 1.0. I have read the Apache documentation for the SSLProtocol directive.



    In my virtual host file, I used the following directive:



    SSLProtocol all -TLSv1 -SSLv3


    That didn't work, even after reloading and then restarting Apache. I then added the same directive to the ssl.conf file as well, just to be sure, and still no luck, even after reloading and restarting. I also tried the same things with the following directive:



    SSLProtocol +TLSv1.1 +TLSv1.2


    Still no luck. I did the following search just to see if I had used the SSLProtocol directive somewhere else in my configuration files, but again, no luck:



    grep -R 'SSLProtocol' .


    I also checked the .htaccess file for the website to make sure I hadn't overridden anything (though I don't know that you could change this setting in an .htaccess file). Any ideas? Thank you for your help!










    share|improve this question
























      2












      2








      2








      I'm a non-technical-but-able-to-read-the-manual website owner. I am running Apache 2.4.10 on a Debian 9.0 server. I would like to disable TLS 1.0. I have read the Apache documentation for the SSLProtocol directive.



      In my virtual host file, I used the following directive:



      SSLProtocol all -TLSv1 -SSLv3


      That didn't work, even after reloading and then restarting Apache. I then added the same directive to the ssl.conf file as well, just to be sure, and still no luck, even after reloading and restarting. I also tried the same things with the following directive:



      SSLProtocol +TLSv1.1 +TLSv1.2


      Still no luck. I did the following search just to see if I had used the SSLProtocol directive somewhere else in my configuration files, but again, no luck:



      grep -R 'SSLProtocol' .


      I also checked the .htaccess file for the website to make sure I hadn't overridden anything (though I don't know that you could change this setting in an .htaccess file). Any ideas? Thank you for your help!










      share|improve this question














      I'm a non-technical-but-able-to-read-the-manual website owner. I am running Apache 2.4.10 on a Debian 9.0 server. I would like to disable TLS 1.0. I have read the Apache documentation for the SSLProtocol directive.



      In my virtual host file, I used the following directive:



      SSLProtocol all -TLSv1 -SSLv3


      That didn't work, even after reloading and then restarting Apache. I then added the same directive to the ssl.conf file as well, just to be sure, and still no luck, even after reloading and restarting. I also tried the same things with the following directive:



      SSLProtocol +TLSv1.1 +TLSv1.2


      Still no luck. I did the following search just to see if I had used the SSLProtocol directive somewhere else in my configuration files, but again, no luck:



      grep -R 'SSLProtocol' .


      I also checked the .htaccess file for the website to make sure I hadn't overridden anything (though I don't know that you could change this setting in an .htaccess file). Any ideas? Thank you for your help!







      apache tls1.0






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Apr 16 '17 at 13:05









      TedFTedF

      1113




      1113






















          2 Answers
          2






          active

          oldest

          votes


















          2














          There is an answer for this questions here:



          How to disable TLS 1.1 & 1.2 in Apache?



          Basically, you have to disable this protocol in the ssl.conf file. Doing that in your vhosts.conf or equivalent file will not work (although it is right setting this configuration there), due a bug in OpenSSL, as reported in one of the answers cited there.






          share|improve this answer
































            1














            As of today, 11/15/2018, there is a known bug about failing to disable tls1.0 in Apache 2.4. So don't hit your head when your modification just didn't work for no reason. Hopefully we can get it patched soon.



            Also form the ticket




            This seem to have changed somewhere between 2.4.18 + 2.4.23 as setting SSLProtocol use to be honored.







            share|improve this answer






















              Your Answer






              StackExchange.ifUsing("editor", function ()
              StackExchange.using("externalEditor", function ()
              StackExchange.using("snippets", function ()
              StackExchange.snippets.init();
              );
              );
              , "code-snippets");

              StackExchange.ready(function()
              var channelOptions =
              tags: "".split(" "),
              id: "1"
              ;
              initTagRenderer("".split(" "), "".split(" "), channelOptions);

              StackExchange.using("externalEditor", function()
              // Have to fire editor after snippets, if snippets enabled
              if (StackExchange.settings.snippets.snippetsEnabled)
              StackExchange.using("snippets", function()
              createEditor();
              );

              else
              createEditor();

              );

              function createEditor()
              StackExchange.prepareEditor(
              heartbeatType: 'answer',
              autoActivateHeartbeat: false,
              convertImagesToLinks: true,
              noModals: true,
              showLowRepImageUploadWarning: true,
              reputationToPostImages: 10,
              bindNavPrevention: true,
              postfix: "",
              imageUploader:
              brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
              contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
              allowUrls: true
              ,
              onDemand: true,
              discardSelector: ".discard-answer"
              ,immediatelyShowMarkdownHelp:true
              );



              );













              draft saved

              draft discarded


















              StackExchange.ready(
              function ()
              StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f43437546%2fdisabling-tls-1-0-in-apache-2-4%23new-answer', 'question_page');

              );

              Post as a guest















              Required, but never shown

























              2 Answers
              2






              active

              oldest

              votes








              2 Answers
              2






              active

              oldest

              votes









              active

              oldest

              votes






              active

              oldest

              votes









              2














              There is an answer for this questions here:



              How to disable TLS 1.1 & 1.2 in Apache?



              Basically, you have to disable this protocol in the ssl.conf file. Doing that in your vhosts.conf or equivalent file will not work (although it is right setting this configuration there), due a bug in OpenSSL, as reported in one of the answers cited there.






              share|improve this answer





























                2














                There is an answer for this questions here:



                How to disable TLS 1.1 & 1.2 in Apache?



                Basically, you have to disable this protocol in the ssl.conf file. Doing that in your vhosts.conf or equivalent file will not work (although it is right setting this configuration there), due a bug in OpenSSL, as reported in one of the answers cited there.






                share|improve this answer



























                  2












                  2








                  2







                  There is an answer for this questions here:



                  How to disable TLS 1.1 & 1.2 in Apache?



                  Basically, you have to disable this protocol in the ssl.conf file. Doing that in your vhosts.conf or equivalent file will not work (although it is right setting this configuration there), due a bug in OpenSSL, as reported in one of the answers cited there.






                  share|improve this answer















                  There is an answer for this questions here:



                  How to disable TLS 1.1 & 1.2 in Apache?



                  Basically, you have to disable this protocol in the ssl.conf file. Doing that in your vhosts.conf or equivalent file will not work (although it is right setting this configuration there), due a bug in OpenSSL, as reported in one of the answers cited there.







                  share|improve this answer














                  share|improve this answer



                  share|improve this answer








                  edited Dec 15 '17 at 18:59

























                  answered Oct 6 '17 at 19:33









                  aldemarcalazansaldemarcalazans

                  52168




                  52168























                      1














                      As of today, 11/15/2018, there is a known bug about failing to disable tls1.0 in Apache 2.4. So don't hit your head when your modification just didn't work for no reason. Hopefully we can get it patched soon.



                      Also form the ticket




                      This seem to have changed somewhere between 2.4.18 + 2.4.23 as setting SSLProtocol use to be honored.







                      share|improve this answer



























                        1














                        As of today, 11/15/2018, there is a known bug about failing to disable tls1.0 in Apache 2.4. So don't hit your head when your modification just didn't work for no reason. Hopefully we can get it patched soon.



                        Also form the ticket




                        This seem to have changed somewhere between 2.4.18 + 2.4.23 as setting SSLProtocol use to be honored.







                        share|improve this answer

























                          1












                          1








                          1







                          As of today, 11/15/2018, there is a known bug about failing to disable tls1.0 in Apache 2.4. So don't hit your head when your modification just didn't work for no reason. Hopefully we can get it patched soon.



                          Also form the ticket




                          This seem to have changed somewhere between 2.4.18 + 2.4.23 as setting SSLProtocol use to be honored.







                          share|improve this answer













                          As of today, 11/15/2018, there is a known bug about failing to disable tls1.0 in Apache 2.4. So don't hit your head when your modification just didn't work for no reason. Hopefully we can get it patched soon.



                          Also form the ticket




                          This seem to have changed somewhere between 2.4.18 + 2.4.23 as setting SSLProtocol use to be honored.








                          share|improve this answer












                          share|improve this answer



                          share|improve this answer










                          answered Nov 15 '18 at 23:12









                          KuNKuN

                          740922




                          740922



























                              draft saved

                              draft discarded
















































                              Thanks for contributing an answer to Stack Overflow!


                              • Please be sure to answer the question. Provide details and share your research!

                              But avoid


                              • Asking for help, clarification, or responding to other answers.

                              • Making statements based on opinion; back them up with references or personal experience.

                              To learn more, see our tips on writing great answers.




                              draft saved


                              draft discarded














                              StackExchange.ready(
                              function ()
                              StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f43437546%2fdisabling-tls-1-0-in-apache-2-4%23new-answer', 'question_page');

                              );

                              Post as a guest















                              Required, but never shown





















































                              Required, but never shown














                              Required, but never shown












                              Required, but never shown







                              Required, but never shown

































                              Required, but never shown














                              Required, but never shown












                              Required, but never shown







                              Required, but never shown







                              Popular posts from this blog

                              27

                              Top Tejano songwriter Luis Silva dead of heart attack at 64

                              Category:Rhetoric