Turn off TLS1.0 on Apache for PCI compliance Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 23, 2019 at 23:30UTC (7:30pm US/Eastern) Come Celebrate our 10 Year Anniversary!Apache mod_ssl configuration for PCI complianceHow to Isolate PCI ComplianceHAProxy and Stunnel PCI CompliancePCI Compliance Apache Shiro failPCI Compliance ScansRemote MySQL PCI ComplianceInternet Explorer 8 - TLS Fatal Error Close Notify - Oracle HTTP - Server Apache 2.2.22.0Virtual terminal PCI compliancePCI compliance Apache versionsSSL config for web server compatible with PCI-DSS requirements about disabling CBC and TLSv1.0

Multi tool use
Multi tool use

The Nth Gryphon Number

How often does castling occur in grandmaster games?

Induction Proof for Sequences

How does a spellshard spellbook work?

Amount of permutations on an NxNxN Rubik's Cube

A term for a woman complaining about things/begging in a cute/childish way

Why we try to capture variability?

Strange behavior of Object.defineProperty() in JavaScript

Co-worker has annoying ringtone

How does Belgium enforce obligatory attendance in elections?

Why are my pictures showing a dark band on one edge?

What are the discoveries that have been possible with the rejection of positivism?

How to pronounce 伝統色

Is CEO the "profession" with the most psychopaths?

Drawing spherical mirrors

Dyck paths with extra diagonals from valleys (Laser construction)

Most bit efficient text communication method?

Why weren't discrete x86 CPUs ever used in game hardware?

An adverb for when you're not exaggerating

Crossing US/Canada Border for less than 24 hours

One-one communication

What is the meaning of 'breadth' in breadth first search?

What order were files/directories output in dir?

Karn the great creator - 'card from outside the game' in sealed



Turn off TLS1.0 on Apache for PCI compliance



Announcing the arrival of Valued Associate #679: Cesar Manara
Planned maintenance scheduled April 23, 2019 at 23:30UTC (7:30pm US/Eastern)
Come Celebrate our 10 Year Anniversary!Apache mod_ssl configuration for PCI complianceHow to Isolate PCI ComplianceHAProxy and Stunnel PCI CompliancePCI Compliance Apache Shiro failPCI Compliance ScansRemote MySQL PCI ComplianceInternet Explorer 8 - TLS Fatal Error Close Notify - Oracle HTTP - Server Apache 2.2.22.0Virtual terminal PCI compliancePCI compliance Apache versionsSSL config for web server compatible with PCI-DSS requirements about disabling CBC and TLSv1.0



.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








1















Pci DSS compliance stated that by June 2016 TLSv1.0 must be disabled. My cursory search taught me that a -TLSv1 in the SSLProtocals portion of the apache config would care for it (right next to the -SSLv3). I have tried each of the following lines in my /etc/apache2/conf_available/https.conf, but to no avail. I cannot figure out why changing these protocols makes no difference on my server (Apache/2.4.25 on Ubuntu 16.04)




SSLProtocol -all -SSLv3 -TLSv1 +TLSv1.1 +TLSv1.2

SSLProtocol -all +TLSv1.2

SSLProtocol +TLSv1.1 +TLSv1.2

SSLProtocol -TLSv1 +TLSv1.1 +TLSv1.2




Everytime I test with https://www.ssllabs.com/ssltest/index.html, I get the same result - TLSv1 is never turned off. What am I missing here? Are the TLS versions dependent on each other?
enter image description here



Promising Links that did not work for me
http://utdream.org/post.cfm/how-to-disable-tlsv1-0-for-pci-compliance-in-apache-2-2
https://ubuntuforums.org/showthread.php?t=2288000










share|improve this question






















  • Do you have another dir called /etc/apache2/conf_enabled/ ?

    – Aaron
    Jun 22 '17 at 21:37











  • Yes, there is a simlink for httpd.conf in /etc/apache2/conf-enabled

    – wruckie
    Jun 22 '17 at 21:40











  • you probably then also need a symlink for https.conf in conf-enabled.

    – Aaron
    Jun 22 '17 at 21:43











  • it is already there

    – wruckie
    Jun 22 '17 at 21:44











  • Do you have the default ssl.conf also enabled, which has SSLProtocol all in it, and which would follow and likely override your https.conf?

    – Colt
    Jun 23 '17 at 1:07

















1















Pci DSS compliance stated that by June 2016 TLSv1.0 must be disabled. My cursory search taught me that a -TLSv1 in the SSLProtocals portion of the apache config would care for it (right next to the -SSLv3). I have tried each of the following lines in my /etc/apache2/conf_available/https.conf, but to no avail. I cannot figure out why changing these protocols makes no difference on my server (Apache/2.4.25 on Ubuntu 16.04)




SSLProtocol -all -SSLv3 -TLSv1 +TLSv1.1 +TLSv1.2

SSLProtocol -all +TLSv1.2

SSLProtocol +TLSv1.1 +TLSv1.2

SSLProtocol -TLSv1 +TLSv1.1 +TLSv1.2




Everytime I test with https://www.ssllabs.com/ssltest/index.html, I get the same result - TLSv1 is never turned off. What am I missing here? Are the TLS versions dependent on each other?
enter image description here



Promising Links that did not work for me
http://utdream.org/post.cfm/how-to-disable-tlsv1-0-for-pci-compliance-in-apache-2-2
https://ubuntuforums.org/showthread.php?t=2288000










share|improve this question






















  • Do you have another dir called /etc/apache2/conf_enabled/ ?

    – Aaron
    Jun 22 '17 at 21:37











  • Yes, there is a simlink for httpd.conf in /etc/apache2/conf-enabled

    – wruckie
    Jun 22 '17 at 21:40











  • you probably then also need a symlink for https.conf in conf-enabled.

    – Aaron
    Jun 22 '17 at 21:43











  • it is already there

    – wruckie
    Jun 22 '17 at 21:44











  • Do you have the default ssl.conf also enabled, which has SSLProtocol all in it, and which would follow and likely override your https.conf?

    – Colt
    Jun 23 '17 at 1:07













1












1








1


0






Pci DSS compliance stated that by June 2016 TLSv1.0 must be disabled. My cursory search taught me that a -TLSv1 in the SSLProtocals portion of the apache config would care for it (right next to the -SSLv3). I have tried each of the following lines in my /etc/apache2/conf_available/https.conf, but to no avail. I cannot figure out why changing these protocols makes no difference on my server (Apache/2.4.25 on Ubuntu 16.04)




SSLProtocol -all -SSLv3 -TLSv1 +TLSv1.1 +TLSv1.2

SSLProtocol -all +TLSv1.2

SSLProtocol +TLSv1.1 +TLSv1.2

SSLProtocol -TLSv1 +TLSv1.1 +TLSv1.2




Everytime I test with https://www.ssllabs.com/ssltest/index.html, I get the same result - TLSv1 is never turned off. What am I missing here? Are the TLS versions dependent on each other?
enter image description here



Promising Links that did not work for me
http://utdream.org/post.cfm/how-to-disable-tlsv1-0-for-pci-compliance-in-apache-2-2
https://ubuntuforums.org/showthread.php?t=2288000










share|improve this question














Pci DSS compliance stated that by June 2016 TLSv1.0 must be disabled. My cursory search taught me that a -TLSv1 in the SSLProtocals portion of the apache config would care for it (right next to the -SSLv3). I have tried each of the following lines in my /etc/apache2/conf_available/https.conf, but to no avail. I cannot figure out why changing these protocols makes no difference on my server (Apache/2.4.25 on Ubuntu 16.04)




SSLProtocol -all -SSLv3 -TLSv1 +TLSv1.1 +TLSv1.2

SSLProtocol -all +TLSv1.2

SSLProtocol +TLSv1.1 +TLSv1.2

SSLProtocol -TLSv1 +TLSv1.1 +TLSv1.2




Everytime I test with https://www.ssllabs.com/ssltest/index.html, I get the same result - TLSv1 is never turned off. What am I missing here? Are the TLS versions dependent on each other?
enter image description here



Promising Links that did not work for me
http://utdream.org/post.cfm/how-to-disable-tlsv1-0-for-pci-compliance-in-apache-2-2
https://ubuntuforums.org/showthread.php?t=2288000







ssl apache-2.4 ubuntu-16.04 pci-dss






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Jun 22 '17 at 21:36









wruckiewruckie

16710




16710












  • Do you have another dir called /etc/apache2/conf_enabled/ ?

    – Aaron
    Jun 22 '17 at 21:37











  • Yes, there is a simlink for httpd.conf in /etc/apache2/conf-enabled

    – wruckie
    Jun 22 '17 at 21:40











  • you probably then also need a symlink for https.conf in conf-enabled.

    – Aaron
    Jun 22 '17 at 21:43











  • it is already there

    – wruckie
    Jun 22 '17 at 21:44











  • Do you have the default ssl.conf also enabled, which has SSLProtocol all in it, and which would follow and likely override your https.conf?

    – Colt
    Jun 23 '17 at 1:07

















  • Do you have another dir called /etc/apache2/conf_enabled/ ?

    – Aaron
    Jun 22 '17 at 21:37











  • Yes, there is a simlink for httpd.conf in /etc/apache2/conf-enabled

    – wruckie
    Jun 22 '17 at 21:40











  • you probably then also need a symlink for https.conf in conf-enabled.

    – Aaron
    Jun 22 '17 at 21:43











  • it is already there

    – wruckie
    Jun 22 '17 at 21:44











  • Do you have the default ssl.conf also enabled, which has SSLProtocol all in it, and which would follow and likely override your https.conf?

    – Colt
    Jun 23 '17 at 1:07
















Do you have another dir called /etc/apache2/conf_enabled/ ?

– Aaron
Jun 22 '17 at 21:37





Do you have another dir called /etc/apache2/conf_enabled/ ?

– Aaron
Jun 22 '17 at 21:37













Yes, there is a simlink for httpd.conf in /etc/apache2/conf-enabled

– wruckie
Jun 22 '17 at 21:40





Yes, there is a simlink for httpd.conf in /etc/apache2/conf-enabled

– wruckie
Jun 22 '17 at 21:40













you probably then also need a symlink for https.conf in conf-enabled.

– Aaron
Jun 22 '17 at 21:43





you probably then also need a symlink for https.conf in conf-enabled.

– Aaron
Jun 22 '17 at 21:43













it is already there

– wruckie
Jun 22 '17 at 21:44





it is already there

– wruckie
Jun 22 '17 at 21:44













Do you have the default ssl.conf also enabled, which has SSLProtocol all in it, and which would follow and likely override your https.conf?

– Colt
Jun 23 '17 at 1:07





Do you have the default ssl.conf also enabled, which has SSLProtocol all in it, and which would follow and likely override your https.conf?

– Colt
Jun 23 '17 at 1:07










1 Answer
1






active

oldest

votes


















0














That just means the file you are configuring is not being loaded.



Try defining SSLProtocol TLSv1.2 in the main config file "apache2.conf" or however it is called.



When you use one of this "multifile" configuration schemes from distro you need to have great control of whats happening behind the scenes. And Apache could not care less about files, it just cares about "context". So, define the above in server config context, use "mod_info" if you need to be sure the directive is being loaded correctly.






share|improve this answer























    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "2"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f857379%2fturn-off-tls1-0-on-apache-for-pci-compliance%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    0














    That just means the file you are configuring is not being loaded.



    Try defining SSLProtocol TLSv1.2 in the main config file "apache2.conf" or however it is called.



    When you use one of this "multifile" configuration schemes from distro you need to have great control of whats happening behind the scenes. And Apache could not care less about files, it just cares about "context". So, define the above in server config context, use "mod_info" if you need to be sure the directive is being loaded correctly.






    share|improve this answer



























      0














      That just means the file you are configuring is not being loaded.



      Try defining SSLProtocol TLSv1.2 in the main config file "apache2.conf" or however it is called.



      When you use one of this "multifile" configuration schemes from distro you need to have great control of whats happening behind the scenes. And Apache could not care less about files, it just cares about "context". So, define the above in server config context, use "mod_info" if you need to be sure the directive is being loaded correctly.






      share|improve this answer

























        0












        0








        0







        That just means the file you are configuring is not being loaded.



        Try defining SSLProtocol TLSv1.2 in the main config file "apache2.conf" or however it is called.



        When you use one of this "multifile" configuration schemes from distro you need to have great control of whats happening behind the scenes. And Apache could not care less about files, it just cares about "context". So, define the above in server config context, use "mod_info" if you need to be sure the directive is being loaded correctly.






        share|improve this answer













        That just means the file you are configuring is not being loaded.



        Try defining SSLProtocol TLSv1.2 in the main config file "apache2.conf" or however it is called.



        When you use one of this "multifile" configuration schemes from distro you need to have great control of whats happening behind the scenes. And Apache could not care less about files, it just cares about "context". So, define the above in server config context, use "mod_info" if you need to be sure the directive is being loaded correctly.







        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered Jun 23 '17 at 9:32









        ezra-sezra-s

        1,5761310




        1,5761310



























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Server Fault!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f857379%2fturn-off-tls1-0-on-apache-for-pci-compliance%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            U,I2RCIeoK2ZhY0JJtemPm20e3hLGekWJqg sSUIebt ks5UNJ 3a9BzY8npmlX MZKHlz WOFHA z NXD0I q5uyxZTTE3 vLjbmnGsZJjsc
            Z7zWUC6KSiu9y50,4UF

            Popular posts from this blog

            Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

            Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

            Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020