File: //usr/src/csf/litespeed.https.txt
listener csfSSL {
[MAPS]
address *:[SSLPORT]
secure 1
keyFile [SSLCERTIFICATEKEYFILE]
certFile [SSLCERTIFICATEFILE]
}
# Virtualhost start - do not remove this line
virtualHost csfssl.[SERVERNAME] {
vhRoot [DIRECTORY]
allowSymbolLink 1
enableScript 1
restrained 1
docRoot [DOCUMENTROOT]
vhDomain [SERVERNAME]
vhAliases [SERVERALIAS]
vhssl {
keyFile [SSLCERTIFICATEKEYFILE]
certFile [SSLCERTIFICATEFILE]
certChain 1
sslProtocol 24
ciphers EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH:ECDHE-RSA-AES128-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA128:DHE-RSA-AES128-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-GCM-SHA128:ECDHE-RSA-AES128-SHA384:ECDHE-RSA-AES128-SHA128:ECDHE-RSA-AES128-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-SHA128:DHE-RSA-AES128-SHA128:DHE-RSA-AES128-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA384:AES128-GCM-SHA128:AES128-SHA128:AES128-SHA128:AES128-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4
enableECDHE 1
renegProtection 1
sslSessionCache 1
enableSpdy 15
enableStapling 1
ocspRespMaxAge 86400
}
}
# Virtualhost end - do not remove this line