diff --git a/tasks/main.yml b/tasks/main.yml index eaa785373323e680e1a73f0645e06cc57fe8e021..672c0e3b55329c8f4e5e5324a63c7571c6c2ddf3 100644 --- a/tasks/main.yml +++ b/tasks/main.yml @@ -12,14 +12,6 @@ path: '/etc/letsencrypt' state: 'directory' - - name: "Write SSL Apache Options" - template: - src: 'options-ssl-apache.conf' - dest: '/etc/letsencrypt/options-ssl-apache.conf' - owner: 'root' - group: 'root' - mode: '644' - - name: "Check Existing Certs" stat: path: '/etc/letsencrypt/live' diff --git a/templates/options-ssl-apache.conf b/templates/options-ssl-apache.conf deleted file mode 100644 index 187effd86b0d5200552d8575669d7784d4e35b1d..0000000000000000000000000000000000000000 --- a/templates/options-ssl-apache.conf +++ /dev/null @@ -1,15 +0,0 @@ -# Baseline setting to Include for SSL sites - -SSLEngine on - -# Intermediate configuration, tweak to your needs -SSLProtocol all -SSLv2 -SSLv3 -SSLCipherSuite ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA -SSLHonorCipherOrder on -SSLCompression off - -SSLOptions +StrictRequire - -# Add vhost name to log entries: -LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-agent}i\"" vhost_combined -LogFormat "%v %h %l %u %t \"%r\" %>s %b" vhost_common