在ApacheHTTPD2.4中禁用安全重新协商

在ApacheHTTPD2.4中禁用安全重新协商,apache,httpd.conf,Apache,Httpd.conf,据报道,我们的网站/域上通过ApacheHTTPD2.4代理托管 New, TLSv1.2, Cipher is ECDHE-RSA-AES128-GCM-SHA256 Server public key is 2048 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE No ALPN negotiated SSL-Session: Protocol : TLSv1.2 Cipher

据报道,我们的网站/域上通过ApacheHTTPD2.4代理托管

New, TLSv1.2, Cipher is ECDHE-RSA-AES128-GCM-SHA256
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    Protocol  : TLSv1.2
    Cipher    : ECDHE-RSA-AES128-GCM-SHA256
    Session-ID: D99A3E3FE44E02D6CFED853DDEF92E8ECAE7F2444D180887B6FCCDB843B0D2A6
    Session-ID-ctx:
    Master-Key: F3D1094E8EABE09492CF7FFDB79F2F566CA3F87473523164A62ECED7D4DA57B07B5317BC73DB12B8DFDACDE739758682
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    Start Time: 1597139113
    Timeout   : 7200 (sec)
    Verify return code: 20 (unable to get local issuer certificate)
    Extended master secret: no
---
R
RENEGOTIATING
并要求关闭相同的,不确定SSLinSecureReconnegotiation是否与安全重新协商相同,根据官方文件,SSLinSecureRecongotiation可以如下禁用。

但我们已经尝试过了,因为默认值是关闭的,所以应该首先禁用它。
有人能告诉我如何在ApacheHTTPD2.4、OpenSSL 1.0.1e-fips上禁用此功能吗?有一个选项可供选择

S开发+严格要求+标准车辆-OptRenegotiate


请参见

有一个选项

S开发+严格要求+标准车辆-OptRenegotiate