IETF RFC 7568 Deprecates SSLv3 As Insecure

Security is hot-topic, so make sure your webserver/mail/sshd is configured with the strongest security levels available..


SSLProtocol All -SSLv2 -SSLv3
SSLHonorCipherOrder On
Header always set Strict-Transport-Security “max-age=63072000; includeSubdomains; preload”
Header always set X-Frame-Options DENY
Header always set X-Content-Type-Options nosniff
# Requires Apache >= 2.4
SSLCompression off
SSLSessionTickets Off
SSLUseStapling on
SSLStaplingCache “shmcb:logs/stapling-cache(150000)”

Continue reading IETF RFC 7568 Deprecates SSLv3 As Insecure