以下是優化Apache SSL性能的關鍵配置:
SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1 # 僅保留TLS 1.3/1.2
SSLSessionCache shmcb:/path/to/ssl_scache(512000) # 緩存大?。▎挝唬鹤止潱?SSLSessionCacheTimeout 300 # 緩存超時時間(秒)
SSLUseStapling on
SSLStaplingCache "shmcb:/var/run/ocsp-stapling-cache(128000)" # 緩存大小
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
SSLCipherSuite HIGH:!aNULL:!MD5 # 禁用弱密碼套件
KeepAlive On
MaxKeepAliveRequests 100
KeepAliveTimeout 5 # 適當縮短超時時間
# 部分場景需安裝特定模塊或硬件驅動,具體需參考服務器文檔
<IfModule mpm_prefork_module>
ServerLimit 256
ThreadsPerChild 256
</IfModule> # 示例配置,需根據實際負載調整
注意事項: