<IfModule ssl_module>
	SSLEngine	on

<IfModule log_config_module>
	LogFormat	ssl
</IfModule>

	# https://bettercrypto.org/static/applied-crypto-hardening.pdf
	SSLHonorCipherOrder	on
	# The default allows for IE8/XP and Java7 but also get's Grade A
	# in SSL Labs - so for now, we avoid the bettercrypto.org setting...
	#SSLCipherSuite		EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA
	# https://blog.qualys.com/ssllabs/2013/08/05/configuring-apache-nginx-and-openssl-for-forward-secrecy
	#SSLCipherSuite "EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EECDH+ECDSA+SHA256 EECDH+aRSA+SHA384 EECDH+aRSA+SHA256 EECDH+aRSA+RC4 EECDH EDH+aRSA RC4 !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS !RC4"

	<Location /cgi-bin/>
		SSLOptions	+StdEnvVars
	</Location>
	<Files ~ "\.(cgi|shtml|phtml|php)$">
		SSLOptions	+StdEnvVars
	</Files>

<IfModule setenvif_module>
	BrowserMatch	".*MSIE.*"	nokeepalive ssl-unclean-shutdown downgrade-1.0 force-response-1.0
</IfModule>

	# https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy#report-to
	Header	set	Reporting-Endpoints			"csp-report=\"/global-cgi-bin/csp-report\""
	#Header	set	Content-Security-Policy-Report-Only	"default-src https: data: wss: 'unsafe-inline' 'unsafe-eval'; form-action https:; report-uri /global-cgi-bin/csp-report"
	Header	setifempty	Content-Security-Policy	"frame-ancestors 'self' https://*.kit.edu; report-uri /global-cgi-bin/csp-report; report-to csp-report"
</IfModule>

# If ANY VHost loads mod_shib, this changes valid-user to shib-session unless we restore compatibility
<IfModule mod_shib>
ShibCompatValidUser	On
</IfModule>
