From b9a3ef486ebcde18a5ade37865ff8f397185d24f Mon Sep 17 00:00:00 2001
From: Till Brehm <tbrehm@ispconfig.org>
Date: Sun, 24 Jul 2016 05:30:59 -0400
Subject: [PATCH] Fixed #3979 Mailbox users unable to save autoresponders

---
 install/tpl/apache_ispconfig.vhost.master |  145 ++++++++++++++++++++++++++++++++++-------------
 1 files changed, 104 insertions(+), 41 deletions(-)

diff --git a/install/tpl/apache_ispconfig.vhost.master b/install/tpl/apache_ispconfig.vhost.master
index 0e646fd..8aa41fa 100644
--- a/install/tpl/apache_ispconfig.vhost.master
+++ b/install/tpl/apache_ispconfig.vhost.master
@@ -1,56 +1,119 @@
-
 ######################################################
 # This virtual host contains the configuration
 # for the ISPConfig controlpanel
 ######################################################
 
-Listen {vhost_port}
-NameVirtualHost *:{vhost_port}
+<tmpl_var name="vhost_port_listen"> Listen <tmpl_var name="vhost_port">
+NameVirtualHost *:<tmpl_var name="vhost_port">
 
-<VirtualHost _default_:{vhost_port}>
-	ServerAdmin webmaster@localhost
+<VirtualHost _default_:<tmpl_var name="vhost_port">>
+  ServerAdmin webmaster@localhost
+
+  <FilesMatch "\.ph(p3?|tml)$">
+    SetHandler None
+  </FilesMatch>
+
+  <IfModule mod_fcgid.c>
+    DocumentRoot /var/www/ispconfig/
+    SuexecUserGroup ispconfig ispconfig
+    <Directory /var/www/ispconfig/>
+      Options -Indexes +FollowSymLinks +MultiViews +ExecCGI
+      AllowOverride AuthConfig Indexes Limit Options FileInfo
+      <FilesMatch "\.php$">
+        SetHandler fcgid-script
+      </FilesMatch>
+      FCGIWrapper /var/www/php-fcgi-scripts/ispconfig/.php-fcgi-starter .php
+      <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
+      Require all granted
+      <tmpl_else>
+      Order allow,deny
+      Allow from all
+      </tmpl_if>
+    </Directory>
+    IPCCommTimeout  7200
+    MaxRequestLen 15728640
+  </IfModule>
+
+  <IfModule mpm_itk_module>
     DocumentRoot /usr/local/ispconfig/interface/web/
-	
-	<IfModule mod_fastcgi.c>
-		<Location /php/php-fcgi>
-                	Options ExecCGI        
-                	SetHandler fastcgi-script
-       		</Location>
+    AssignUserId ispconfig ispconfig
+    AddType application/x-httpd-php .php
+    <Directory /usr/local/ispconfig/interface/web>
+      # php_admin_value open_basedir "/usr/local/ispconfig/interface:/usr/share:/tmp"
+      Options +FollowSymLinks
+      AllowOverride None
+      <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
+      Require all granted
+      <tmpl_else>
+      Order allow,deny
+      Allow from all
+      </tmpl_if>
+      php_value magic_quotes_gpc        0
+    </Directory>
+  </IfModule>
 
-        	Action php-fastcgi /php/php-fcgi
+  # ErrorLog /var/log/apache2/error.log
+  # CustomLog /var/log/apache2/access.log combined
+  ServerSignature Off
 
-		ScriptAlias /php/ /usr/local/ispconfig/interface/bin/
+  <IfModule mod_security2.c>
+    SecRuleEngine Off
+  </IfModule>
 
-		<Directory "/usr/local/ispconfig/interface/bin/">
-                        AllowOverride None
-                        Options +ExecCGI -MultiViews -Indexes
-                        Order allow,deny
-                        Allow from all                              
-        	</Directory>
-	</IfModule>
+  # SSL Configuration
+  <tmpl_var name="ssl_comment">SSLEngine On
+  <tmpl_if name='apache_version' op='>=' value='2.3.16' format='version'>
+  <tmpl_var name="ssl_comment">SSLProtocol All -SSLv3
+  <tmpl_else>
+  <tmpl_var name="ssl_comment">SSLProtocol All -SSLv2 -SSLv3
+  </tmpl_if>
+  <tmpl_var name="ssl_comment">SSLCertificateFile /usr/local/ispconfig/interface/ssl/ispserver.crt
+  <tmpl_var name="ssl_comment">SSLCertificateKeyFile /usr/local/ispconfig/interface/ssl/ispserver.key
+  <tmpl_var name="ssl_bundle_comment">SSLCACertificateFile /usr/local/ispconfig/interface/ssl/ispserver.bundle
 
-	<IfModule mod_php5.c>
-  		AddType application/x-httpd-php .php
-	</IfModule>
-	
-	<Directory /usr/local/ispconfig/interface/web/>
-		Options FollowSymLinks
-		AllowOverride None
-		Order allow,deny
-		Allow from all
-	</Directory>
-	
-	# ErrorLog /var/log/apache2/error.log
-	# CustomLog /var/log/apache2/access.log combined
-    ServerSignature Off
-	
+  <tmpl_var name="ssl_comment">SSLCipherSuite ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS
+  <tmpl_var name="ssl_comment">SSLHonorCipherOrder On
+  <tmpl_if name='apache_version' op='>=' value='2.4.3' format='version'>
+  <tmpl_var name="ssl_comment">SSLCompression Off
+  </tmpl_if>
+  <tmpl_if name='apache_version' op='>=' value='2.4.11' format='version'>
+  <tmpl_var name="ssl_comment">SSLSessionTickets Off
+  </tmpl_if>
+
+  <IfModule mod_headers.c>
+    Header always add Strict-Transport-Security "max-age=15768000"
+	RequestHeader unset Proxy early
+  </IfModule>
+
+  <tmpl_if name='apache_version' op='>=' value='2.3.3' format='version'>
+  <tmpl_var name="ssl_comment">SSLUseStapling On
+  <tmpl_var name="ssl_comment">SSLStaplingResponderTimeout 5
+  <tmpl_var name="ssl_comment">SSLStaplingReturnResponderErrors Off
+  </tmpl_if>
 </VirtualHost>
 
-###########################################
-# Logfile configuration for vlogger
-###########################################
+<tmpl_if name='apache_version' op='>=' value='2.3.3' format='version'>
+<IfModule mod_ssl.c>
+  <tmpl_var name="ssl_comment">SSLStaplingCache shmcb:/var/run/ocsp(128000)
+</IfModule>
+</tmpl_if>
 
-LogFormat "%v %h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined_ispconfig
-CustomLog "| /usr/sbin/vlogger -s access.log /var/log/ispconfig/httpd" combined_ispconfig
+<Directory /var/www/php-cgi-scripts>
+  AllowOverride None
+  <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
+  Require all denied
+  <tmpl_else>
+  Order Deny,Allow
+  Deny from all
+  </tmpl_if>
+</Directory>
 
-
+<Directory /var/www/php-fcgi-scripts>
+  AllowOverride None
+  <tmpl_if name='apache_version' op='>' value='2.2' format='version'>
+  Require all denied
+  <tmpl_else>
+  Order Deny,Allow
+  Deny from all
+  </tmpl_if>
+</Directory>

--
Gitblit v1.9.1