Revert "Enable OCSP stapling on jessie"
authorPeter Palfrader <peter@palfrader.org>
Tue, 2 Jun 2015 14:45:24 +0000 (16:45 +0200)
committerPeter Palfrader <peter@palfrader.org>
Tue, 2 Jun 2015 14:45:24 +0000 (16:45 +0200)
This reverts commit 6b5309cf417a7c629ae1a44c9420fe686804b626.

Apache fails with its mutexes all the time, disable OCSP stapling.

modules/apache2/templates/puppet-config.erb

index 5aa2c11..fca5a8b 100644 (file)
@@ -8,8 +8,5 @@
     SSLCipherSuite ECDH+AESGCM:ECDH+AES256:ECDH+AES128:ECDH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!eNULL:!LOW:!MD5:!EXP:!RC4:!SEED:!DSS
   <% else -%>
     SSLCipherSuite ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!eNULL:!LOW:!MD5:!EXP:!RC4:!SEED:!DSS
-
-    SSLUseStapling On
-    SSLStaplingCache shmcb:${APACHE_RUN_DIR}/ssl_stapling(32768)
   <% end -%>
 </IfModule>