Last active
August 11, 2020 13:10
-
-
Save hzburki/6646ea9a0e8788bc9be1ff74576127a6 to your computer and use it in GitHub Desktop.
File for Configuring SSL Certificate to Elastic Beanstalk - Single Instance
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Resources: | |
| sslSecurityGroupIngress: | |
| Type: AWS::EC2::SecurityGroupIngress | |
| Properties: | |
| GroupId: {"Fn::GetAtt" : ["AWSEBSecurityGroup", "GroupId"]} | |
| IpProtocol: tcp | |
| ToPort: 443 | |
| FromPort: 443 | |
| CidrIp: 0.0.0.0/0 | |
| packages: | |
| yum: | |
| mod24_ssl : [] | |
| files: | |
| /etc/httpd/conf.d/ssl.conf: | |
| mode: "000644" | |
| owner: root | |
| group: root | |
| content: | | |
| LoadModule ssl_module modules/mod_ssl.so | |
| Listen 443 | |
| <VirtualHost *:443> | |
| <Proxy *> | |
| Order deny,allow | |
| Allow from all | |
| </Proxy> | |
| SSLEngine on | |
| SSLCertificateFile "/etc/pki/tls/certs/server.crt" | |
| SSLCertificateChainFile "/etc/pki/tls/certs/chain.pem" | |
| SSLCertificateKeyFile "/etc/pki/tls/certs/server.key" | |
| SSLCipherSuite EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH | |
| SSLProtocol All -SSLv2 -SSLv3 | |
| SSLHonorCipherOrder On | |
| SSLSessionTickets Off | |
| Header always set Strict-Transport-Security "max-age=63072000; includeSubdomains; preload" | |
| Header always set X-Frame-Options DENY | |
| Header always set X-Content-Type-Options nosniff | |
| ProxyPass / http://localhost:80/ retry=0 | |
| ProxyPassReverse / http://localhost:80/ | |
| ProxyPreserveHost on | |
| RequestHeader set X-Forwarded-Proto "https" early | |
| </VirtualHost> | |
| /etc/pki/tls/certs/server.crt: | |
| mode: "000400" | |
| owner: root | |
| group: root | |
| source: 'https://s3-eu-west-1.amazonaws.com/numu.elasticbean/ssl/`{"Ref": "AWSEBEnvironmentName" }`.crt' | |
| authentication: S3Access | |
| /etc/pki/tls/certs/server.key: | |
| mode: "000400" | |
| owner: root | |
| group: root | |
| source: 'https://s3-eu-west-1.amazonaws.com/numu.elasticbean/ssl/`{"Ref": "AWSEBEnvironmentName" }`.key' | |
| authentication: S3Access | |
| /etc/pki/tls/certs/chain.pem: | |
| mode: "000400" | |
| owner: root | |
| group: root | |
| source: 'https://s3-eu-west-1.amazonaws.com/numu.elasticbean/ssl/`{"Ref": "AWSEBEnvironmentName" }`.pem' | |
| authentication: S3Access |
I am following your tutorial but unable to make it work that's why asking.
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Do I need to change anything on file? or paste it as is it?