# Test your apache configs:
/usr/local/apache/bin/apachectl configtest
# If it's fine, distill the config to make it permanent:
/usr/local/cpanel/bin/apache_conf_distiller --update --main
# /usr/local/cpanel/etc/stunnel/default/stunnel.conf
# Add this below the Authentication block:
options = NO_SSLv2
# Reload configurations
/usr/local/cpanel/startup
# You may get false positives about OpenSSL being out of date, specifically on
OS's that like to backport security fixes (Fedora/CentOS/RedHat); explaining
that to the vendor should be sufficient.
if the above apache compliance dont' work and you get an invalid cipher string try this
also if you don't want to show your php version in your server header. do this below
Let’s see how we can disable it. In order to prevent PHP from exposing the fact that it is installed on the server, by adding its signature to the web server header we need to locate in php.ini the variable expose_php and turn it off.
By default expose_php is set to On.
In your php.ini (based on your Linux distribution this can be found in various places, like /etc/php.ini, /etc/php5/apache2/php.ini, etc.) locate the line containing “expose_php On” and set it to Off:
expose_php = Off
After making this change PHP will no longer add it’s signature to the web server header. Doing this, will not make your server more secure… it will just prevent remote hosts to easily see that you have PHP installed on the system and what version you are running.