In the httpd.conf:
Header settings
Header always append X-Frame-Options SAMEORIGIN
Header always set X-Content-Type-Options nosniff
Header always set Referrer-Policy “same-origin”
Header always set X-Permitted-Cross-Domain-Policies: none
In vhssl.conf
Header always set Strict-Transport-Security “max-age=63072000; includeSubDomains”
In config.php:
<?php
$CONFIG = array (
'passwordsalt' => 'BcOq8l1lKcKYUrnXCBFoGeD7dQDUXP',
'secret' => 'jzOirLK3QSoyReT3iSK9g1WsZxANeX14FfnqZnmrZnTnLrqx',
'trusted_domains' =>
array (
0 => 'localhost',
1 => 'cloud.robkalmeijer.nl',
2 => '192.168.1.15',
3 => '[2a02:a465:54ef:1::1:5]',
),
'datadirectory' => '/srv/www/vhosts/cloud.robkalmeijer.nl/httpsdocs/data',
'dbtype' => 'mysql',
'version' => '30.0.2.2',
'overwrite.cli.url' => 'http://localhost',
'dbname' => 'nextcloud',
'dbhost' => 'localhost',
'dbport' => '',
'dbtableprefix' => 'oc_',
'mysql.utf8mb4' => true,
'dbuser' => 'nextcloud',
'dbpassword' => 'Nextcloud1',
'default_timezone' => 'Europe/Amsterdam',
'installed' => true,
'instanceid' => 'oclltontihs4',
'theme' => '',
'skeletondirectory' => '/srv/www/vhosts/cloud.robkalmeijer.nl/httpsdocs/core/skeleton',
'logfile' => '/var/log/nextcloud.log',
'loglevel' => 2,
'logfilemode' => 416,
'log_rotate_size' => 0,
'logo_url' => 'https://cloud.robkalmeijer.nl/',
'maintenance' => false,
'mail_from_address' => 'nextcloud',
'mail_smtpmode' => 'smtp',
'mail_sendmailmode' => 'smtp',
'mail_domain' => 'robkalmeijer.nl',
'mail_smtphost' => '127.0.0.1',
'mail_smtpport' => 25,
'mail_smtpsecure' => '',
'mail_send_plaintext_only' => false,
'default_phone_region' => 'NL',
'maintenance_window_start' => 1,
'memcache.local' => '\\OC\\Memcache\\APCu',
'memcache.locking' => '\\OC\\Memcache\\Redis',
'redis' =>
array (
'host' => '/run/redis/redis.sock',
'port' => 0,
'timeout' => 0.0,
),
'redis_log_file' => '/var/log/redis/redis_nextcloud.log',
);
See also:
[Httpserver](https://www.robkalmeijer.nl/techniek/computer/servers/http/index.html)