It is recommended to explicitly list all ciphers supported by Apache on port 443, to ensure security by default and avoid insecure defaults/fallbacks. For reference regarding the latest best practices, please refer to [BCP-195](https://www.rfc-editor.org/bcp/bcp195.txt) and [Qualys' SSL/TLS Deployment Best Practices](https://www.ssllabs.com/downloads/SSL_TLS_Deployment_Best_Practices.pdf) or [here](https://www.ssllabs.com/projects/documentation/index.html).