X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=apache%2Fmyslice.conf;h=b36a75ecd8ba91c327bde726dc81ceccdbe42a1b;hb=83f238a32f62a34370f24d69e85823c709d95627;hp=4331bcc5514ac91a17a3069efe04b8bb358c769f;hpb=bc52c646eaf241e974004f88c63e164e8d33508c;p=unfold.git diff --git a/apache/myslice.conf b/apache/myslice.conf index 4331bcc5..b36a75ec 100644 --- a/apache/myslice.conf +++ b/apache/myslice.conf @@ -1,6 +1,6 @@ WSGIScriptAlias / /usr/share/unfold/myslice/wsgi.py - + Order deny,allow Allow from all @@ -12,3 +12,37 @@ Allow from all + +# This port (not necessarily well picked) is configured +# with client-certificate required +# corresponding trusted roots (e.g. ple.gid and plc.gid) should be +# configured in /etc/unfold/trusted_roots +# check Jordan's email and pointer to trac, although we do not want +# this to be optional on that port + + + WSGIScriptAlias / /usr/share/unfold/myslice/wsgi.py + + + Order deny,allow + Allow from all + + + Alias /static/ /usr/share/unfold/static/ + + Order deny,allow + Allow from all + + + SSLEngine on + SSLVerifyClient require + SSLVerifyDepth 5 +# make this a symlink to /etc/sfa/trusted_roots if that makes sense in your env. + SSLCACertificatePath /etc/unfold/trusted_roots +# see init-ssl.sh for how to create self-signed stuff in here + SSLCertificateFile /etc/unfold/myslice.cert + SSLCertificateKeyFile /etc/unfold/myslice.key + +# SSLOptions +StdEnvVars +ExportCertData + SSLOptions +StdEnvVars +