X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=apache%2Fmyslice.conf;h=b36a75ecd8ba91c327bde726dc81ceccdbe42a1b;hb=dcd1b07f1d6a300dd561d67d70bdbec3e6fa801a;hp=a7f6f2cef3ea7b91a6e02793129839224f585c54;hpb=bb1f5f96f8a8a3eeb8585357a3a94c047c1c496b;p=unfold.git
diff --git a/apache/myslice.conf b/apache/myslice.conf
index a7f6f2ce..b36a75ec 100644
--- a/apache/myslice.conf
+++ b/apache/myslice.conf
@@ -1,6 +1,6 @@
- WSGIScriptAlias / /usr/share/unfold/apache/wsgi.py
-
+ WSGIScriptAlias / /usr/share/unfold/myslice/wsgi.py
+
Order deny,allow
Allow from all
@@ -12,3 +12,37 @@
Allow from all
+
+# This port (not necessarily well picked) is configured
+# with client-certificate required
+# corresponding trusted roots (e.g. ple.gid and plc.gid) should be
+# configured in /etc/unfold/trusted_roots
+# check Jordan's email and pointer to trac, although we do not want
+# this to be optional on that port
+
+
+ WSGIScriptAlias / /usr/share/unfold/myslice/wsgi.py
+
+
+ Order deny,allow
+ Allow from all
+
+
+ Alias /static/ /usr/share/unfold/static/
+
+ Order deny,allow
+ Allow from all
+
+
+ SSLEngine on
+ SSLVerifyClient require
+ SSLVerifyDepth 5
+# make this a symlink to /etc/sfa/trusted_roots if that makes sense in your env.
+ SSLCACertificatePath /etc/unfold/trusted_roots
+# see init-ssl.sh for how to create self-signed stuff in here
+ SSLCertificateFile /etc/unfold/myslice.cert
+ SSLCertificateKeyFile /etc/unfold/myslice.key
+
+# SSLOptions +StdEnvVars +ExportCertData
+ SSLOptions +StdEnvVars
+