split unfold and unfold-ssl so we can enable only the non-SSL stuff; the SSL service...
[myslice.git] / apache / unfold.conf
index ff3de7f..357db7e 100644 (file)
@@ -1,3 +1,5 @@
+# see also unfold-ssl.conf
+
 <VirtualHost *:80>
        WSGIDaemonProcess unfold processes=2 threads=25
        WSGIProcessGroup  unfold
         Allow from all
         </Directory>
 </VirtualHost>
-
-# This port (not necessarily well picked) is configured 
-# with client-certificate required
-# corresponding trusted roots (e.g. ple.gid and plc.gid) should be 
-# configured in /etc/unfold/trusted_roots
-# check Jordan's email and pointer to trac, although we do not want 
-# this to be optional on that port
-
-<VirtualHost *:443>
-       WSGIDaemonProcess unfold-ssl processes=2 threads=25
-       WSGIProcessGroup  unfold-ssl
-       CustomLog ${APACHE_LOG_DIR}/myslice-ssl-access.log common
-       ErrorLog ${APACHE_LOG_DIR}/myslice-ssl-error.log
-        WSGIScriptAlias / /usr/share/unfold/apache/unfold.wsgi
-        <Directory /usr/share/unfold/apache/>
-        <Files unfold.wsgi>
-        Order deny,allow
-        Allow from all
-        </Files>
-        </Directory>
-        Alias /static/ /usr/share/unfold/static/
-        <Directory /usr/share/unfold/static>
-        Order deny,allow
-        Allow from all
-        </Directory>
-
-       SSLEngine on
-       SSLVerifyClient require
-       SSLVerifyDepth 5
-# make this a symlink to /etc/sfa/trusted_roots if that makes sense in your env.
-       SSLCACertificatePath /etc/unfold/trusted_roots
-# see init-ssl.sh for how to create self-signed stuff in here
-       SSLCertificateFile    /etc/unfold/myslice.cert
-       SSLCertificateKeyFile /etc/unfold/myslice.key
-
-#      SSLOptions +StdEnvVars +ExportCertData
-       SSLOptions +StdEnvVars
-</VirtualHost>