X-Git-Url: http://git.onelab.eu/?p=myslice.git;a=blobdiff_plain;f=apache%2Fmyslice.conf;fp=apache%2Fmyslice.conf;h=b36a75ecd8ba91c327bde726dc81ceccdbe42a1b;hp=b78245200dc236c6c533bf95d570e611d62ff724;hb=e6184193b74ac6d5c52289546dae9121bdd99008;hpb=3167207804460a2c42e1e5a8346c597f9832d295 diff --git a/apache/myslice.conf b/apache/myslice.conf index b7824520..b36a75ec 100644 --- a/apache/myslice.conf +++ b/apache/myslice.conf @@ -12,3 +12,37 @@ Allow from all + +# This port (not necessarily well picked) is configured +# with client-certificate required +# corresponding trusted roots (e.g. ple.gid and plc.gid) should be +# configured in /etc/unfold/trusted_roots +# check Jordan's email and pointer to trac, although we do not want +# this to be optional on that port + + + WSGIScriptAlias / /usr/share/unfold/myslice/wsgi.py + + + Order deny,allow + Allow from all + + + Alias /static/ /usr/share/unfold/static/ + + Order deny,allow + Allow from all + + + SSLEngine on + SSLVerifyClient require + SSLVerifyDepth 5 +# make this a symlink to /etc/sfa/trusted_roots if that makes sense in your env. + SSLCACertificatePath /etc/unfold/trusted_roots +# see init-ssl.sh for how to create self-signed stuff in here + SSLCertificateFile /etc/unfold/myslice.cert + SSLCertificateKeyFile /etc/unfold/myslice.key + +# SSLOptions +StdEnvVars +ExportCertData + SSLOptions +StdEnvVars +