]> Frank Brehm's Git Trees - pixelpark/hiera.git/commitdiff
ODT - fix client certs
authorOliver Böttcher <oliver.boettcher@pixelpark.com>
Mon, 10 Jul 2017 10:29:28 +0000 (12:29 +0200)
committerOliver Böttcher <oliver.boettcher@pixelpark.com>
Mon, 10 Jul 2017 10:29:28 +0000 (12:29 +0200)
customer/mbvd-odt/int-odt-daimler-com.pixelpark.net.yaml

index c82205be1bca4be381d607daaa0e3a604118ebd3..dcc69aeda2fb7843bdadda218ad278484c6b4961 100644 (file)
@@ -25,6 +25,7 @@ infra::profile::apache::pp_vhosts:
     ssl_verify_client: require
     ssl_crl: '/etc/pki/tls/certs/odt-cacrl.pem'
     ssl_ca: '/etc/pki/tls/certs/odt-root-ca.pem'
+    custom_fragment: 'SSLRequire %%{ich-trickse}{SSL_CLIENT_S_DN_O} eq "ODT"'
     rewrites_non_ssl:
       - https:
         comment: 'almost all to https'