X-Git-Url: http://git.rot13.org/?p=via-proxy;a=blobdiff_plain;f=ssl.conf;h=9f4328fc5f13b7161b73f68069025b327334ef78;hp=a37752ea9b6e7d56886eaf91e4de0dc0cc8cdfe1;hb=289e941c2e0ca1ea0b7bcdc378c7c946a94138ea;hpb=391259b321850a0a87c29b09c9c3b718ab5fa796 diff --git a/ssl.conf b/ssl.conf index a37752e..9f4328f 100644 --- a/ssl.conf +++ b/ssl.conf @@ -3,3 +3,25 @@ SSLCertificateFile /etc/letsencrypt/live/proxy.knjiznice.ffzg.hr/cert.pem SSLCertificateKeyFile /etc/letsencrypt/live/proxy.knjiznice.ffzg.hr/privkey.pem SSLCertificateChainFile /etc/letsencrypt/live/proxy.knjiznice.ffzg.hr/chain.pem + + + + Order deny,allow + # allow local subnets + Allow from 193.198.212 193.198.213 193.198.214 193.198.215 + deny from all + # file is htpasswd as first try and ldap as second + AuthBasicProvider file ldap + AuthType basic + AuthUserFile /data/proxy/.htpasswd + AuthName "[ UPUTA: za pristup se koristi AAI korisnicki racun dobiven na FFZG. ]" + + AuthLDAPURL "ldaps://ldap.ffzg.hr/dc=ffzg,dc=hr?hrEduPersonUniqueID?" + + Require valid-user + satisfy any + + + +# don't pass through authorization header! +RequestHeader unset Authorization