From: Dobrica Pavlinusic Date: Fri, 23 Mar 2018 16:52:09 +0000 (+0100) Subject: add htpasswd and ldap autorization X-Git-Url: http://git.rot13.org/?p=via-proxy;a=commitdiff_plain;h=c6ecedf943c1cc78b71ca2e2d5f799c0056fc10d;ds=sidebyside add htpasswd and ldap autorization --- diff --git a/ssl.conf b/ssl.conf index a37752e..9f4328f 100644 --- a/ssl.conf +++ b/ssl.conf @@ -3,3 +3,25 @@ SSLCertificateFile /etc/letsencrypt/live/proxy.knjiznice.ffzg.hr/cert.pem SSLCertificateKeyFile /etc/letsencrypt/live/proxy.knjiznice.ffzg.hr/privkey.pem SSLCertificateChainFile /etc/letsencrypt/live/proxy.knjiznice.ffzg.hr/chain.pem + + + + Order deny,allow + # allow local subnets + Allow from 193.198.212 193.198.213 193.198.214 193.198.215 + deny from all + # file is htpasswd as first try and ldap as second + AuthBasicProvider file ldap + AuthType basic + AuthUserFile /data/proxy/.htpasswd + AuthName "[ UPUTA: za pristup se koristi AAI korisnicki racun dobiven na FFZG. ]" + + AuthLDAPURL "ldaps://ldap.ffzg.hr/dc=ffzg,dc=hr?hrEduPersonUniqueID?" + + Require valid-user + satisfy any + + + +# don't pass through authorization header! +RequestHeader unset Authorization