]> git.openstreetmap.org Git - chef.git/blobdiff - cookbooks/chef/templates/default/apache.erb
community: Enable new IPv6 template
[chef.git] / cookbooks / chef / templates / default / apache.erb
index fed8d3a2d42fe18134e8375046065c317a85b3cf..9d86d910e7c858b4ccdfdd3b9e71391e8c8a7705 100644 (file)
@@ -8,6 +8,7 @@
        CustomLog /var/log/apache2/chef.openstreetmap.org-access.log combined
        ErrorLog /var/log/apache2/chef.openstreetmap.org-error.log
 
        CustomLog /var/log/apache2/chef.openstreetmap.org-access.log combined
        ErrorLog /var/log/apache2/chef.openstreetmap.org-error.log
 
+       RedirectPermanent /.well-known/acme-challenge/ http://acme.openstreetmap.org/.well-known/acme-challenge/
        Redirect permanent / https://chef.openstreetmap.org/
 </VirtualHost>
 
        Redirect permanent / https://chef.openstreetmap.org/
 </VirtualHost>
 
        ServerName chef.openstreetmap.org
        ServerAdmin webmaster@openstreetmap.org
 
        ServerName chef.openstreetmap.org
        ServerAdmin webmaster@openstreetmap.org
 
-       SSLEngine on
-       SSLProtocol all -SSLv2
-       SSLCipherSuite ALL:!ADH:!EXPORT:!SSLv2:RC4+RSA:+HIGH:+MEDIUM:+LOW
-       SSLCertificateFile /etc/ssl/certs/openstreetmap.pem
-       SSLCertificateKeyFile /etc/ssl/private/openstreetmap.key
-
        CustomLog /var/log/apache2/chef.openstreetmap.org-access.log combined
        ErrorLog /var/log/apache2/chef.openstreetmap.org-error.log
 
        CustomLog /var/log/apache2/chef.openstreetmap.org-access.log combined
        ErrorLog /var/log/apache2/chef.openstreetmap.org-error.log
 
+       SSLEngine on
        SSLProxyEngine on
        SSLProxyEngine on
+       SSLCertificateFile /etc/ssl/certs/chef.openstreetmap.org.pem
+       SSLCertificateKeyFile /etc/ssl/private/chef.openstreetmap.org.key
 
 
-       ProxyPass / http://127.0.0.1:4000/
+       ProxyPassMatch ^/.*\.git/ !
+       ProxyPass / https://<%= node[:fqdn] %>:4443/
+       ProxyPreserveHost on
 </VirtualHost>
 </VirtualHost>