summaryrefslogtreecommitdiffstats
path: root/install/conf
diff options
context:
space:
mode:
authorMartin Kosek <mkosek@redhat.com>2013-05-06 09:22:27 +0200
committerMartin Kosek <mkosek@redhat.com>2013-05-06 13:33:52 +0200
commit77e4f445cce087a915533ad3ae2e35e93db762c5 (patch)
tree8a82db7a7961dff5fcad1a19a34ae54253733f29 /install/conf
parent6e2c3a45a1da4b2b39037bf7ed3a0d3fcd42b008 (diff)
downloadfreeipa-77e4f445cce087a915533ad3ae2e35e93db762c5.tar.gz
freeipa-77e4f445cce087a915533ad3ae2e35e93db762c5.tar.xz
freeipa-77e4f445cce087a915533ad3ae2e35e93db762c5.zip
Update pki proxy configuration
Replicas with Dogtag pki-ca 10.0.2 CA require access to additional Dogtag REST API calls. Update pki proxy configuration to allow that. https://fedorahosted.org/freeipa/ticket/3601
Diffstat (limited to 'install/conf')
-rw-r--r--install/conf/ipa-pki-proxy.conf4
1 files changed, 2 insertions, 2 deletions
diff --git a/install/conf/ipa-pki-proxy.conf b/install/conf/ipa-pki-proxy.conf
index 8c4f3a9b6..6f0463242 100644
--- a/install/conf/ipa-pki-proxy.conf
+++ b/install/conf/ipa-pki-proxy.conf
@@ -1,4 +1,4 @@
-# VERSION 2 - DO NOT REMOVE THIS LINE
+# VERSION 3 - DO NOT REMOVE THIS LINE
ProxyRequests Off
@@ -11,7 +11,7 @@ ProxyRequests Off
</LocationMatch>
# matches for admin port and installer
-<LocationMatch "^/ca/admin/ca/getCertChain|^/ca/admin/ca/getConfigEntries|^/ca/admin/ca/getCookie|^/ca/admin/ca/getStatus|^/ca/admin/ca/securityDomainLogin|^/ca/admin/ca/getDomainXML|^/ca/rest/installer/installToken">
+<LocationMatch "^/ca/admin/ca/getCertChain|^/ca/admin/ca/getConfigEntries|^/ca/admin/ca/getCookie|^/ca/admin/ca/getStatus|^/ca/admin/ca/securityDomainLogin|^/ca/admin/ca/getDomainXML|^/ca/rest/installer/installToken|^/ca/admin/ca/updateNumberRange|^/ca/rest/securityDomain/domainInfo|^/ca/rest/account/login|^/ca/admin/ca/tokenAuthenticate|^/ca/admin/ca/updateNumberRange|^/ca/admin/ca/updateDomainXML|^/ca/rest/account/logout|^/ca/rest/securityDomain/installToken">
NSSOptions +StdEnvVars +ExportCertData +StrictRequire +OptRenegotiate
NSSVerifyClient none
ProxyPassMatch ajp://localhost:$DOGTAG_PORT