Advertisement
Guest User

Apache vhost for Puppet

a guest
Dec 6th, 2012
37
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.80 KB | None | 0 0
  1. # you probably want to tune these settings
  2. PassengerHighPerformance on
  3. PassengerMaxPoolSize 12
  4. PassengerPoolIdleTime 1500
  5. # PassengerMaxRequests 1000
  6. PassengerStatThrottleRate 120
  7. RackAutoDetect On
  8. RailsAutoDetect On
  9.  
  10. #Listen 80
  11. Listen 8000
  12.  
  13. <VirtualHost *:8000>
  14. ServerName puppetmaster
  15.  
  16. SSLEngine on
  17. SSLProtocol -ALL +SSLv3 +TLSv1
  18. SSLCipherSuite ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:-LOW:-SSLv2:-EXP
  19.  
  20. SSLCertificateFile /var/lib/puppet/ssl/certs/puppetmaster.pem
  21. SSLCertificateKeyFile /var/lib/puppet/ssl/private_keys/puppetmaster.pem
  22. SSLCertificateChainFile /var/lib/puppet/ssl/ca/ca_crt.pem
  23. SSLCACertificateFile /var/lib/puppet/ssl/ca/ca_crt.pem
  24. # If Apache complains about invalid signatures on the CRL, you can try disabling
  25. # CRL checking by commenting the next line, but this is not recommended.
  26. SSLCARevocationFile /var/lib/puppet/ssl/ca/ca_crl.pem
  27. SSLVerifyClient optional
  28. SSLVerifyDepth 1
  29. # The `ExportCertData` option is needed for agent certificate expiration warnings
  30. SSLOptions +StdEnvVars +ExportCertData
  31.  
  32. # This header needs to be set if using a loadbalancer or proxy
  33. RequestHeader unset X-Forwarded-For
  34.  
  35. RequestHeader set X-SSL-Subject %{SSL_CLIENT_S_DN}e
  36. RequestHeader set X-Client-DN %{SSL_CLIENT_S_DN}e
  37. RequestHeader set X-Client-Verify %{SSL_CLIENT_VERIFY}e
  38.  
  39. ErrorLog /var/log/apache2/perror
  40. LogLevel debug
  41.  
  42. DocumentRoot /etc/puppet/rack/public/
  43. RackBaseURI /
  44. <Directory /etc/puppet/rack/public/>
  45. Options None
  46. AllowOverride None
  47. Order allow,deny
  48. allow from all
  49. </Directory>
  50. </VirtualHost>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement