X-Git-Url: https://dehnerts.com/gitweb/?a=blobdiff_plain;f=sites-available%2Fmit-proxy.conf;h=088d5d3f04eba30d458969d4aeb8ccd337d94a4a;hb=3be7dceb6a9812dcd7e8c633b9da6e4ec17b49fa;hp=b3d06f6e24c184f617e01894426f40001cddd1cb;hpb=9aa0f02267fd65d712ba8b7bbfafd600a1ba68af;p=sysconfig%2Fapache2.git diff --git a/sites-available/mit-proxy.conf b/sites-available/mit-proxy.conf index b3d06f6..088d5d3 100644 --- a/sites-available/mit-proxy.conf +++ b/sites-available/mit-proxy.conf @@ -6,8 +6,8 @@ # # ServerName squaresdb.dehnerts.com -# ProxyPass "/" "http://squaresdb.lushan-vms.dehnerts.com/" -# ProxyPassReverse "/" "http://squaresdb.lushan-vms.dehnerts.com/" +# ProxyPass "/" "http://squaresdb.augsburg.vms.dehnerts.com/" +# ProxyPassReverse "/" "http://squaresdb.augsburg.vms.dehnerts.com/" # @@ -17,11 +17,9 @@ SSLProxyVerify require SSLProxyVerifyDepth 2 SSLProxyCACertificatePath /etc/ssl/certs - # Really I want to validate that the name matches squaresdb.dehnerts.com, - # but apparently that's not a thing, AFAICT. - SSLProxyCheckPeerName off - ProxyPass "/" "https://squaresdb.lushan-vms.dehnerts.com/" - ProxyPassReverse "/" "https://squaresdb.lushan-vms.dehnerts.com/" + SSLProxyCheckPeerName on + ProxyPass "/" "https://squaresdb.augsburg.vms.dehnerts.com/" + ProxyPassReverse "/" "https://squaresdb.augsburg.vms.dehnerts.com/" ProxyPreserveHost on Include sites-common/ssl-common SSLCertificateFile /etc/letsencrypt/live/squaresdb.dehnerts.com/fullchain.pem @@ -29,3 +27,34 @@ SSLCertificateKeyFile /etc/letsencrypt/live/squaresdb.dehnerts.com/privkey.pem + + + ServerName zulip.dehnerts.com + ServerAlias *.zulip.dehnerts.com + ProxyPassReverse "/" "http://zulip.augsburg.vms.dehnerts.com/" + ProxyPreserveHost on + + DocumentRoot /var/www/letsencrypt-verify/ + RewriteEngine on + RewriteCond /var/www/letsencrypt-verify/%{REQUEST_URI} !-f + RewriteRule ^/.well-known/acme-challenge/(.*)$ http://zulip.augsburg.vms.dehnerts.com/.well-known/acme-challenge/$1 [P,QSA,L] + + +# +# +# ServerName zulip.dehnerts.com +# ServerAlias *.zulip.dehnerts.com +# SSLProxyEngine on +# SSLProxyVerify require +# SSLProxyVerifyDepth 2 +# SSLProxyCACertificatePath /etc/ssl/certs +# SSLProxyCheckPeerName on +# ProxyPass "/" "https://zulip.augsburg.vms.dehnerts.com/" +# ProxyPassReverse "/" "https://zulip.augsburg.vms.dehnerts.com/" +# ProxyPreserveHost on +# Include sites-common/ssl-common +# SSLCertificateFile /etc/letsencrypt/live/zulip.dehnerts.com/fullchain.pem +# SSLCertificateChainFile /etc/letsencrypt/live/zulip.dehnerts.com/fullchain.pem +# SSLCertificateKeyFile /etc/letsencrypt/live/zulip.dehnerts.com/privkey.pem +# +#