#ssl_verify_client: require
ssl_crl: '/etc/pki/tls/certs/odt-cacrl.pem'
ssl_ca: '/etc/pki/tls/certs/odt-root-ca.pem'
- custom_fragment_ssl: 'SSLRequire %%{ich-trickse}{SSL_CLIENT_S_DN_O} eq "ODT"'
+ custom_fragment_ssl: 'SSLRequire %%{ich-trickse}{SSL_CLIENT_I_DN_O} eq "ODT"'
rewrites_non_ssl:
- https:
comment: 'almost all to https'
provider: location
path: '/'
custom_fragment: |
- SSLRequire %%{ich-trickse}{SSL_CLIENT_S_DN_O} eq "ODT"
+ SSLRequire %%{ich-trickse}{SSL_CLIENT_I_DN_O} eq "ODT"
SSLVerifyClient require
- webservice:
provider: location