9991ea
From 8e8a020f8d2476cca321349fa24db4bee95270d8 Mon Sep 17 00:00:00 2001
9991ea
From: Martin Kosek <mkosek@redhat.com>
9991ea
Date: Thu, 20 Mar 2014 09:34:53 +0100
9991ea
Subject: [PATCH] Proxy PKI clone /ca/ee/ca/profileSubmit URI
9991ea
9991ea
PKI change done in ticket https://fedorahosted.org/pki/ticket/816
9991ea
requires the PKI Clone's SSL Server certificate to be issued by
9991ea
it's associated PKI master.
9991ea
9991ea
Allow this call on IPA master.
9991ea
9991ea
https://fedorahosted.org/freeipa/ticket/4265
9991ea
9991ea
Reviewed-By: Jan Cholasta <jcholast@redhat.com>
9991ea
---
9991ea
 install/conf/ipa-pki-proxy.conf | 4 ++--
9991ea
 1 file changed, 2 insertions(+), 2 deletions(-)
9991ea
9991ea
diff --git a/install/conf/ipa-pki-proxy.conf b/install/conf/ipa-pki-proxy.conf
9991ea
index 6f0463242b75a58cf63a38e62c23fa372aeacf64..224cdd45b5b5f72671a179570fd15772fe8cfaab 100644
9991ea
--- a/install/conf/ipa-pki-proxy.conf
9991ea
+++ b/install/conf/ipa-pki-proxy.conf
9991ea
@@ -1,9 +1,9 @@
9991ea
-# VERSION 3 - DO NOT REMOVE THIS LINE
9991ea
+# VERSION 4 - DO NOT REMOVE THIS LINE
9991ea
 
9991ea
 ProxyRequests Off
9991ea
 
9991ea
 # matches for ee port
9991ea
-<LocationMatch "^/ca/ee/ca/checkRequest|^/ca/ee/ca/getCertChain|^/ca/ee/ca/getTokenInfo|^/ca/ee/ca/tokenAuthenticate|^/ca/ocsp|^/ca/ee/ca/updateNumberRange|^/ca/ee/ca/getCRL">
9991ea
+<LocationMatch "^/ca/ee/ca/checkRequest|^/ca/ee/ca/getCertChain|^/ca/ee/ca/getTokenInfo|^/ca/ee/ca/tokenAuthenticate|^/ca/ocsp|^/ca/ee/ca/updateNumberRange|^/ca/ee/ca/getCRL|^/ca/ee/ca/profileSubmit">
9991ea
     NSSOptions +StdEnvVars +ExportCertData +StrictRequire +OptRenegotiate
9991ea
     NSSVerifyClient none
9991ea
     ProxyPassMatch ajp://localhost:$DOGTAG_PORT
9991ea
-- 
9991ea
1.8.5.3
9991ea