Gentoo Logo
Gentoo Spaceship




Note: Due to technical difficulties, the Archives are currently not up to date. GMANE provides an alternative service for most mailing lists.
c.f. bug 424647
List Archive: gentoo-user
Navigation:
Lists: gentoo-user: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-user@g.o
From: Tanstaafl <tanstaafl@...>
Subject: Re: Restrict site access by SSL Client Cert?
Date: Wed, 15 Feb 2012 11:24:52 -0500
On 2012-02-15 10:46 AM, Paul Hartman <paul.hartman+gentoo@...> wrote:
> On Wed, Feb 15, 2012 at 8:46 AM, Tanstaafl<tanstaafl@...>  wrote:
>> Hi everyone,
>>
>> I know that you can restrict access to a certain site using either Basic
>> HTTP Auth or Digest Auth, but I was wondering - can you do the same with an
>> SSL Client Certificate?
>
> Yes, you can. The specifics of how depend on what web server you're using.
>
> For Apache, there are some examples of different scenarios here:
> https://httpd.apache.org/docs/2.0/ssl/ssl_howto.html#allclients
>
>> I'd also like to provide for IP based exceptions if possible
>
> Trivial in Apache using mod_authz_host which is made for that kind of
> thing. :)  You can combine the two access methods (allow all if it's
> coming from your company's internal IP, otherwise require
> certificate).

Perfect, thanks Paul (and yes this is with Apache)...

Glad to know I can do it, hopefully I can get it working without having 
to sign up to yet another email list to ask for help... ;)


References:
Restrict site access by SSL Client Cert?
-- Tanstaafl
Re: Restrict site access by SSL Client Cert?
-- Paul Hartman
Navigation:
Lists: gentoo-user: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: Restrict site access by SSL Client Cert?
Next by thread:
How do I deamonize every service?
Previous by date:
Re: Re: Switching to clocksource tsc: takes AGES on boot
Next by date:
Re: Re: grub vs grub 2


Updated May 04, 2012

Summary: Archive of the gentoo-user mailing list.

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.