From: Oliver Böttcher <oliver.boettcher@pixelpark.com>
Date: Mon, 10 Jul 2017 10:29:28 +0000 (+0200)
Subject: ODT - fix client certs
X-Git-Tag: v0.1.0~2687^2~1
X-Git-Url: https://git.uhu-banane.net/?a=commitdiff_plain;h=902a34b685bc75426cc8563474520dde38ecb814;p=pixelpark%2Fhiera.git

ODT - fix client certs
---

diff --git a/customer/mbvd-odt/int-odt-daimler-com.pixelpark.net.yaml b/customer/mbvd-odt/int-odt-daimler-com.pixelpark.net.yaml
index c82205be..dcc69aed 100644
--- a/customer/mbvd-odt/int-odt-daimler-com.pixelpark.net.yaml
+++ b/customer/mbvd-odt/int-odt-daimler-com.pixelpark.net.yaml
@@ -25,6 +25,7 @@ infra::profile::apache::pp_vhosts:
     ssl_verify_client: require
     ssl_crl: '/etc/pki/tls/certs/odt-cacrl.pem'
     ssl_ca: '/etc/pki/tls/certs/odt-root-ca.pem'
+    custom_fragment: 'SSLRequire %%{ich-trickse}{SSL_CLIENT_S_DN_O} eq "ODT"'
     rewrites_non_ssl:
       - https:
         comment: 'almost all to https'