Displaying 20 results from an estimated 23 matches for "sslverifydepth".
2006 Aug 30
1
Rails + Apache FCGI Client Auth BUG
...request.
But when on SSL I type the same thing and I get:
=> nil
I don''t know why, but this does not happen all the time, seldom it shows 
my params variable even when on SSL.
This is how I configured SSL Client Auth on Apache:
<Location /myapp>
    SSLVerifyClient require
    SSLVerifyDepth  10
</Location>
<Files ~ "\.(cgi|fcgi|shtml|phtml|php3?)$">
    SSLOptions +StdEnvVars +ExportCertData
</Files>
Please help, I''m stuck and frustrated, could this be a bug?
Thanks.
-Ofir
-- 
Posted via http://www.ruby-forum.com/.
--~--~---------~--~----~----...
2012 Feb 06
1
Puppet / Passenger SSL Problems with DRBD
...t.pem
    SSLCACertificateFile    /drbd01/puppet/var/lib/puppet/ssl/ca/
ca_crt.pem
    # CRL checking should be enabled; if you have problems with Apache
complaining about the CRL, disable the nex
t line
#    SSLCARevocationFile     /var/lib/puppet/ssl/ca/ca_crl.pem
    SSLVerifyClient optional
    SSLVerifyDepth  1
    SSLOptions +StdEnvVars
    # The following client headers allow the same configuration to
work with Pound.
    RequestHeader set X-SSL-Subject %{SSL_CLIENT_S_DN}e
    RequestHeader set X-Client-DN %{SSL_CLIENT_S_DN}e
    RequestHeader set X-Client-Verify %{SSL_CLIENT_VERIFY}e
    RackAutoD...
2013 Jul 23
3
Debugging Puppetmaster with Apache/Rack/Passenger
...ib/puppet/ssl/private_keys/
<puppetmaster>.pem
        SSLCertificateChainFile /var/lib/puppet/ssl/ca/ca_crt.pem
        SSLCACertificateFile    /var/lib/puppet/ssl/ca/ca_crt.pem
        SSLCARevocationFile     /var/lib/puppet/ssl/ca/ca_crl.pem
        SSLVerifyClient         optional
        SSLVerifyDepth          1
        SSLOptions              +StdEnvVars +ExportCertData
        
        # These request headers are used to pass the client certificate
        # authentication information on to the puppet master process
        RequestHeader set X-SSL-Subject %{SSL_CLIENT_S_DN}e
        RequestHea...
2013 May 30
4
Could not request certificate: Error 405 on SERVER
...icateKeyFile   
/var/lib/puppet/ssl/private_keys/pmaster.localdomain.pem
    SSLCertificateChainFile /var/lib/puppet/ssl/ca/ca_crt.pem
    SSLCACertificateFile    /var/lib/puppet/ssl/ca/ca_crt.pem
    SSLCARevocationFile     /var/lib/puppet/ssl/ca/ca_crl.pem
    SSLVerifyClient         optional
    SSLVerifyDepth          1
    SSLOptions              +StdEnvVars +ExportCertData
    DocumentRoot /usr/share/puppet/rack/puppetmasterd/public/
    <Directory /usr/share/puppet/rack/puppetmasterd/>
        Options None
        AllowOverride None
        Order Allow,Deny
        Allow from All
    </Dire...
2010 Dec 22
3
Using Puppet's client certificates for Apache, SSLVerifyClient
...EXPORT:RC4+RSA
        SSLCertificateFile
/var/lib/puppet/ssl/certs/puppet01.ops.az.domain.local.pem
        SSLCertificateKeyFile
/var/lib/puppet/ssl/private_keys/puppet01.ops.az.domain.local.pem
        SSLCACertificateFile /var/lib/puppet/ssl/ca/ca_crt.pem
        SSLVerifyClient require
        SSLVerifyDepth 1
        SSLOptions +StdEnvVars
        ErrorLog /var/log/httpd/ssltest-error.log
        CustomLog /var/log/httpd/ssltest-access.log combined
</VirtualHost>
Pretty simple, right?  Am I doing this properly?
A little background:  I am in the process of building AMIs for
Amazon''s EC...
2012 Apr 22
2
centos 6.2 - puppet 2.7.13 - SSL_connect returned=1 errno=0 state=SSLv3 read server session ticket A: tlsv1 alert protocol version
...pet/ssl/ca/ca_crt.pem
    SSLCACertificateFile    /var/lib/puppet/ssl/ca/ca_crt.pem
    # CRL checking should be enabled; if you have problems with Apache 
complaining about the CRL, disable the next line
    SSLCARevocationFile     /var/lib/puppet/ssl/ca/ca_crl.pem
    SSLVerifyClient optional
    SSLVerifyDepth  1
    SSLOptions +StdEnvVars
    # The following client headers allow the same configuration to work 
with Pound.
    RequestHeader set X-SSL-Subject %{SSL_CLIENT_S_DN}e
    RequestHeader set X-Client-DN %{SSL_CLIENT_S_DN}e
    RequestHeader set X-Client-Verify %{SSL_CLIENT_VERIFY}e
    Passenge...
2010 Aug 20
5
puppet dashboard gui looks odd from apache2
...ppet/ssl/ca/ca_crt.pem
        # If Apache complains about invalid signatures on the CRL, you
can try disabling
        # CRL checking by commenting the next line, but this is not recommended.
        SSLCARevocationFile     /var/lib/puppet/ssl/ca/ca_crl.pem
        SSLVerifyClient optional
        SSLVerifyDepth  1
        SSLOptions +StdEnvVars
        DocumentRoot /usr/share/puppet/rack/puppetmasterd/public/
        RackBaseURI /
        <Directory /usr/share/puppet/rack/puppetmasterd/>
                Options None
                AllowOverride None
                Order allow,deny...
2010 Jun 09
12
Foreman -- Reporting
Hello All,
     I don''t seem to be able to get reports to display on the foreman
interface.  I copied extras/puppet/foreman/files/foreman-report.rb to /
usr/lib/ruby/site_ruby/1.8/puppet/reportsforeman.rb, instead of /usr/
lib/ruby/1.8/puppet/reports/foreman.rb. Config: Centos5.4, Apache/
Passenger, Puppet 0.25.4.
     The reports are coming from the clients, because I can see them
in
2009 Oct 19
7
Passenger Woes
...et/ssl/ca/ca_crt.pem
        # If Apache complains about invalid signatures on the CRL, you
can try disabling
        # CRL checking by commenting the next line, but this is not recommended.
        SSLCARevocationFile     /var/lib/puppet/ssl/ca/ca_crl.pem
        SSLVerifyClient optional
        SSLVerifyDepth  1
        SSLOptions +StdEnvVars
        DocumentRoot /etc/puppet/rack/public/
        RackBaseURI /
        <Directory /etc/puppet/rack/>
                Options None
                AllowOverride None
                Order allow,deny
                allow from all
        </Directory&g...
2012 Jun 12
1
Dashboard with RackbaseURI / and RailsAutoDetect off
...If Apache complains about invalid signatures on the CRL, you can 
> try disabling
>         # CRL checking by commenting the next line, but this is not 
> recommended.
>         SSLCARevocationFile     /var/lib/puppet/ssl/ca/ca_crl.pem
>         SSLVerifyClient optional
>         SSLVerifyDepth  1
>         SSLOptions +StdEnvVars
>
>         ErrorLog    logs/puppet_error_log
>         TransferLog logs/puppet_access_log
>         LogLevel    warn
>         # This header needs to be set if using a loadbalancer or proxy
>         #RequestHeader unset X-Forwarded-For
>...
2014 Aug 29
0
Using puppet with Apache mod_disk_cache and passenger over SSL
...SSLCertificateKeyFile   /var/lib/puppet/ssl/private_keys/hostname.pem
    SSLCertificateChainFile /var/lib/puppet/ssl/ca/ca_crt.pem
    SSLCACertificateFile    /var/lib/puppet/ssl/ca/ca_crt.pem
    SSLCARevocationFile     /var/lib/puppet/ssl/ca/ca_crl.pem
    SSLVerifyClient         optional
    SSLVerifyDepth          1
    SSLOptions              +StdEnvVars +ExportCertData
    # These request headers are used to pass the client certificate
    # authentication information on to the puppet master process
    RequestHeader set X-SSL-Subject %{SSL_CLIENT_S_DN}e
    RequestHeader set X-Client-DN %{SSL_CL...
2009 Sep 07
2
passenger-status error messages
...ib/puppet/ssl/ca/ca_crt.pem
	SSLCACertificateFile    /var/lib/puppet/ssl/ca/ca_crt.pem
	# If Apache complains about invalid signatures on the CRL, you can
try disabling
	# CRL checking by commenting the next line.
	SSLCARevocationFile     /var/lib/puppet/ssl/ca/ca_crl.pem
	SSLVerifyClient optional
	SSLVerifyDepth  1
	SSLOptions +StdEnvVars
	# The following client headers allow the same configuration to work with Pound.
	RequestHeader set X-SSL-Subject %{SSL_CLIENT_S_DN}e
	RequestHeader set X-Client-DN %{SSL_CLIENT_S_DN}e
	RequestHeader set X-Client-Verify %{SSL_CLIENT_VERIFY}e
	RackAutoDetect On
	Document...
2012 Dec 17
1
multiple puppet masters
...File    /var/lib/puppet/ssl/ca/ca_crt.pem
    # If Apache complains about invalid signatures on the CRL, you can try disabling
    # CRL checking by commenting the next line, but this is not recommended.
    #SSLCARevocationFile     /var/lib/puppet/ssl/ca/ca_crl.pem
    SSLVerifyClient optional
    SSLVerifyDepth  1
    # The `ExportCertData` option is needed for agent certificate expiration warnings
    SSLOptions +StdEnvVars +ExportCertData
    # This header needs to be set if using a loadbalancer or proxy
    RequestHeader unset X-Forwarded-For
    RequestHeader set X-SSL-Subject %{SSL_CLIENT_S_DN}e...
2011 Jun 29
0
Setting up puppetmaster-passenger on Debian
...sl/ca/ca_crl.pem
        # Set to require if this puppetmaster doesn''t issue certificates
        # to puppet clients.
        # NB: this requires SSLCACertificateFile
/var/lib/puppet/ssl/certs/ca.pem
        #     issuing puppet client certificate.
        SSLVerifyClient optional
        SSLVerifyDepth  1
        SSLOptions +StdEnvVars
        # Passenger options that can be set in a virtual host
        # configuration block.
        PassengerHighPerformance on
        PassengerStatThrottleRate 120
        PassengerUseGlobalQueue on
        RackAutoDetect Off
        RailsAutoDetect Off...
2011 May 31
3
uploading files via REST?
Hello,
I am a bit confused by the REST syntax - how can I PUT an arbitrary file in 
the bucket? Downloading works fine (Perl+LWP), see below, but for PUT I only 
see this line in the docs (http://docs.puppetlabs.com/guides/rest_api.html):
PUT /{environment}/file_bucket_file/md5/{checksum}
Should I compute the MD5 of the file and port its contents at the url ?
my code: 
my $ua =
2007 Nov 21
6
mod_proxy_balancer under heavy load.
...OW:-EXPORT:RC4+RSA
    SSLCertificateFile /path/to/certfile.pem
    SSLCertificateKeyFile /path/to/certkeyfile.pem
    SSLCertificateChainFile /path/to/certchainfile.pem
    SSLCACertificateFile /path/to/cacertfile.pem
    SSLCARevocationFile /path/to/carevocfile.pem
    SSLVerifyClient require
    SSLVerifyDepth  1
    SSLOptions +StdEnvVars
    RequestHeader set X-SSL-Subject %{SSL_CLIENT_S_DN}e
    RequestHeader set X-Client-DN %{SSL_CLIENT_S_DN}e
    RequestHeader set X-Client-Verify %{SSL_CLIENT_VERIFY}e
    <Location />
        SetHandler balancer-manager
        Order allow,deny
        Allow f...
2009 Feb 10
3
something wrong with mongrel?
...cateKeyFile		/var/lib/puppet/ssl/private_keys/gridinstall.pic.es.pem
    SSLCertificateChainFile     /var/lib/puppet/ssl/ca/ca_crt.pem
    SSLCACertificateFile        /var/lib/puppet/ssl/ca/ca_crt.pem
    SSLCARevocationFile         /var/lib/puppet/ssl/ca/ca_crl.pem
    SSLVerifyClient optional
    SSLVerifyDepth  1
    SSLOptions +StdEnvVars
    RequestHeader set X-Client-DN %{SSL_CLIENT_S_DN}e
    RequestHeader set X-Client-Verify %{SSL_CLIENT_VERIFY}e
    <Location />
       SetHandler balancer-manager
       Order allow,deny
       Allow from all
    </Location>
    ProxyPass / balancer://pu...
2012 Jun 14
15
Problem with Load Balancing Puppet masters with Apache mod_proxy
...teKeyFile /var/lib/puppet/ssl/private_keys/
puppetlb.example.com.pem
        SSLCertificateChainFile /var/lib/puppet/ssl/certs/ca.pem
        SSLCACertificateFile /var/lib/puppet/ssl/ca/ca_crt.pem
        SSLCARevocationFile /var/lib/puppet/ssl/ca/ca_crl.pem
        SSLVerifyClient optional
        SSLVerifyDepth 1
        SSLOptions +StdEnvVars
        RequestHeader set X-SSL-Subject %{SSL_CLIENT_S_DN}e
        RequestHeader set X-Client-DN %{SSL_CLIENT_S_DN}e
        RequestHeader set X-Client-Verify %{SSL_CLIENT_VERIFY}e
        <Location />
                SetHandler balancer-manager...
2011 Dec 16
12
Seperate CA's/Master behind load balancer
...tc/puppet/ssl/ca/ca_crt.pem
  # CRL checking should be enabled
  # disable next line if Apache complains about CRL
  #SSLCARevocationFile /etc/puppet/ssl/ca/ca_crl.pem
  # optional to allow CSR request, required if certificates
distributed to client during provisioning.
  SSLVerifyClient optional
  SSLVerifyDepth 1
  SSLOptions +StdEnvVars
  # The following client headers record authentication information for
down stream workers.
  RequestHeader set X-SSL-Subject %{SSL_CLIENT_S_DN}e
  RequestHeader set X-Client-DN %{SSL_CLIENT_S_DN}e
  RequestHeader set X-Client-Verify %{SSL_CLIENT_VERIFY}e
  # WARNING THIS...
2012 Oct 08
11
Puppet 3.0 upgrade issue
Hi @all,
after upgrading my puppet server to Puppet 3.0 I got the following error
every time a client connect to the server:
[ pid=1532 thr=70147393710520 file=utils.rb:176 time=2012-10-08
11:17:56.504 ]: *** Exception NoMethodError in
PhusionPassenger::Rack::ApplicationSpawner (undefined method `settings'' for
Puppet:Module) (process 1532, thread #<Thread:0x7f98ecf7d370>):