--- loncom/loncapa_apache.conf 2004/04/01 14:28:49 1.76 +++ loncom/loncapa_apache.conf 2004/06/29 14:19:32 1.88 @@ -1,7 +1,7 @@ ## ## loncapa_apache.conf -- Apache HTTP LON-CAPA configuration file ## -## $Id: loncapa_apache.conf,v 1.76 2004/04/01 14:28:49 albertel Exp $ +## $Id: loncapa_apache.conf,v 1.88 2004/06/29 14:19:32 albertel Exp $ ## # @@ -60,9 +60,24 @@ ErrorDocument 500 /adm/errorhandler PerlAccessHandler Apache::lonenc ErrorDocument 403 /adm/login +ErrorDocument 404 /adm/notfound.html +ErrorDocument 406 /adm/roles ErrorDocument 500 /adm/errorhandler + +PerlAccessHandler Apache::lonacc +SetHandler perl-script +PerlHandler Apache::portfolio + + + +SetHandler perl-script +PerlHandler Apache::portfolio + + + + PerlAccessHandler Apache::lontokacc PerlCleanupHandler Apache::lontokacc::removefile @@ -71,7 +86,9 @@ PerlCleanupHandler Apache::lontokacc::re PerlAccessHandler Apache::lonacc PerlHeaderParserHandler Apache::lonuploadrep +ErrorDocument 403 /adm/login ErrorDocument 404 /adm/notfound.html +ErrorDocument 406 /adm/roles ErrorDocument 500 /adm/errorhandler @@ -235,8 +252,9 @@ SetHandler perl-script PerlHandler Apache::lonrights - + SetHandler perl-script +PerlHandler Apache::londatecheck PerlHandler Apache::lonxml @@ -253,6 +271,16 @@ ErrorDocument 403 /adm/login ErrorDocument 500 /adm/errorhandler + +PerlAccessHandler Apache::lonacc +SetHandler perl-script +PerlHandler Apache::lonsource +ErrorDocument 403 /adm/login +ErrorDocument 406 /adm/roles +ErrorDocument 500 /adm/errorhandler + + + PerlAccessHandler Apache::lonacc SetHandler perl-script @@ -328,6 +356,14 @@ ErrorDocument 403 /adm/login ErrorDocument 500 /adm/errorhandler + +PerlAccessHandler Apache::lonacc +SetHandler perl-script +PerlHandler Apache::lonpickcode +ErrorDocument 403 /adm/login +ErrorDocument 500 /adm/errorhandler + + SetHandler perl-script PerlHandler Apache::lonlogin @@ -899,6 +935,78 @@ PerlSetVar lonSqlAccess localhos PerlSetVar lonhttpdPort 8080 +#---------------------------------------------------------------------------- +# +# Parameters used by secure lond/lonc + +# +# Secure lond/lonc require ssl certificate and private +# key files to function correctly. The certificate +# files need not be terribly secure, but the private key files +# should be set up so that only www (the lonc/lond effective user) +# can read them. +# +# The definition below is the full path to the directory that +# contains the certificate and key files: + +PerlSetVar lonCertificateDirectory /home/httpd/lonCerts + +# +# Secure lond/lonc require two certificates and a private host key. +# The certificates required are that of the lonCAPA certificate authority +# and the certificate that authority issued to this host. +# lonnetCertificateAuthority is the name of the file that contains the +# lonCAPA certificate authority's certificate. +# lonnetCertificate is the name of the file that contains the certificate +# issued to the host by the certificate authority. +# Both of these variables are names of files assumed to be in +# lonCertificateDirectory: + +PerlSetVar lonnetCertificateAuthority loncapaCA.pem +PerlSetVar lonnetCertificate lonhostcert.pem + +# +# To generate the request for a certificate, and to negotiate the +# initial ssl connection, the host requires a private key. This key +# is created at lonCAPA install time. Did we mention above that it +# should be set so that only www can read it? The variale below +# is the name of the file relative to lonnetCertificateDirectory +# that has the host's private key. Did we remember to tell you to +# keep the permissions on that file set to rw------- (0600)? +# + +PerlSetVar lonnetPrivateKey lonKey.pem + +# Did we mention that the file described above must have +# permissions really locked down so that it can't be stolen? + +#------------------------------------------------------------------------- + +# Parameters that define where all the ssl stuff is that's needed +# to generate certificate requests and, on a system that's a CA +# the certificate authority. +# +# SSLProgram -> Path to the openssl command +# SSLDirectory -> Directory containing ssl configuration files etc. +# SSLCAConfig -> Name of the SSL config file for the certificate +# Authority. +# SSLCAFile -> Full path to the Certificate authority file +# (on the cert manager system). +# SSLEmail -> E-mail address of loncapa certificate manager. +# The following are good for the loncapa redhat installs and +# the loncapa certificate authority system: +# +PerlSetVar SSLProgram /usr/bin/openssl +PerlSetVar SSLDirectory /usr/share/ssl +PerlSetVar SSLCAConfig loncapaca +PerlSetVar SSLCAFile /usr/share/ssl/loncapaca/cacert.pem +# CHANGE THIS!!!!! +PerlSetVar SSLEmail fox@nscl.msu.edu + +#------------------------------------------------------------------------- + + + # ====================================== Include machine-specific configuration