这是Apache虚拟主机配置的一部分,匹配的传入请求被转发到Apache Tomcat服务器。所有客户端都必须发送客户端证书以进行App1的身份验证,但对于App2,它应该是可选的。
SSLVerifyClient require
SSLVerifyDepth 2
SSLOptions +ExportCertData +StdEnvVars
ProxyRequests Off
ProxyPass /app1/services/App01 ajp://localhost:8307/app1/services/App01
ProxyPass /app1/services/App02 ajp://localhost:8307/app2/services/App02
<Location /app1/services/App01>
ProxyPassReverse ajp://localhost:8307/app2/services/App02
</Location>
<Location /app2/services/App02>
ProxyPassReverse ajp://localhost:8307/app2/services/App02
</Location>
那么是否有可能将app2 SSLVerifyClient指令从必需切换为可选?
答案 0 :(得分:1)
在阅读了大量文档并尝试了不同的方法后,我找到了解决方案!
将所有代理指令带入Location上下文,将这些主机或虚拟主机的 SSLVerifyClient 指令设置为可选,并将 SSLVerifyClient require 放入需要的位置指令。
SSLVerifyClient optional
SSLVerifyDepth 2
SSLOptions +ExportCertData +StdEnvVars
ProxyRequests Off
<Location /app1/services/App01>
SSLVerifyClient require
ProxyPass ajp://localhost:8307/app1/services/App01
ProxyPassReverse ajp://localhost:8307/app2/services/App02
</Location>
<Location /app2/services/App02>
ProxyPass ajp://localhost:8307/app2/services/App02
ProxyPassReverse ajp://localhost:8307/app2/services/App02
</Location>