Subject svn commit: r1776075 - in /httpd/httpd/trunk/docs/manual/mod: mod_proxy_protocol.html mod_proxy_protocol.html.en
Date Mon, 26 Dec 2016 21:35:36 GMT
Author: jim
Date: Mon Dec 26 21:35:36 2016
New Revision: 1776075

and xforms 


Added: httpd/httpd/trunk/docs/manual/mod/mod_proxy_protocol.html
--- httpd/httpd/trunk/docs/manual/mod/mod_proxy_protocol.html (added)
+++ httpd/httpd/trunk/docs/manual/mod/mod_proxy_protocol.html Mon Dec 26 21:35:36 2016
@@ -0,0 +1,5 @@
+URI: mod_proxy_protocol.html.en
+Content-Language: en
+Content-type: text/html; charset=ISO-8859-1

Added: httpd/httpd/trunk/docs/manual/mod/mod_proxy_protocol.html.en
--- httpd/httpd/trunk/docs/manual/mod/mod_proxy_protocol.html.en (added)
+++ httpd/httpd/trunk/docs/manual/mod/mod_proxy_protocol.html.en Mon Dec 26 21:35:36 2016
@@ -0,0 +1,123 @@
+<?xml version="1.0" encoding="ISO-8859-1"?>
+<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "">
+<html xmlns="" lang="en" xml:lang="en"><head>
+<meta content="text/html; charset=ISO-8859-1" http-equiv="Content-Type" />
+              This file is generated from xml source: DO NOT EDIT
+      -->
+<title>mod_proxy_protocol - Apache HTTP Server Version 2.5</title>
+<link href="../style/css/manual.css" rel="stylesheet" media="all" type="text/css" title="Main
stylesheet" />
+<link href="../style/css/manual-loose-100pc.css" rel="alternate stylesheet" media="all"
type="text/css" title="No Sidebar - Default font size" />
+<link href="../style/css/manual-print.css" rel="stylesheet" media="print" type="text/css"
/><link rel="stylesheet" type="text/css" href="../style/css/prettify.css" />
+<script src="../style/scripts/prettify.min.js" type="text/javascript">
+<link href="../images/favicon.ico" rel="shortcut icon" /></head>
+<div id="page-content">
+<div id="preamble"><h1>Apache Module mod_proxy_protocol</h1>
+<div class="toplang">
+<p><span>Available Languages: </span><a href="../en/mod/mod_proxy_protocol.html"
+<table class="module"><tr><th><a href="module-dict.html#Description">Description:</a></th><td>Implements
the server side of the proxy protocol.</td></tr>
+<tr><th><a href="module-dict.html#Status">Status:</a></th><td>Extension</td></tr>
+<tr><th><a href="module-dict.html#ModuleIdentifier">Module Identifier:</a></th><td>proxy_protocol_module</td></tr>
+<tr><th><a href="module-dict.html#SourceFile">Source File:</a></th><td>mod_proxy_protocol.c</td></tr></table>
+    <p><code class="module"><a href="../mod/mod_proxy_protocol.html">mod_proxy_protocol</a></code>
implements the server side of
+    HAProxy's
+    <a href="">Proxy Protocol</a>.</p>
+    <p>The module overrides the client IP address for the connection
+    with the information supplied by the upstream proxy in the proxy
+    protocol (connection) header.</p>
+    <p>This overridden useragent IP address is then used for the
+    <code class="module"><a href="../mod/mod_authz_host.html">mod_authz_host</a></code>
+    <code class="directive"><a href="../mod/mod_authz_core.html#require">Require
+    feature, is reported by <code class="module"><a href="../mod/mod_status.html">mod_status</a></code>,
and is recorded by
+    <code class="module"><a href="../mod/mod_log_config.html">mod_log_config</a></code>
<code>%a</code> and <code class="module"><a href="../mod/core.html">core</a></code>
+    <code>%a</code> format strings. The underlying client IP of the connection
+    is available in the <code>%{c}a</code> format string.</p>
+    <div class="warning">It is critical to only enable this behavior from
+    intermediate proxies which are trusted by this server, since it is trivial
+    for the remote client to impersonate another client. Currently this must
+    be done by external means (such as a firewall) as this module does not
+    (yet) implement access controls.</div>
+<div class="top"><a href="#page-header"><img alt="top" src="../images/up.gif"
+<div class="directive-section"><h2><a name="ProxyProtocolFilter " id="ProxyProtocolFilter
">ProxyProtocolFilter </a> <a name="proxyprotocolfilter " id="proxyprotocolfilter
+<table class="directive">
+<tr><th><a href="directive-dict.html#Description">Description:</a></th><td>Enable
or disable the proxy protocol handling</td></tr>
+<tr><th><a href="directive-dict.html#Syntax">Syntax:</a></th><td><code>ProxyProtocolFilter
+<tr><th><a href="directive-dict.html#Context">Context:</a></th><td>server
config, virtual host</td></tr>
+<tr><th><a href="directive-dict.html#Status">Status:</a></th><td>Extension</td></tr>
+<tr><th><a href="directive-dict.html#Module">Module:</a></th><td>mod_proxy_protocol</td></tr>
+    <p>The <code class="directive">ProxyProtocolFilter</code> enables or
disables the
+    reading and handling of the proxy protocol connection header. If enabled
+    the upstream client <em>must</em> send the header every time it opens a
+    connection or the connection will get aborted.</p>
+    <p>While this directive may be specified in any virtual host, it is
+    important to understand that because the proxy protocol is connection
+    based and protocol agnostic, the enabling and disabling is actually based
+    on ip-address and port. This means that if you have multiple name-based
+    virtual hosts for the same host and port, and you enable it any one of
+    them, then it is enabled for all them (with that host and port). It also
+    means that if you attempt to enable the proxy protocol in one and disable
+    in the other, that won't work; in such a case the last one wins and a
+    notice will be logged indicating which setting was being overridden.</p>
+    <pre class="prettyprint lang-config">ProxyProtocolFilter On</pre>
