Return-Path: Delivered-To: apmail-tomcat-dev-archive@www.apache.org Received: (qmail 17370 invoked from network); 11 Mar 2009 23:29:11 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.2) by minotaur.apache.org with SMTP; 11 Mar 2009 23:29:11 -0000 Received: (qmail 90493 invoked by uid 500); 11 Mar 2009 23:29:07 -0000 Delivered-To: apmail-tomcat-dev-archive@tomcat.apache.org Received: (qmail 90335 invoked by uid 500); 11 Mar 2009 23:29:06 -0000 Mailing-List: contact dev-help@tomcat.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Tomcat Developers List" Delivered-To: mailing list dev@tomcat.apache.org Received: (qmail 90324 invoked by uid 99); 11 Mar 2009 23:29:05 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 11 Mar 2009 16:29:05 -0700 X-ASF-Spam-Status: No, hits=-2000.0 required=10.0 tests=ALL_TRUSTED X-Spam-Check-By: apache.org Received: from [140.211.11.4] (HELO eris.apache.org) (140.211.11.4) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 11 Mar 2009 23:29:03 +0000 Received: by eris.apache.org (Postfix, from userid 65534) id 8ABB123888E7; Wed, 11 Mar 2009 23:28:42 +0000 (UTC) Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Subject: svn commit: r752691 - /tomcat/connectors/trunk/jk/xdocs/generic_howto/proxy.xml Date: Wed, 11 Mar 2009 23:28:42 -0000 To: dev@tomcat.apache.org From: rjung@apache.org X-Mailer: svnmailer-1.0.8 Message-Id: <20090311232842.8ABB123888E7@eris.apache.org> X-Virus-Checked: Checked by ClamAV on apache.org Author: rjung Date: Wed Mar 11 23:28:42 2009 New Revision: 752691 URL: http://svn.apache.org/viewvc?rev=752691&view=rev Log: Add a few tweaks to the new proxy docs page. Modified: tomcat/connectors/trunk/jk/xdocs/generic_howto/proxy.xml Modified: tomcat/connectors/trunk/jk/xdocs/generic_howto/proxy.xml URL: http://svn.apache.org/viewvc/tomcat/connectors/trunk/jk/xdocs/generic_howto/proxy.xml?rev=752691&r1=752690&r2=752691&view=diff ============================================================================== --- tomcat/connectors/trunk/jk/xdocs/generic_howto/proxy.xml (original) +++ tomcat/connectors/trunk/jk/xdocs/generic_howto/proxy.xml Wed Mar 11 23:28:42 2009 @@ -92,9 +92,13 @@
  • SSL cipher: getAttribute(javax.servlet.request.cipher_suite)
  • -
  • SSL key size: getAttribute(javax.servlet.request.key_size) +
  • SSL key size: getAttribute(javax.servlet.request.key_size). +Can be disabled using JkOptions -ForwardKeySize.
  • -
  • SSL client certificate: getAttribute(javax.servlet.request.X509Certificate) +
  • SSL client certificate: getAttribute(javax.servlet.request.X509Certificate). +If you want the whole certificate chain, then you need to also set JkOptions ForwardSSLCertChain. +It is likely, that in this case you also need to adjust the maximal AJP packet size +using the worker attribute max_packet_size.
  • SSL session ID: getAttribute(javax.servlet.request.ssl_session). This is for Tomcat, it has not yet been standardized. @@ -169,6 +173,11 @@

    All variables, that are not SSL-related have only been introduced in version 1.2.27.

    +

    Finally there is a shortcut to forward the local IP of the web server as the remote IP. +This can be useful, e.g. when using the Tomcat remote address valve for allowing connections +only from registered Apache web servers. This feature is activated by setting +JkOptions ForwardLocalAddress. +


    --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org For additional commands, e-mail: dev-help@tomcat.apache.org