Return-Path:
Delivered-To: apmail-tomcat-dev-archive@www.apache.org
Received: (qmail 17370 invoked from network); 11 Mar 2009 23:29:11 -0000
Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.2)
by minotaur.apache.org with SMTP; 11 Mar 2009 23:29:11 -0000
Received: (qmail 90493 invoked by uid 500); 11 Mar 2009 23:29:07 -0000
Delivered-To: apmail-tomcat-dev-archive@tomcat.apache.org
Received: (qmail 90335 invoked by uid 500); 11 Mar 2009 23:29:06 -0000
Mailing-List: contact dev-help@tomcat.apache.org; run by ezmlm
Precedence: bulk
List-Help:
List-Unsubscribe:
List-Post:
List-Id:
Reply-To: "Tomcat Developers List"
Delivered-To: mailing list dev@tomcat.apache.org
Received: (qmail 90324 invoked by uid 99); 11 Mar 2009 23:29:05 -0000
Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230)
by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 11 Mar 2009 16:29:05 -0700
X-ASF-Spam-Status: No, hits=-2000.0 required=10.0
tests=ALL_TRUSTED
X-Spam-Check-By: apache.org
Received: from [140.211.11.4] (HELO eris.apache.org) (140.211.11.4)
by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 11 Mar 2009 23:29:03 +0000
Received: by eris.apache.org (Postfix, from userid 65534)
id 8ABB123888E7; Wed, 11 Mar 2009 23:28:42 +0000 (UTC)
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Subject: svn commit: r752691 -
/tomcat/connectors/trunk/jk/xdocs/generic_howto/proxy.xml
Date: Wed, 11 Mar 2009 23:28:42 -0000
To: dev@tomcat.apache.org
From: rjung@apache.org
X-Mailer: svnmailer-1.0.8
Message-Id: <20090311232842.8ABB123888E7@eris.apache.org>
X-Virus-Checked: Checked by ClamAV on apache.org
Author: rjung
Date: Wed Mar 11 23:28:42 2009
New Revision: 752691
URL: http://svn.apache.org/viewvc?rev=752691&view=rev
Log:
Add a few tweaks to the new proxy docs page.
Modified:
tomcat/connectors/trunk/jk/xdocs/generic_howto/proxy.xml
Modified: tomcat/connectors/trunk/jk/xdocs/generic_howto/proxy.xml
URL: http://svn.apache.org/viewvc/tomcat/connectors/trunk/jk/xdocs/generic_howto/proxy.xml?rev=752691&r1=752690&r2=752691&view=diff
==============================================================================
--- tomcat/connectors/trunk/jk/xdocs/generic_howto/proxy.xml (original)
+++ tomcat/connectors/trunk/jk/xdocs/generic_howto/proxy.xml Wed Mar 11 23:28:42 2009
@@ -92,9 +92,13 @@
SSL cipher: getAttribute(javax.servlet.request.cipher_suite)
-SSL key size: getAttribute(javax.servlet.request.key_size)
+SSL key size: getAttribute(javax.servlet.request.key_size)
.
+Can be disabled using JkOptions -ForwardKeySize
.
-SSL client certificate: getAttribute(javax.servlet.request.X509Certificate)
+SSL client certificate: getAttribute(javax.servlet.request.X509Certificate)
.
+If you want the whole certificate chain, then you need to also set JkOptions ForwardSSLCertChain
.
+It is likely, that in this case you also need to adjust the maximal AJP packet size
+using the worker attribute max_packet_size.
SSL session ID: getAttribute(javax.servlet.request.ssl_session)
.
This is for Tomcat, it has not yet been standardized.
@@ -169,6 +173,11 @@
All variables, that are not SSL-related have only been introduced in version 1.2.27.
+Finally there is a shortcut to forward the local IP of the web server as the remote IP.
+This can be useful, e.g. when using the Tomcat remote address valve for allowing connections
+only from registered Apache web servers. This feature is activated by setting
+JkOptions ForwardLocalAddress
.
+
---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org