From e5e44d5bc1b91acb3ba460b79956d37e8111206f Mon Sep 17 00:00:00 2001 From: Gregory Colpart Date: Fri, 18 Aug 2017 02:31:41 +0200 Subject: [PATCH] standard Evolix name is /etc/apache2/ipaddr_whitelist.conf cf https://wiki.evolix.org/HowtoApache --- apache/tasks/auth.yml | 10 ++++----- apache/templates/evolinux-default.conf.j2 | 26 +++++++++++------------ 2 files changed, 18 insertions(+), 18 deletions(-) diff --git a/apache/tasks/auth.yml b/apache/tasks/auth.yml index 32b9966a..0f550a3c 100644 --- a/apache/tasks/auth.yml +++ b/apache/tasks/auth.yml @@ -1,9 +1,9 @@ --- -- name: Init private_ipaddr_whitelist.conf file +- name: Init ipaddr_whitelist.conf file copy: src: private_ipaddr_whitelist.conf - dest: /etc/apache2/private_ipaddr_whitelist.conf + dest: /etc/apache2/ipaddr_whitelist.conf owner: root group: root mode: "0640" @@ -13,7 +13,7 @@ - name: add IP addresses to private IP whitelist lineinfile: - dest: /etc/apache2/private_ipaddr_whitelist.conf + dest: /etc/apache2/ipaddr_whitelist.conf line: "Require ip {{ item }}" state: present with_items: "{{ apache_private_ipaddr_whitelist_present }}" @@ -23,7 +23,7 @@ - name: remove IP addresses from private IP whitelist lineinfile: - dest: /etc/apache2/private_ipaddr_whitelist.conf + dest: /etc/apache2/ipaddr_whitelist.conf line: "Require ip {{ item }}" state: absent with_items: "{{ apache_private_ipaddr_whitelist_absent }}" @@ -34,7 +34,7 @@ - name: include private IP whitelist for server-status lineinfile: dest: /etc/apache2/mods-available/status.conf - line: " include /etc/apache2/private_ipaddr_whitelist.conf" + line: " include /etc/apache2/ipaddr_whitelist.conf" insertafter: 'SetHandler server-status' state: present tags: diff --git a/apache/templates/evolinux-default.conf.j2 b/apache/templates/evolinux-default.conf.j2 index a1f681e4..a53d3c9f 100644 --- a/apache/templates/evolinux-default.conf.j2 +++ b/apache/templates/evolinux-default.conf.j2 @@ -5,24 +5,24 @@ DocumentRoot /var/www/ - Include /etc/apache2/private_ipaddr_whitelist.conf + Include /etc/apache2/ipaddr_whitelist.conf Options -Indexes Require all denied - Include /etc/apache2/private_ipaddr_whitelist.conf + Include /etc/apache2/ipaddr_whitelist.conf # Munin. We need to set Directory directive as Alias take precedence. Alias /munin /var/cache/munin/www Require all denied - Include /etc/apache2/private_ipaddr_whitelist.conf + Include /etc/apache2/ipaddr_whitelist.conf Options -Indexes Require all denied - Include /etc/apache2/private_ipaddr_whitelist.conf + Include /etc/apache2/ipaddr_whitelist.conf # For CGI Scripts. We need to set Directory directive as ScriptAlias take precedence. @@ -30,7 +30,7 @@ Options +ExecCGI -MultiViews +SymLinksIfOwnerMatch Require all denied - Include /etc/apache2/private_ipaddr_whitelist.conf + Include /etc/apache2/ipaddr_whitelist.conf CustomLog /var/log/apache2/access.log vhost_combined @@ -53,7 +53,7 @@ SetHandler server-status - include /etc/apache2/private_ipaddr_whitelist.conf + include /etc/apache2/ipaddr_whitelist.conf Require local @@ -68,12 +68,12 @@ DocumentRoot /var/www/ - Include /etc/apache2/private_ipaddr_whitelist.conf + Include /etc/apache2/ipaddr_whitelist.conf Options -Indexes Require all denied - Include /etc/apache2/private_ipaddr_whitelist.conf + Include /etc/apache2/ipaddr_whitelist.conf SSLEngine on @@ -83,19 +83,19 @@ # We override these 2 Directory directives setted in apache2.conf. # We want no access except from allowed IP address. - Include /etc/apache2/private_ipaddr_whitelist.conf + Include /etc/apache2/ipaddr_whitelist.conf # Munin. We need to set Directory directive as Alias take precedence. Alias /munin /var/cache/munin/www Require all denied - Include /etc/apache2/private_ipaddr_whitelist.conf + Include /etc/apache2/ipaddr_whitelist.conf Options -Indexes Require all denied - Include /etc/apache2/private_ipaddr_whitelist.conf + Include /etc/apache2/ipaddr_whitelist.conf # For CGI Scripts. We need to set Directory directive as ScriptAlias take precedence. @@ -103,7 +103,7 @@ Options +ExecCGI -MultiViews +SymLinksIfOwnerMatch Require all denied - Include /etc/apache2/private_ipaddr_whitelist.conf + Include /etc/apache2/ipaddr_whitelist.conf CustomLog /var/log/apache2/access.log vhost_combined @@ -113,7 +113,7 @@ SetHandler server-status - include /etc/apache2/private_ipaddr_whitelist.conf + include /etc/apache2/ipaddr_whitelist.conf Require local