From 9d55be3dae2f7def1ad2397be393474c157ccd75 Mon Sep 17 00:00:00 2001 From: Patrick Uiterwijk Date: Wed, 23 Nov 2016 00:36:46 +0000 Subject: [PATCH] Use GSSAPI local username Signed-off-by: Patrick Uiterwijk --- roles/koji_hub/templates/kojihub.conf.j2 | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/roles/koji_hub/templates/kojihub.conf.j2 b/roles/koji_hub/templates/kojihub.conf.j2 index e9ccebcd19..d88b69733c 100644 --- a/roles/koji_hub/templates/kojihub.conf.j2 +++ b/roles/koji_hub/templates/kojihub.conf.j2 @@ -31,12 +31,13 @@ SSLVerifyClient optional SSLVerifyDepth 10 SSLOptions +StdEnvVars {% else %} - SSLVerifyClient optional + SSLVerifyClient optional SSLVerifyDepth 1 SSLOptions +StrictRequire +StdEnvVars +OptRenegotiate AuthType GSSAPI GssapiSSLonly On + GssapiLocalName On AuthName "GSSAPI Single Sign On Login" GssapiCredStore keytab:/etc/koji-hub-http.keytab