Commit 9c134474 authored by Fabien Combernous's avatar Fabien Combernous

Merge branch '79-webui_force_https-is-not-used' into 'master'

Resolve "webui_force_https is not used"

Closes #79

See merge request !77
parents 5bbcb54d c66d1c59
Pipeline #3283 canceled with stages
in 8 seconds
......@@ -67,7 +67,6 @@ class {'freeipa':
install_epel => true,
webui_disable_kerberos => true,
webui_enable_proxy => true,
webui_force_https => true,
humanadmins => {
jdupond => {
ensure => 'present',
......
......@@ -60,7 +60,6 @@ class {'freeipa':
install_epel => true,
webui_disable_kerberos => true,
webui_enable_proxy => true,
webui_force_https => true,
humanadmins => { foo => { password => 'secret123', ensure => 'present'}, bar => { password => 'secret123', ensure => 'present'} },
}
```
......@@ -345,14 +344,6 @@ If true, then httpd is configured to act as a reverse proxy for the IPA Web UI.
Default value: `false`
##### `webui_force_https`
Data type: `Boolean`
If true, then /etc/httpd/conf.d/ipa-rewrite.conf is modified to force all connections to https.
Default value: `false`
##### `webui_proxy_external_fqdn`
Data type: `Stdlib::Fqdn`
......
......@@ -16,7 +16,6 @@
# install_epel => true,
# webui_disable_kerberos => true,
# webui_enable_proxy => true,
# webui_force_https => true,
# humanadmins => { foo => { password => 'secret123', ensure => 'present'}, bar => { password => 'secret123', ensure => 'present'} },
# }
#
......@@ -64,7 +63,6 @@
# proxied port, while allowing IPA client access to function as normal.
# @param webui_enable_proxy If true, then httpd is configured to act as a reverse proxy for the IPA Web UI. This allows
# the Web UI to be accessed from different ports and hostnames than the default.
# @param webui_force_https If true, then /etc/httpd/conf.d/ipa-rewrite.conf is modified to force all connections to https.
# This is necessary to allow the WebUI to be accessed behind a reverse proxy when using nonstandard ports.
# @param webui_proxy_external_fqdn The public or external FQDN used to access the IPA Web UI behind the reverse proxy.
# @param webui_proxy_https_port The HTTPS port to use for the reverse proxy. Cannot be 443.
......@@ -115,7 +113,6 @@ class freeipa (
String $sssdtools_package_name = 'sssd-tools',
Boolean $webui_disable_kerberos = false,
Boolean $webui_enable_proxy = false,
Boolean $webui_force_https = false,
Stdlib::Fqdn $webui_proxy_external_fqdn = 'localhost',
String $webui_proxy_https_port = '8440',
) {
......
......@@ -20,7 +20,6 @@ describe 'freeipa class' do
install_epel => true,
webui_disable_kerberos => true,
webui_enable_proxy => true,
webui_force_https => true,
ipa_master_fqdn => 'ipa-server-1.example.lan',
humanadmins => {
foo => {
......@@ -117,7 +116,6 @@ describe 'freeipa class' do
install_epel => true,
webui_disable_kerberos => true,
webui_enable_proxy => true,
webui_force_https => true,
ipa_master_fqdn => 'ipa-server-1.example.lan',
}
EOS
......@@ -236,7 +234,6 @@ describe 'freeipa class' do
install_epel => true,
webui_disable_kerberos => true,
webui_enable_proxy => true,
webui_force_https => true,
ipa_master_fqdn => 'ipa-server-1.example.lan',
humanadmins => {
foo => {
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment