## USE: git clone git+ssh://$USER@puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet.git
##
-<Directory /srv/ftp.root/debian-security>
- IndexOptions NameWidth=* +SuppressDescription
- Options +FollowSymLinks
- Options +Indexes
- FileETag MTime Size
- Require all granted
-</Directory>
-
<VirtualHost *:80>
ServerAdmin debian-admin@debian.org
DocumentRoot /srv/ftp.root/debian-security
ServerAlias security-cdn1.debian.org
ServerAlias security-cdn2.debian.org
ServerAlias security-nagios.debian.org
+ <% if scope.function_onion_global_service_hostname(['security.debian.org']) -%>
+ ServerAlias <%= scope.function_onion_global_service_hostname(['security.debian.org']) %>
+ <% end %>
+ ServerAlias security.backend.mirrors.debian.org
+ ServerAlias *.security.backend.mirrors.debian.org
+ ServerAlias security.anycast-test.mirrors.debian.org
+
ExpiresActive On
ExpiresDefault "access plus 2 minutes"
Use ftp-archive /srv/ftp.root/debian-security
RewriteEngine on
- RewriteRule ^/$ http://www.debian.org/security/
-
- # Possible values include: debug, info, notice, warn, error, crit,
- # alert, emerg.
- LogLevel warn
+ RewriteRule ^/$ https://www.debian.org/security/
+
+ RewriteCond %{HTTP:Fastly-Client-IP} !. [NV]
+ RewriteCond %{HTTP_USER_AGENT} "!Amazon CloudFront"
+ <% if scope.function_onion_global_service_hostname(['security.debian.org']) -%>
+ RewriteCond %{HTTP_HOST} "!=<%= scope.function_onion_global_service_hostname(['security.debian.org']) %>"
+ <% end %>
+ RewriteRule ^/(pool/updates/main/l/linux/.*) http://security-cdn.debian.org/$1 [L,R=302]
+ RewriteCond %{HTTP:Fastly-Client-IP} !. [NV]
+ RewriteCond %{HTTP_USER_AGENT} "!Amazon CloudFront"
+ <% if scope.function_onion_global_service_hostname(['security.debian.org']) -%>
+ RewriteCond %{HTTP_HOST} "!=<%= scope.function_onion_global_service_hostname(['security.debian.org']) %>"
+ <% end %>
+ RewriteRule ^/debian-security/(pool/updates/main/l/linux/.*) http://security-cdn.debian.org/$1 [L,R=302]
CustomLog /var/log/apache2/security.debian.org-access.log privacy
ServerSignature On
</VirtualHost>
-# vim: set ts=3 sw=3 et:
+# vim:set syn=apache: