[Zope] Zope and SSL

Frank Tegtmeyer fte@lightwerk.com
22 Feb 2002 09:24:57 +0100


"Thierry Florac" <thierry.florac@onf.fr> writes:

> I'd like to let users access my Zope web site normally through HTTP, but
> make my Zope management screens (in fact, any URL containing '/manage')
> only available through HTTPS.

We (still) don't use virtual host monster, but virtual site root
instead (http://www.zope.org/Members/comlounge/vsr/).

In Apache you can do something like this:

RewriteRule ^.*/manage(_.*|())$ - [forbidden]

Please be aware that there may be products that don't use the 'manage'
convention. So this rule doesn't restrict all possible management
screens.

At the SSL server no special handling of management screens is
necessary.

Regards, Frank
-- 
CTO   fte@Lightwerk.com         http://www.Lightwerk.com/
Fax: +49-2434-80 07 94           Phone: +49-2434-80 07 81
Lightwerk GmbH * An der Kull 11 * 41844 Wegberg * Germany
Besuchen Sie uns auf der CeBIT:  Halle 6, Stand F68 / 595