1
0
Fork 0
forked from infra/ansible
ansible/roles/httpd/reverseproxy
Adam Williamson 77ba912e7b Bump SSLProxyVerifyDepth in forgejo -> pagure.io redirect
From the logs on the proxies I can see the reason the redirects
for attachments are failing is the certificate chain for
pagure.io is now deeper than it was before:

[Fri Aug 07 23:23:10.874410 2026] [ssl:error] [pid 2283452:tid 2288622] [remote 2620:52:6:1161::32:443] AH02040: Certificate Verification: Certificate Chain too long (chain has 3 certificates, but maximum allowed are only 2)

I don't know why this changed, but I guess it's something to do
with preparation for pagure.io retirement? Anyway, assuming the
change is expected, this fixes the redirects (I tested by hand
patching proxy04 and forcing my box to always use proxy04 for
forge.fp.o, it works fine).

Resolves: forge/forge#703

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2026-08-10 18:20:59 +00:00
..
tasks Move the qa-landingpage reverse proxy config removal 2026-01-21 15:44:01 -08:00
templates Bump SSLProxyVerifyDepth in forgejo -> pagure.io redirect 2026-08-10 18:20:59 +00:00
vars Fix majority of remaining yamllint warnings and errors 2024-11-28 17:31:45 +10:00