<VirtualHost *:80>
        ServerAdmin webmaster@feggm.de
        ServerName ffsync2.feggm.de
        <Location />
                Redirect 301 / https://ffsync2.feggm.de/
        </Location>

        <Location /server-status>
                SetHandler server-status
                Order Deny,Allow
                Deny from all
                Allow from 10.45.1
        </Location>
</VirtualHost>

<IfModule mod_ssl.c>
<VirtualHost *:443>
        ServerAdmin webmaster@feggm.de
        ServerName ffsync2.feggm.de

        DocumentRoot /usr/local/firefox-sync-server/server-full

        <Directory /usr/local/firefox-sync-server/server-full>
                Order deny,allow
                Allow from all
        </Directory>

        WSGIProcessGroup ffsync
        WSGIDaemonProcess ffsync user=ffsync group=ffsync processes=2 threads=25
        WSGIPassAuthorization On
        WSGIScriptAlias / /usr/local/firefox-sync-server/server-full/sync.wsgi

        <Location /server-status>
                SetHandler server-status
                Order Deny,Allow
                Deny from all
                Allow from 10.45.1
        </Location>

        ErrorLog ${APACHE_LOG_DIR}/error.log

        LogLevel warn

        CustomLog ${APACHE_LOG_DIR}/ffsync2_access.log combined

        SSLEngine on

        SSLCertificateFile    /etc/apache2/ssl/apache.pem
#       SSLCertificateKeyFile /etc/ssl/private/ssl-cert-snakeoil.key

        <FilesMatch "\.(cgi|shtml|phtml|php)$">
                SSLOptions +StdEnvVars
        </FilesMatch>
        <Directory /usr/lib/cgi-bin>
                SSLOptions +StdEnvVars
        </Directory>

        BrowserMatch "MSIE [2-6]" \
                nokeepalive ssl-unclean-shutdown \
                downgrade-1.0 force-response-1.0
        # MSIE 7 and newer should be able to use keepalive
        BrowserMatch "MSIE [17-9]" ssl-unclean-shutdown

</VirtualHost>
</IfModule>
