################################################################################
#
# Apache2 shibboleth authentication file.
#
# The shibboleth authentication file contains configuration options that allow
# authentication against the kit.edu shibboleth servers. It can be included from
# within a <Directory> but not from a .htaccess file. A common setup would be:
#
#   Include		/etc/apache2/include/auth_shibboleth
#   Require		shibboleth

<IfModule mod_shib>
	# Shibboleth is unable to change to https by itself :-(
	RewriteEngine		On
	RewriteCond		%{HTTPS}	!=on
	RewriteRule		.*		https://%{SERVER_NAME}%{REQUEST_URI}	[R=permanent,L]
	# So now that we have encryption enabled, here comes the shib auth
	AuthType		shibboleth
	ShibRequestSetting	requireSession	1
	ShibRequestMapperAuthz	Off
</IfModule>
