From c1ce2ab2bd24c30f640bcef3d131513d1b0573c7 Mon Sep 17 00:00:00 2001 From: jakob Date: Fri, 21 Nov 2025 08:52:47 +0000 Subject: [PATCH] new configuration version --- ...8s-nevisauth-ac27dd7daad0ca2b7229bfaf.yaml | 2 +- .../own/agov-ident-signer-keystore/key.pem | 104 +++++++++--------- .../agov-ident-signer-keystore/keystore.pem | 104 +++++++++--------- ...oxy-instance-bd83dfbd467e8211ffe71d28.yaml | 2 +- .../security_nevismeta_web_console.conf | 18 +++ .../WEB-INF/web.xml | 97 ++++++++++++++++ 6 files changed, 221 insertions(+), 106 deletions(-) create mode 100644 DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/security_nevismeta_web_console.conf diff --git a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/auth/etc/nevis/k8s-nevisauth-ac27dd7daad0ca2b7229bfaf.yaml b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/auth/etc/nevis/k8s-nevisauth-ac27dd7daad0ca2b7229bfaf.yaml index e798377..674fdf7 100644 --- a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/auth/etc/nevis/k8s-nevisauth-ac27dd7daad0ca2b7229bfaf.yaml +++ b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/auth/etc/nevis/k8s-nevisauth-ac27dd7daad0ca2b7229bfaf.yaml @@ -45,7 +45,7 @@ spec: podDisruptionBudget: maxUnavailable: "50%" git: - tag: "r-ffccb0ac6d5831789f198ab73f0ecfff9ea38df7" + tag: "r-153c4f15e7495a3864d7ae40ed58b6b28b543733" dir: "DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/auth" credentials: "git-credentials" keystores: diff --git a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/auth/var/opt/keys/own/agov-ident-signer-keystore/key.pem b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/auth/var/opt/keys/own/agov-ident-signer-keystore/key.pem index 0154273..584d4c0 100644 --- a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/auth/var/opt/keys/own/agov-ident-signer-keystore/key.pem +++ b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/auth/var/opt/keys/own/agov-ident-signer-keystore/key.pem @@ -1,54 +1,54 @@ -----BEGIN ENCRYPTED PRIVATE KEY----- -MIIJqzBVBgkqhkiG9w0BBQ0wSDAnBgkqhkiG9w0BBQwwGgQUuj8UNQmLKEwOD3Ij -gjT2bC1IgOUCAggAMB0GCWCGSAFlAwQBKgQQilo/zrSzyfj+eUjtGegooASCCVBn -3gQUmNY8CiejjthSXhpxCfVdX4P0lyhQ1Y7Q4wGhxVNTRNQoAJoUx6rnvhO+bLyp -/cW5OkIu212YrSaF9Yr+H06k6v8fMMeDEqLCrAT54HjtNqKP3NerBT0bQHs+ZHI7 -CK92SyxDlwVXzmLBei2vTnclud93AwFXlnY1HEmt6nOIzzZYOZOrJJARoUfnsdEP -q0c27EhJ4crY6V4Ld+fhudOo7pPGchDOwagEXIjmi/rLnk3ZPo9vUE5TZh85bcv6 -ggAoOKXR6nBVSykdUvwjBSQgkZj13WRSoutWOILxHer98qql3OhstFbmn0OPqabx -C3XL9Xh2iycWNWUFRoRb/b+g6asJrTKNmbq9h1v/iFr2s2dC8bHK3IXRuV0sTGyT -m3iUQOjFN1e1/kAcCu4a7qZwKk0athIPsEX89nkP0TV8TyGKRjP7jyECiTt4AwyE -b/I/gbJs8d6zACPkslXJmLmPUhxwwHBRw8Ayk83xvAtjGJAGMNqa2DjjTGE40jnJ -2/Mmq9uIK1tf7TBF7cp5SJrEpd+c+eq+nx2tgGhYfj3TrlG0LLi2kW/QVcYlJyVE -hDxA/PDQQ9ykuwwHGtmgykjEpxqhIlkzrsFfuShRw9KcwFwLaAWDzECzMjzwdCux -z3U4HYWMuSUgvwF/ek40yvw40DLPOz9l6WgFRwdtr2t7wPLu/g3KkyRp0SXL5Wf2 -8cyMQ/CZhm10aSzOqFda9c2rFKZ+ICfPg96NGJ9y2lMm7aKVXywxlk42u8wfkG6B -Q0vRUNhmhED+SC+aDmxUpwmG5WCX5SJVvt3e9VRBDxZzHVEqTgtOqN8XgFDpoLg8 -nis2Gz3VEpV2Ex1N4mgVNRSp8qIkB+SXm8aFi0s4XFAc4MBVDaW5orS8ucgxoX1m -SGa16/EwnP68rQou5bWlApe6TdmxFPGKiQgEb9eHLXy9Ye8wsUo85iDcLUGmiK9k -A9OnE5+essvEKEP0UPkSvML/uf5kaLWNb6lmWmZ9LZd9XuvrAwY+4jH+03OxWEwB -UBuEWCrkkYqYubMh6avkZQl/nG0I2nJx1lz7XOaWgXXaHm6w6kqQdfBvpzr6MUXy -gJKFKaCydI/z+Hb/HRsxQLBTXo/BdTGCYbakiQQbXEKmhrrrHuXUb273kJpmKAWu -s0147rjEPnZlZjsnKctILUOrUctkB8E53yXLx4mp4ptxOtbb/FgOxdUIo9iQ5/sZ -5o2whxjHIXn/jCGXUbdZXmAJ7fG9WY6WHBlcJrJuKJt3duu8OqJ45IZA6kkZLvCm -eR4tFSJWqvHfxLrzznHLzENOgB2A4Syvrzvbi9nBWWavS6dtqnBpVCr4FbchpZEM -N+ljYY3SJ7iX2a0mPpQ5llOfhC3yqrG71aaPLxcuFAY1g/YX/SWRTT3yMds/XZAh -Cd3iCR48Y+NZXQdnnTTyGpe3O+pxZbzxTeRcq7OKETKM/KJaISynEveccTvR1Jh0 -7oHr+SxqmzFA3McupLvupv81ERT3kXe6h+5KlIdawwxW30gsIgFpx4XhpYQeBEPC -j/zH+ivBXJRs5+H4KGdTPJCRmXbSVmbCDPedrQOLNHY+rj79PhsV3Ut4s5+EHNiV -269FL0q3MdrPnZfbQSno2HCrOBoixVfFh7Kk+gEAL575NZPvhmkYdtS/ysYlR4yJ -Y6Zwl6IUV/bAu1hTg9vSZsxDId0mrmiJ9U6ovWrIzXHif1asLoHX1oxQHTJq0T9o -boLodekjlXswfXHckQyPwa3fDa0MnGb5ZN1vOo0X+DvmwthNKwhAuUULrTYqSJPQ -zGziNz1aEntO+2W6p+ZiHC0sUl3slVWS13borTLCs1GxyF3THctwCisfs6KfUQ46 -N9urr/IGyD76TJgXDCWyCStNnDFSi5T67yvHkIkdJsFw4FhFq7nKCiiSqHy0hvwl -LuCnBDA5Io+77xRdWKY1X9qdFxeEnp7nTPsk0k0+LH6Ty213wxyOPrIzTGtPYGaH -AmFbY4yQ2jEjR1D1IAhH7AjPAP6Ifszp+PdSlCX++nIOQ6JFNw0TKIcxhg5iQ+hS -5a76Nmf1R1/KwWTB2h1aP9GxbKnz08xba4zdkf8WOKXTY943i5Dy2mNZ149ha03N -oOsyzihPw0Spf2ckI4fSTfosXtugoFw8lzt8IKn0V9xk1xWdKGIqCsPXVg9e0YT3 -i/axJeQ6bEOUvUzMqmj20BxNZ+zwCRcFYJjaC9+L3DAmRpqKgZ9FAi+IHu+F2XS7 -sQ6rsFJap7L4fbYy4h05Yr8PAwekJVmw3wOM2Y6jbTa0X/rE/kcOq+eHKywB1zia -fwzGNfE1yDujucQ7gDkFUCHXl2s/5PKYyKf/YSxz5v3KNp4KSNSEM8zgru45xvJx -bNn1A0loW6/KdJVT5lnZ62sKgrd46Zd+8asruQWl0KMCK8t+B0GEuhTUraZd2Ynb -8yOFnjHfzVcaBaaj5IILw5uVGJ30+vtx7ewaeXF82ssiXjPGE7DMDjW4CQsG5PTk -upTmWm3zmZnvo/YCLfbzI/WjTnaIoF0vFpE2bIuB4L/BqP1nYlmmFreKmqs0YFoE -uLn/7xmbxmw3z6dEboRPPgf9Yx2i+lOJhmfxYjSL0pnnRkFEJWkgaogMaTBgU9p1 -aUvOQZy25SiTnjPagikHIGyQHbWfISAEG2hlpT1Au3pvowQrQ1YdfNHTklRSy32C -tA5EaR2AhZmrnSK9TqDREyayM0/g7ms7r7Ul0XbuZ0AJISkcpNvY64C6GCDrN/e4 -NG+bTh7ALAX7f9QSJns86DAI4n+bYzoFBwclTiQ5N6q05StJIimNkOplNAXpAD26 -H2d/Mz1JtfhHv9V9w0eM1d64Fcb8SqE2D8f+9m733JRPz8I7LdADq3nRBAwyrusO -6/D5tp85Bnt29aPspkJT6AYhPXql9mygg+fzjpnVzBZstkqBAALfgHelRfEyK3sp -6f2FvxHuHbS7/iSmdLkZ5HCo1A1U2UFocOhfSxnscghwjDaMoueR+Km034Xc9sCf -gXQoZyvcy86NssJvnmIPHF0PP+T3+8lxyl8wE8zWS4xUMPtChQLIZlqQP8iy0Jlo -O9FxMcvUnSCzFilbfihHd9VwFkOPcYoyhtyWtAEAhZz0qVjjchESO0D0hiJ9pAYI -QymW8hknE9mkKNvA+dv2t0EYdiEkUZxXJxpAp29c5A== +MIIJqzBVBgkqhkiG9w0BBQ0wSDAnBgkqhkiG9w0BBQwwGgQU4I8IE/YYU75bKRAC +IFTez1dC3OQCAggAMB0GCWCGSAFlAwQBKgQQjNio9EnwBf2SwaLGHoz4sASCCVCU +bCt2Yy8LyQxnkMa0IBx/TB8IsnEs6NnY1U9x52EP7rgwdLLP3qqb7Rh3rsWxQtZ0 +Xpi62QBNtiOb/y0eIifvwSl+g5GQwbimaH5JQXkdX7uecsjOpYI/KbDwKwUxtPSr +5nn8nZRR/ivd6C/iNWbbSs5xlZW9FNUouKgbcWsaDkGRHD6xs4TVSuMefYcVoDOD +ynOEHc3x1DK2Oc36VnFvW/DHJBvUZrTjiKI7WDaXcIVqAsPsCR/VtBuJNWOklMSS +ZAYtZlrODEWEaBokiZGHqBgieqJ4eq40JZJ6CMiAKbhBYbsGHhXJddQD8II1blHL +cr4VwtGtkVQ10n+/sFKyy0CkoveGPqi2osYhhIMYLH6r3W+cmDMTADtAOqtu/L87 +esM3OAGcy82L8O/iaXF8pS1vg+6wLQIWEpzJdRLoHzVsgu8oxSbsmBTGX8bHvVQz +Im4Wx1ofBgfawGjTAWKFQwa5BeN6DiMhgxLhfMtzUNvUfnoxhPKQiLfxvy0IVwkF +L3iabpkIUJS1qvPd8rZc8stpH5YumNy0rH5IbfG27VH/MBGjibNPMAgXU/eQrSBP +1ndVDkiTK1YdLMC0fOKIwaxHgJx6rWv613VrOMJMJ55wT6fGNr8hQSEqOI/zfD/N +1Hlmsmj8blE9rspUXekTShBCFb1x64E/a163V6DpSFFEmgSPJua81dneR/BF+IZX +AJIagH6gaIRiC7/DP0gVqQzIDXklXblvrZzkd52z2qif2MMTTuY+P/4MDEQXoOVi +jg28yUGQKkhOFviqJLRvJdpjOOZ6tWm9EKiogQbB7JfufS87ZAIczo1vCemGmJza +TJKHH0fvHHmoPVZBuRng4SRfZJPzj0HI5z8J87QNdeMAVoZDxuOfVYLNsyj1dUpk +IKw38AafPzMrIVP5/owkC09LQZwPWGJDX8ZBoV3qXTf2Y4klNbz18jSNkO6UwU6d +Qk4Kx5CGy/LKkeynIDSyJmbg3Mo4zyD16KCYxm/R4xDm615Xb65ofBQq+LyG1feW +5yraDCovTLAyLuY3e+1zJJqIMk5q4pAXezjM9zUWFeMLyKTJHlbDiAj+FJsDYHqN +VhcENiTn25zueoTelSce7bb5rKewfTIoIrx6EJGY3cka5+/cRxOyzS67iusA4JjA ++Uh3qNNvbaUsiei1snYdT2pNw8U5krmWjK1WKB6PDkq3OtalwBxuVkMKuu73aQSh +MghDP7lfcJNVBcRLHaqIMUKid3+jr6nw8yRVG9tCe5vC1HlUt2FLKP45lN1P6wzI +jnyn43jqCuzSkJlC1otu9SCZxaPuKzZX5gr/a2b2eLAPZ4LXY49w6egvlzYaS2Uu +TB8dPsCsGOthBflcrldijmk9M/xsFe2svffWP8gu9DMJKXuNxOoKR6oZIsicpcJG +lIqsKI+44V9P1YzjoeKndvX1bthWMYQftel9SKl91lQaayXoboU3Cv+DQDZHGlfC +7EIeE+U+66j1sxW1fkMx/ONb7qTyhIPvfypDcE6vSqgajxyXjCDU+R/EquZAxDwv +pDy+HCpHoLCJMG6r3hEVrElkGoS8ualEFiIHHxwbfVdbvRBMeWhvNnR3Pl6wLdYc +Bd+28jbckrGuFC5g62JgVSdUBnhqtrQveO9ia4s0Uxa88T6V/r7lIAzuzWM06/b6 +9Ab0NS/b3xDpucnrvkWJuWWZaeSKRtnHXZW4H2SqGId7uzQ3e5Oir/DhFO3MesTy +uRYaeqMX/Pa22tOhfO0Etu73KTjqg1x0gD9nucI8c+2j0cY7kupt0SQ7Hd/sH0jn +9gRx0z/8ORL7F1LvgemxohFJkPbwFDfMikNhMnP83+oEz1sxUVtgF+p6oYJazlrq +FbnjPZdG7mtdmD/6w5gBlcgnRp+AfzfaXxyIs+p812KC5hq4XpDwiFwMtxNaSKDe +vj3fqhRhNrVSOTnGA0CiM4WBYsnxZzMuR3EpDYgPmWLSVEoc8cGbzOFO8Pcu5nSn +Qr5kiPkurazyMGaabgi5qLHuJvhj9tB+bzih6M9MWS0OQvj9jTGfsICT7xkd2px7 +bxBiVQlPVZqiGRCpW/FQTXm1zkGP360yPp60LlxQs+2+zJICCdmKG705rwrL4+p2 +nJazyBizcf2N6HmQVilYqmLsSpdt1FF1WP9JQEG5+rUtHA/LeNXP35ouhrOjmqch +GAC84aWPiX76WHboj7wxBlTZL5D1UleFO77N8qzvSCJDhUXKiWa+0ju7V3G8ZbHV +rvPCdSFvYFFc7h6bMbrVflBhbao/y3bX6IvHfwBuo39iMCTHbXy1L92h5e8FjUlU +4D7BRtqbgNgHjkrEPtq3MC7rGMH2YWlugaOvfzP3smG5QMbVr2ucgjR11eQ1Cw3A +LAjSvbAoNLl+n99ZPpPnJOZnGvZtmC2T7Rs6dfXmDoAge/gFWUx9xn+hIvR0mT+a ++8zbQR41qkx7t11U82GdpP+F0bmyCGl6BttQA7f+wgzUSdBWv+NDPi4fxcGKwSHZ +/2oF/1gQGdHFALt2kfu1nWI+etefztNcF2RgdbI9HlqNf/h6Hn1CJ/gXeUpNnV4/ +f03ElWKJ+zFPrHoFbYO5ZGYOux2ZgQNesgIOlaZN0jgbv/gOdbr0TGHjwqUpuNqh +sI9f7e4fncCYflpCPFtRRCZSlVyjHGCBaRVXug3xWqe6M19rLTayHZ7D33oJlI0V +ELxQKj0CL2/o0EmkHQWCgUDYVGoKuAm6IZZjHy53vpSNz1zAoLU21gQSg4ts6PXr +Hl6TOQjpTVfOtM4MbLbqkJFebyH2sOY2Qd2yLOHm7vH/7mmceot8Y3j3a9H6jLJ9 +LDe3c75y8nHkz7pKXMwvPnFng9N7l0nVgW/SFLrKs5HGWkhdgJEdIGPEZn4tKuYI +Uy9AUPNhW4A8h3rxX+8Hk2jhDgV7WncANMCYsgxy2f7a/lx0SjBXvRDxECDaHDQ4 +lS1tqVuj26Mb5eU1YNDEUQ83zC9mP7kgcWowHf2WSS+/PByuzaZqnIbdJAzx7rfJ +MCEQkXr33PZDLpFCPcnxKIKmKGf8iTtcIsh6l+7+GvccEcoKlOHEcy2iOLY5j8HL +ilK9DJ1nSTR8EOGkPqNdpjK/1z6ZL+qrs0+rCwrXBpJLcodtN7fcMf7YetFVXIIx +4ol0/nBcXC4/ePHSuoJtkQ4khBa3Ifw3VPBphx8Kyg== -----END ENCRYPTED PRIVATE KEY----- diff --git a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/auth/var/opt/keys/own/agov-ident-signer-keystore/keystore.pem b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/auth/var/opt/keys/own/agov-ident-signer-keystore/keystore.pem index a649288..37b8ca2 100644 --- a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/auth/var/opt/keys/own/agov-ident-signer-keystore/keystore.pem +++ b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/auth/var/opt/keys/own/agov-ident-signer-keystore/keystore.pem @@ -1,56 +1,56 @@ -----BEGIN ENCRYPTED PRIVATE KEY----- -MIIJqzBVBgkqhkiG9w0BBQ0wSDAnBgkqhkiG9w0BBQwwGgQUuj8UNQmLKEwOD3Ij -gjT2bC1IgOUCAggAMB0GCWCGSAFlAwQBKgQQilo/zrSzyfj+eUjtGegooASCCVBn -3gQUmNY8CiejjthSXhpxCfVdX4P0lyhQ1Y7Q4wGhxVNTRNQoAJoUx6rnvhO+bLyp -/cW5OkIu212YrSaF9Yr+H06k6v8fMMeDEqLCrAT54HjtNqKP3NerBT0bQHs+ZHI7 -CK92SyxDlwVXzmLBei2vTnclud93AwFXlnY1HEmt6nOIzzZYOZOrJJARoUfnsdEP -q0c27EhJ4crY6V4Ld+fhudOo7pPGchDOwagEXIjmi/rLnk3ZPo9vUE5TZh85bcv6 -ggAoOKXR6nBVSykdUvwjBSQgkZj13WRSoutWOILxHer98qql3OhstFbmn0OPqabx -C3XL9Xh2iycWNWUFRoRb/b+g6asJrTKNmbq9h1v/iFr2s2dC8bHK3IXRuV0sTGyT -m3iUQOjFN1e1/kAcCu4a7qZwKk0athIPsEX89nkP0TV8TyGKRjP7jyECiTt4AwyE -b/I/gbJs8d6zACPkslXJmLmPUhxwwHBRw8Ayk83xvAtjGJAGMNqa2DjjTGE40jnJ -2/Mmq9uIK1tf7TBF7cp5SJrEpd+c+eq+nx2tgGhYfj3TrlG0LLi2kW/QVcYlJyVE -hDxA/PDQQ9ykuwwHGtmgykjEpxqhIlkzrsFfuShRw9KcwFwLaAWDzECzMjzwdCux -z3U4HYWMuSUgvwF/ek40yvw40DLPOz9l6WgFRwdtr2t7wPLu/g3KkyRp0SXL5Wf2 -8cyMQ/CZhm10aSzOqFda9c2rFKZ+ICfPg96NGJ9y2lMm7aKVXywxlk42u8wfkG6B -Q0vRUNhmhED+SC+aDmxUpwmG5WCX5SJVvt3e9VRBDxZzHVEqTgtOqN8XgFDpoLg8 -nis2Gz3VEpV2Ex1N4mgVNRSp8qIkB+SXm8aFi0s4XFAc4MBVDaW5orS8ucgxoX1m -SGa16/EwnP68rQou5bWlApe6TdmxFPGKiQgEb9eHLXy9Ye8wsUo85iDcLUGmiK9k -A9OnE5+essvEKEP0UPkSvML/uf5kaLWNb6lmWmZ9LZd9XuvrAwY+4jH+03OxWEwB -UBuEWCrkkYqYubMh6avkZQl/nG0I2nJx1lz7XOaWgXXaHm6w6kqQdfBvpzr6MUXy -gJKFKaCydI/z+Hb/HRsxQLBTXo/BdTGCYbakiQQbXEKmhrrrHuXUb273kJpmKAWu -s0147rjEPnZlZjsnKctILUOrUctkB8E53yXLx4mp4ptxOtbb/FgOxdUIo9iQ5/sZ -5o2whxjHIXn/jCGXUbdZXmAJ7fG9WY6WHBlcJrJuKJt3duu8OqJ45IZA6kkZLvCm -eR4tFSJWqvHfxLrzznHLzENOgB2A4Syvrzvbi9nBWWavS6dtqnBpVCr4FbchpZEM -N+ljYY3SJ7iX2a0mPpQ5llOfhC3yqrG71aaPLxcuFAY1g/YX/SWRTT3yMds/XZAh -Cd3iCR48Y+NZXQdnnTTyGpe3O+pxZbzxTeRcq7OKETKM/KJaISynEveccTvR1Jh0 -7oHr+SxqmzFA3McupLvupv81ERT3kXe6h+5KlIdawwxW30gsIgFpx4XhpYQeBEPC -j/zH+ivBXJRs5+H4KGdTPJCRmXbSVmbCDPedrQOLNHY+rj79PhsV3Ut4s5+EHNiV -269FL0q3MdrPnZfbQSno2HCrOBoixVfFh7Kk+gEAL575NZPvhmkYdtS/ysYlR4yJ -Y6Zwl6IUV/bAu1hTg9vSZsxDId0mrmiJ9U6ovWrIzXHif1asLoHX1oxQHTJq0T9o -boLodekjlXswfXHckQyPwa3fDa0MnGb5ZN1vOo0X+DvmwthNKwhAuUULrTYqSJPQ -zGziNz1aEntO+2W6p+ZiHC0sUl3slVWS13borTLCs1GxyF3THctwCisfs6KfUQ46 -N9urr/IGyD76TJgXDCWyCStNnDFSi5T67yvHkIkdJsFw4FhFq7nKCiiSqHy0hvwl -LuCnBDA5Io+77xRdWKY1X9qdFxeEnp7nTPsk0k0+LH6Ty213wxyOPrIzTGtPYGaH -AmFbY4yQ2jEjR1D1IAhH7AjPAP6Ifszp+PdSlCX++nIOQ6JFNw0TKIcxhg5iQ+hS -5a76Nmf1R1/KwWTB2h1aP9GxbKnz08xba4zdkf8WOKXTY943i5Dy2mNZ149ha03N -oOsyzihPw0Spf2ckI4fSTfosXtugoFw8lzt8IKn0V9xk1xWdKGIqCsPXVg9e0YT3 -i/axJeQ6bEOUvUzMqmj20BxNZ+zwCRcFYJjaC9+L3DAmRpqKgZ9FAi+IHu+F2XS7 -sQ6rsFJap7L4fbYy4h05Yr8PAwekJVmw3wOM2Y6jbTa0X/rE/kcOq+eHKywB1zia -fwzGNfE1yDujucQ7gDkFUCHXl2s/5PKYyKf/YSxz5v3KNp4KSNSEM8zgru45xvJx -bNn1A0loW6/KdJVT5lnZ62sKgrd46Zd+8asruQWl0KMCK8t+B0GEuhTUraZd2Ynb -8yOFnjHfzVcaBaaj5IILw5uVGJ30+vtx7ewaeXF82ssiXjPGE7DMDjW4CQsG5PTk -upTmWm3zmZnvo/YCLfbzI/WjTnaIoF0vFpE2bIuB4L/BqP1nYlmmFreKmqs0YFoE -uLn/7xmbxmw3z6dEboRPPgf9Yx2i+lOJhmfxYjSL0pnnRkFEJWkgaogMaTBgU9p1 -aUvOQZy25SiTnjPagikHIGyQHbWfISAEG2hlpT1Au3pvowQrQ1YdfNHTklRSy32C -tA5EaR2AhZmrnSK9TqDREyayM0/g7ms7r7Ul0XbuZ0AJISkcpNvY64C6GCDrN/e4 -NG+bTh7ALAX7f9QSJns86DAI4n+bYzoFBwclTiQ5N6q05StJIimNkOplNAXpAD26 -H2d/Mz1JtfhHv9V9w0eM1d64Fcb8SqE2D8f+9m733JRPz8I7LdADq3nRBAwyrusO -6/D5tp85Bnt29aPspkJT6AYhPXql9mygg+fzjpnVzBZstkqBAALfgHelRfEyK3sp -6f2FvxHuHbS7/iSmdLkZ5HCo1A1U2UFocOhfSxnscghwjDaMoueR+Km034Xc9sCf -gXQoZyvcy86NssJvnmIPHF0PP+T3+8lxyl8wE8zWS4xUMPtChQLIZlqQP8iy0Jlo -O9FxMcvUnSCzFilbfihHd9VwFkOPcYoyhtyWtAEAhZz0qVjjchESO0D0hiJ9pAYI -QymW8hknE9mkKNvA+dv2t0EYdiEkUZxXJxpAp29c5A== +MIIJqzBVBgkqhkiG9w0BBQ0wSDAnBgkqhkiG9w0BBQwwGgQU4I8IE/YYU75bKRAC +IFTez1dC3OQCAggAMB0GCWCGSAFlAwQBKgQQjNio9EnwBf2SwaLGHoz4sASCCVCU +bCt2Yy8LyQxnkMa0IBx/TB8IsnEs6NnY1U9x52EP7rgwdLLP3qqb7Rh3rsWxQtZ0 +Xpi62QBNtiOb/y0eIifvwSl+g5GQwbimaH5JQXkdX7uecsjOpYI/KbDwKwUxtPSr +5nn8nZRR/ivd6C/iNWbbSs5xlZW9FNUouKgbcWsaDkGRHD6xs4TVSuMefYcVoDOD +ynOEHc3x1DK2Oc36VnFvW/DHJBvUZrTjiKI7WDaXcIVqAsPsCR/VtBuJNWOklMSS +ZAYtZlrODEWEaBokiZGHqBgieqJ4eq40JZJ6CMiAKbhBYbsGHhXJddQD8II1blHL +cr4VwtGtkVQ10n+/sFKyy0CkoveGPqi2osYhhIMYLH6r3W+cmDMTADtAOqtu/L87 +esM3OAGcy82L8O/iaXF8pS1vg+6wLQIWEpzJdRLoHzVsgu8oxSbsmBTGX8bHvVQz +Im4Wx1ofBgfawGjTAWKFQwa5BeN6DiMhgxLhfMtzUNvUfnoxhPKQiLfxvy0IVwkF +L3iabpkIUJS1qvPd8rZc8stpH5YumNy0rH5IbfG27VH/MBGjibNPMAgXU/eQrSBP +1ndVDkiTK1YdLMC0fOKIwaxHgJx6rWv613VrOMJMJ55wT6fGNr8hQSEqOI/zfD/N +1Hlmsmj8blE9rspUXekTShBCFb1x64E/a163V6DpSFFEmgSPJua81dneR/BF+IZX +AJIagH6gaIRiC7/DP0gVqQzIDXklXblvrZzkd52z2qif2MMTTuY+P/4MDEQXoOVi +jg28yUGQKkhOFviqJLRvJdpjOOZ6tWm9EKiogQbB7JfufS87ZAIczo1vCemGmJza +TJKHH0fvHHmoPVZBuRng4SRfZJPzj0HI5z8J87QNdeMAVoZDxuOfVYLNsyj1dUpk +IKw38AafPzMrIVP5/owkC09LQZwPWGJDX8ZBoV3qXTf2Y4klNbz18jSNkO6UwU6d +Qk4Kx5CGy/LKkeynIDSyJmbg3Mo4zyD16KCYxm/R4xDm615Xb65ofBQq+LyG1feW +5yraDCovTLAyLuY3e+1zJJqIMk5q4pAXezjM9zUWFeMLyKTJHlbDiAj+FJsDYHqN +VhcENiTn25zueoTelSce7bb5rKewfTIoIrx6EJGY3cka5+/cRxOyzS67iusA4JjA ++Uh3qNNvbaUsiei1snYdT2pNw8U5krmWjK1WKB6PDkq3OtalwBxuVkMKuu73aQSh +MghDP7lfcJNVBcRLHaqIMUKid3+jr6nw8yRVG9tCe5vC1HlUt2FLKP45lN1P6wzI +jnyn43jqCuzSkJlC1otu9SCZxaPuKzZX5gr/a2b2eLAPZ4LXY49w6egvlzYaS2Uu +TB8dPsCsGOthBflcrldijmk9M/xsFe2svffWP8gu9DMJKXuNxOoKR6oZIsicpcJG +lIqsKI+44V9P1YzjoeKndvX1bthWMYQftel9SKl91lQaayXoboU3Cv+DQDZHGlfC +7EIeE+U+66j1sxW1fkMx/ONb7qTyhIPvfypDcE6vSqgajxyXjCDU+R/EquZAxDwv +pDy+HCpHoLCJMG6r3hEVrElkGoS8ualEFiIHHxwbfVdbvRBMeWhvNnR3Pl6wLdYc +Bd+28jbckrGuFC5g62JgVSdUBnhqtrQveO9ia4s0Uxa88T6V/r7lIAzuzWM06/b6 +9Ab0NS/b3xDpucnrvkWJuWWZaeSKRtnHXZW4H2SqGId7uzQ3e5Oir/DhFO3MesTy +uRYaeqMX/Pa22tOhfO0Etu73KTjqg1x0gD9nucI8c+2j0cY7kupt0SQ7Hd/sH0jn +9gRx0z/8ORL7F1LvgemxohFJkPbwFDfMikNhMnP83+oEz1sxUVtgF+p6oYJazlrq +FbnjPZdG7mtdmD/6w5gBlcgnRp+AfzfaXxyIs+p812KC5hq4XpDwiFwMtxNaSKDe +vj3fqhRhNrVSOTnGA0CiM4WBYsnxZzMuR3EpDYgPmWLSVEoc8cGbzOFO8Pcu5nSn +Qr5kiPkurazyMGaabgi5qLHuJvhj9tB+bzih6M9MWS0OQvj9jTGfsICT7xkd2px7 +bxBiVQlPVZqiGRCpW/FQTXm1zkGP360yPp60LlxQs+2+zJICCdmKG705rwrL4+p2 +nJazyBizcf2N6HmQVilYqmLsSpdt1FF1WP9JQEG5+rUtHA/LeNXP35ouhrOjmqch +GAC84aWPiX76WHboj7wxBlTZL5D1UleFO77N8qzvSCJDhUXKiWa+0ju7V3G8ZbHV +rvPCdSFvYFFc7h6bMbrVflBhbao/y3bX6IvHfwBuo39iMCTHbXy1L92h5e8FjUlU +4D7BRtqbgNgHjkrEPtq3MC7rGMH2YWlugaOvfzP3smG5QMbVr2ucgjR11eQ1Cw3A +LAjSvbAoNLl+n99ZPpPnJOZnGvZtmC2T7Rs6dfXmDoAge/gFWUx9xn+hIvR0mT+a ++8zbQR41qkx7t11U82GdpP+F0bmyCGl6BttQA7f+wgzUSdBWv+NDPi4fxcGKwSHZ +/2oF/1gQGdHFALt2kfu1nWI+etefztNcF2RgdbI9HlqNf/h6Hn1CJ/gXeUpNnV4/ +f03ElWKJ+zFPrHoFbYO5ZGYOux2ZgQNesgIOlaZN0jgbv/gOdbr0TGHjwqUpuNqh +sI9f7e4fncCYflpCPFtRRCZSlVyjHGCBaRVXug3xWqe6M19rLTayHZ7D33oJlI0V +ELxQKj0CL2/o0EmkHQWCgUDYVGoKuAm6IZZjHy53vpSNz1zAoLU21gQSg4ts6PXr +Hl6TOQjpTVfOtM4MbLbqkJFebyH2sOY2Qd2yLOHm7vH/7mmceot8Y3j3a9H6jLJ9 +LDe3c75y8nHkz7pKXMwvPnFng9N7l0nVgW/SFLrKs5HGWkhdgJEdIGPEZn4tKuYI +Uy9AUPNhW4A8h3rxX+8Hk2jhDgV7WncANMCYsgxy2f7a/lx0SjBXvRDxECDaHDQ4 +lS1tqVuj26Mb5eU1YNDEUQ83zC9mP7kgcWowHf2WSS+/PByuzaZqnIbdJAzx7rfJ +MCEQkXr33PZDLpFCPcnxKIKmKGf8iTtcIsh6l+7+GvccEcoKlOHEcy2iOLY5j8HL +ilK9DJ1nSTR8EOGkPqNdpjK/1z6ZL+qrs0+rCwrXBpJLcodtN7fcMf7YetFVXIIx +4ol0/nBcXC4/ePHSuoJtkQ4khBa3Ifw3VPBphx8Kyg== -----END ENCRYPTED PRIVATE KEY----- -----BEGIN CERTIFICATE----- diff --git a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/etc/nevis/k8s-operations-nevisproxy-instance-bd83dfbd467e8211ffe71d28.yaml b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/etc/nevis/k8s-operations-nevisproxy-instance-bd83dfbd467e8211ffe71d28.yaml index 438f380..9779042 100644 --- a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/etc/nevis/k8s-operations-nevisproxy-instance-bd83dfbd467e8211ffe71d28.yaml +++ b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/etc/nevis/k8s-operations-nevisproxy-instance-bd83dfbd467e8211ffe71d28.yaml @@ -46,7 +46,7 @@ spec: podDisruptionBudget: maxUnavailable: "50%" git: - tag: "r-ffccb0ac6d5831789f198ab73f0ecfff9ea38df7" + tag: "r-153c4f15e7495a3864d7ae40ed58b6b28b543733" dir: "DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp" credentials: "git-credentials" keystores: diff --git a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/security_nevismeta_web_console.conf b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/security_nevismeta_web_console.conf new file mode 100644 index 0000000..792db8e --- /dev/null +++ b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/security_nevismeta_web_console.conf @@ -0,0 +1,18 @@ +# load modsecurity +Include /var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/modsecurity.conf + +# apply whitelist modifications - must be done before loading other rules (replaces REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf) +SecRule REQUEST_URI "@beginsWith /nevismeta/index.xhtml" "pass,nolog,id:500004,ctl:ruleRemoveById=200004 + +# apply application-specific paranoia level +SecAction "id:900000,phase:1,nolog,pass,t:none,setvar:tx.paranoia_level=1" + +# load the rule set of the virtual host +Include /var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/rules.conf + +# apply rule exceptions (replaces RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf) + + +# set mode +SecRuleEngine On + diff --git a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/web.xml b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/web.xml index 6c35659..0b661f6 100644 --- a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/web.xml +++ b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/web.xml @@ -146,6 +146,21 @@ replacement + + + CSRFRewrite_nevisMeta_Web_Console + ch::nevis::isiweb4::filter::rewrite::RewriteFilter + + + ResponseBody + PCRE/(if\s?\(isValidDomain\(document.domain,).*$/:$1(function(h) { var i = h.indexOf("\:"); return h.substring(0, i != -1 ? i \: h.length) })("ENV\:HTTP_Host;"))) {:PT + + + + ResponseBody.Mode + replacement + + DefaultErrorFilter @@ -263,6 +278,16 @@ /var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/security_nevisidm_operations_administration_gui.conf + + + ModSecurity_nevisMeta_Web_Console + ch::nevis::nevisproxy::filter::modsecurity::ModsecurityFilter + + + ConfigFile + /var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/security_nevismeta_web_console.conf + + Redirect_Default @@ -595,6 +620,11 @@ /nevisidm/* + + SessionHandler_SAML_SP_nevisidm_operations_Realm + /nevismeta/* + + SAML_AllowCORS_SAML_SP_nevisidm_operations_Realm /SAML2/ACS/* @@ -614,6 +644,11 @@ ModSecurity_nevisIDM_Operations_Administration_GUI /nevisidm/admin/* + + + ModSecurity_nevisMeta_Web_Console + /nevismeta/* + ModSecurity_OP-ONBRDNG-ModSecuritySettings @@ -630,6 +665,11 @@ /nevisidm/* + + Authentication_SAML_SP_nevisidm_operations_Realm + /nevismeta/* + + SAML_SAML_SP_nevisidm_operations_Realm /SAML2/ACS/* @@ -649,6 +689,11 @@ Requirement_NEVIS_SecToken_SAML_SP_nevisidm_operations_Realm /nevisidm/* + + + Requirement_NEVIS_SecToken_SAML_SP_nevisidm_operations_Realm + /nevismeta/* + Authorization_Required_Roles_AGOV-Loi.level300_AGOV-Loi.level400_AGOV-Loi.level500_SAML_SP_nevisidm_operations_Realm @@ -659,11 +704,21 @@ Token_NEVIS_SecToken /nevisidm/* + + + Token_NEVIS_SecToken + /nevismeta/* + CSRFRewrite_nevisIDM_Operations_Administration_GUI /nevisidm/JavaScriptServlet + + + CSRFRewrite_nevisMeta_Web_Console + /nevismeta/JavaScriptServlet + ch::nevis::isiweb4::listener::SessionListener @@ -847,6 +902,42 @@ true + + + Connector_nevisMeta_Web_Console + + ch::nevis::isiweb4::servlet::connector::http::HttpsConnectorServlet + + + AllowedMethods + ALL-HTTP,ALL-WEBDAV,-TRACE,-CONNECT + + + + AutoRewrite + header + + + + CookieManager + retain:^.*$ + + + + InetAddress + agov-w.azure.adnovum.net-web.adn-agov-mobile-01-uat:8996 + + + + ResourceManager.RetryTimeout + 0 + + + + UseSSL + true + + Hosting_Default @@ -947,6 +1038,12 @@ NevisLogrendConnector_nevisLogrend /nevislogrend/* + + + Connector_nevisMeta_Web_Console + /nevismeta/* + /nevismeta/rest/.* + Hosting_Default /*