From e563ca2f0f7e733736b78fe9e710572f659007e9 Mon Sep 17 00:00:00 2001 From: haburger Date: Wed, 30 Oct 2024 16:40:17 +0000 Subject: [PATCH] new configuration version --- ...oxy-instance-bd83dfbd467e8211ffe71d28.yaml | 2 +- .../WEB-INF/security_artreporting.conf | 18 ---- .../WEB-INF/web.xml | 90 +------------------ 3 files changed, 3 insertions(+), 107 deletions(-) delete mode 100644 DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/security_artreporting.conf diff --git a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/etc/nevis/k8s-operations-nevisproxy-instance-bd83dfbd467e8211ffe71d28.yaml b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/etc/nevis/k8s-operations-nevisproxy-instance-bd83dfbd467e8211ffe71d28.yaml index 7ca12a5..cb9f621 100644 --- a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/etc/nevis/k8s-operations-nevisproxy-instance-bd83dfbd467e8211ffe71d28.yaml +++ b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/etc/nevis/k8s-operations-nevisproxy-instance-bd83dfbd467e8211ffe71d28.yaml @@ -46,7 +46,7 @@ spec: podDisruptionBudget: maxUnavailable: "50%" git: - tag: "r-58fcf0ca3e3e5b189ec00c971320c3f2a1b493b0" + tag: "r-3341a3df2b54ab6368125d7df7c223019a1fb969" dir: "DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp" credentials: "git-credentials" keystores: diff --git a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/security_artreporting.conf b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/security_artreporting.conf deleted file mode 100644 index 992d95a..0000000 --- a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/security_artreporting.conf +++ /dev/null @@ -1,18 +0,0 @@ -# load modsecurity -Include /var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/modsecurity.conf - -# apply whitelist modifications - must be done before loading other rules (replaces REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf) - - -# apply application-specific paranoia level -SecAction "id:900000,phase:1,nolog,pass,t:none,setvar:tx.paranoia_level=1" - -# load the rule set of the virtual host -Include /var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/rules.conf - -# apply rule exceptions (replaces RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf) - - -# set mode -SecRuleEngine DetectionOnly - diff --git a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/web.xml b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/web.xml index 6fc8797..c753b92 100644 --- a/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/web.xml +++ b/DEFAULT-ADN-AGOV-ADMIN-PROJECT/DEFAULT-ADN-AGOV-ADMIN-INV/proxy-sp/var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/web.xml @@ -131,21 +131,6 @@ nevisIdm.Root - - - Authorization_Required_Roles_AGOV-Art.Access_SAML_SP_nevisidm_operations_Realm - ch::nevis::isiweb4::filter::auth::SecurityRoleFilter - - - DynamicRoleAcquire - false - - - - RolesRequired - AGOV-Art.Access - - Authorization_Required_Roles_nevisIdm.Helpdesk_nevisIdm.TemplateAdmin_nevisIdm.UserAndUnitAdmin_nevisIdm.AppAdmin_nevisIdm.UserAdmin_nevisIdm.AppOwner_nevisIdm.EnterpriseRoleAdmin_nevisIdm.ClientRoot_SAML_SP_nevisidm_operations_Realm @@ -220,16 +205,6 @@ - - - ModSecurity_ArtReporting - ch::nevis::nevisproxy::filter::modsecurity::ModsecurityFilter - - - ConfigFile - /var/opt/nevisproxy/default/host-op.agov-w.azure.adnovum.net/WEB-INF/security_artreporting.conf - - ModSecurity_GreenMail @@ -600,7 +575,7 @@ SessionHandler_SAML_SP_nevisidm_operations_Realm - /art/* + /mail/* @@ -613,11 +588,6 @@ /SAML2/stepup/* - - SessionHandler_SAML_SP_nevisidm_operations_Realm - /mail/* - - SessionHandler_SAML_SP_nevisidm_operations_Realm /nevisidm/* @@ -643,11 +613,6 @@ SessionHandler_OP-ONBRDNG-AuthenticationRealm /AUTH/ONBOARDING/* - - - ModSecurity_ArtReporting - /art/* - ModSecurity_GreenMail @@ -686,11 +651,6 @@ ^/canary/api/.*$ - - Authentication_SAML_SP_nevisidm_operations_Realm - /art/* - - Authentication_SAML_SP_nevisidm_operations_Realm /mail/* @@ -731,11 +691,6 @@ Requirement_NEVIS_SecToken_SAML_SP_nevisidm_operations_Realm /nevisidm/* - - - Authorization_Required_Roles_AGOV-Art.Access_SAML_SP_nevisidm_operations_Realm - /art/* - Authorization_Required_Roles_nevisIdm.Helpdesk_nevisIdm.TemplateAdmin_nevisIdm.UserAndUnitAdmin_nevisIdm.AppAdmin_nevisIdm.UserAdmin_nevisIdm.AppOwner_nevisIdm.EnterpriseRoleAdmin_nevisIdm.ClientRoot_SAML_SP_nevisidm_operations_Realm @@ -760,42 +715,6 @@ ch::nevis::isiweb4::listener::SessionListener - - - Connector_ArtReporting - - ch::nevis::isiweb4::servlet::connector::http::HttpsConnectorServlet - - - AllowedMethods - ALL-HTTP,ALL-WEBDAV,-TRACE,-CONNECT - - - - AutoRewrite - header - - - - CookieManager - retain:^.*$ - - - - DNSCache.ttl - 60 - - - - InetAddress - art-report-server.adn-agov-connect-01-dev:8080 - - - - UseSSL - false - - Connector_GreenMail @@ -824,7 +743,7 @@ InetAddress - rainloop.adn-agov-mail-01-dev:80 + rainloop.adn-agov-mail-01-uat:80 @@ -1131,11 +1050,6 @@ Hosting_Default /SAML2/stepup/* - - - Connector_ArtReporting - /art/* - Connector_Web_Application_canaryPage_frontend