diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-6ec6739e824c8e56d9633622.yaml b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-6ec6739e824c8e56d9633622.yaml index fdbd1e4..ace3213 100644 --- a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-6ec6739e824c8e56d9633622.yaml +++ b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-6ec6739e824c8e56d9633622.yaml @@ -45,11 +45,10 @@ spec: podDisruptionBudget: maxUnavailable: "50%" git: - tag: "r-bc24fc84643c9386aa8dd06d4216e6c125b244e5" + tag: "r-3357c2abd09c33f401a7d1a0d44c03d1e5b5c5e0" dir: "DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai" credentials: "git-credentials" keystores: - - "nai-sh4r3d-keystore-proxy-auth" - "nai-default-identity" - "nai-sh4r3d-default-default-signer" truststores: diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-sh4r3d-keystore-proxy-auth-6ec6739e824c8e56d9633622.yaml b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-sh4r3d-keystore-proxy-auth-6ec6739e824c8e56d9633622.yaml deleted file mode 100644 index fee9f43..0000000 --- a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-sh4r3d-keystore-proxy-auth-6ec6739e824c8e56d9633622.yaml +++ /dev/null @@ -1,18 +0,0 @@ -apiVersion: "operator.nevis-security.ch/v1" -kind: "NevisKeyStore" -metadata: - name: "nai-sh4r3d-keystore-proxy-auth" - namespace: "adn-postit-tknxchng-01-dev" - labels: - deploymentTarget: "nai" - annotations: - projectKey: "DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT" - patternId: "6ec6739e824c8e56d9633622" -spec: - cn: "New_OAuth_2.0_Authorization_Server_OpenID_Provider-signer" - usage: "signer" - san: - dns: - - "nai" - - "nai.adn-postit-tknxchng-01-dev" - email: [] diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/conf/esauth4.xml b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/conf/esauth4.xml index 2a04c66..426a227 100644 --- a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/conf/esauth4.xml +++ b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/conf/esauth4.xml @@ -42,11 +42,6 @@ - - - - - @@ -55,11 +50,7 @@ - - - - @@ -109,114 +100,6 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - @@ -228,7 +111,7 @@ - + @@ -237,37 +120,6 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/plugin/cossa-token-exchange-authstates.jar b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/plugin/cossa-token-exchange-authstates.jar index a06c73f..3690fdc 100644 Binary files a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/plugin/cossa-token-exchange-authstates.jar and b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/plugin/cossa-token-exchange-authstates.jar differ diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/etc/nevis/k8s-npi-92e282d1dc2b69d9e4f91fc0.yaml b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/etc/nevis/k8s-npi-92e282d1dc2b69d9e4f91fc0.yaml index a78d87c..961d957 100644 --- a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/etc/nevis/k8s-npi-92e282d1dc2b69d9e4f91fc0.yaml +++ b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/etc/nevis/k8s-npi-92e282d1dc2b69d9e4f91fc0.yaml @@ -46,7 +46,7 @@ spec: podDisruptionBudget: maxUnavailable: "50%" git: - tag: "r-a6580914174774342b195a78256c5958db82987f" + tag: "r-3357c2abd09c33f401a7d1a0d44c03d1e5b5c5e0" dir: "DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi" credentials: "git-credentials" keystores: diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/var/opt/nevisproxy/default/host-klp.agov-w.azure.adnovum.net/WEB-INF/web.xml b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/var/opt/nevisproxy/default/host-klp.agov-w.azure.adnovum.net/WEB-INF/web.xml index d2286f4..55f3109 100644 --- a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/var/opt/nevisproxy/default/host-klp.agov-w.azure.adnovum.net/WEB-INF/web.xml +++ b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/var/opt/nevisproxy/default/host-klp.agov-w.azure.adnovum.net/WEB-INF/web.xml @@ -6,66 +6,6 @@ SectokenVerifierCert /var/opt/keys/trust/npi-mockrelam-signer-trust/truststore.pem - - - AuthenticationService_MockRelam - ch::nevis::isiweb4::filter::auth::IdentityCreationFilter - - - AuthenticationServlet - Connector_MockRelam - - - - BodyReadSize - 32768 - - - - EntryPointID - klp.agov-w.azure.adnovum.net - - - - InactiveInterval - 7200 - - - - InterceptionRedirect - never - - - - LoginRendererServlet - LoginRenderer_nli - - - - Realm - MockRelam - - - - RecheckAuthentication - On - - - - RenewIdentification - true - - - - StateKey - MockRelam - - - - StoreInterceptedRequest - false - - Authentication_MockRelam @@ -139,33 +79,6 @@ - - - OAuth_Preflighted_CORS_New OAuth 2.0 Authorization Server / OpenID Provider - ch::nevis::isiweb4::filter::lua::LuaFilter - - - Script - - function inputHeader(request, response) - response:setHeader("Access-Control-Allow-Origin", "*") - response:setHeader("Access-Control-Allow-Credentials", "true") - response:setHeader("Access-Control-Allow-Methods", "GET, POST, PUT, OPTIONS") - response:setHeader("Access-Control-Allow-Headers", "Authorization") - response:setHeader("Access-Control-Expose-Headers", "*") - response:setHeader("Access-Control-Max-Age", "600") - if request:getMethod() == "OPTIONS" then - response:send(204) - end - end - - - - - Script.InputHeaderFunctionName - inputHeader - - ResponseHeader_Default @@ -239,43 +152,13 @@ SessionHandler_MockRelam /* - ^/asdf/.*$|^/errorpages.*$|^/favicon.ico$|^/hallo.txt$|^/index.html$|^/nevislogrend/.*$|^/qwert/.*$|^/resources.*$ - - - - SessionHandler_MockRelam - /asdf/* - - - - SessionHandler_MockRelam - /qwert/* - - - - OAuth_Preflighted_CORS_New OAuth 2.0 Authorization Server / OpenID Provider - /asdf/* - - - - OAuth_Preflighted_CORS_New OAuth 2.0 Authorization Server / OpenID Provider - /qwert/* + ^/errorpages.*$|^/favicon.ico$|^/hallo.txt$|^/index.html$|^/nevislogrend/.*$|^/resources.*$ Authentication_MockRelam /* - ^/asdf/.*$|^/errorpages.*$|^/favicon.ico$|^/hallo.txt$|^/index.html$|^/nevislogrend/.*$|^/qwert/.*$|^/resources.*$ - - - - AuthenticationService_MockRelam - /asdf/* - - - - AuthenticationService_MockRelam - /qwert/* + ^/errorpages.*$|^/favicon.ico$|^/hallo.txt$|^/index.html$|^/nevislogrend/.*$|^/resources.*$ @@ -332,12 +215,6 @@ /var/opt/keys/own/npi-mockrelam-identity/key.pem - - - Hosting_Default - - ch::nevis::isiweb4::servlet::defaults::DefaultServlet - Hosting_New_Hosting_Service @@ -417,26 +294,20 @@ /nevislogrend + + Hosting_Default + ch::nevis::isiweb4::servlet::defaults::DefaultServlet + Hosting_New_Hosting_Service /* - - - Hosting_Default - /asdf/* - NevisLogrendConnector_nli /nevislogrend/* - - - Hosting_Default - /qwert/* - Hosting_Default /index.html