From 4956b48ff0e26449d5d45d5f5e68a0ac36e58bdf Mon Sep 17 00:00:00 2001 From: mamo Date: Mon, 11 Nov 2024 10:18:36 +0000 Subject: [PATCH] new configuration version --- .../k8s-nai-6ec6739e824c8e56d9633622.yaml | 2 +- .../opt/nevisauth/default/conf/esauth4.xml | 155 +++++++- .../k8s-npi-92e282d1dc2b69d9e4f91fc0.yaml | 2 +- .../WEB-INF/web.xml | 368 ++++++++++++++++++ 4 files changed, 524 insertions(+), 3 deletions(-) diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-6ec6739e824c8e56d9633622.yaml b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-6ec6739e824c8e56d9633622.yaml index ac67bff..bb7eb72 100644 --- a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-6ec6739e824c8e56d9633622.yaml +++ b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-6ec6739e824c8e56d9633622.yaml @@ -45,7 +45,7 @@ spec: podDisruptionBudget: maxUnavailable: "50%" git: - tag: "r-b0b26fa9649d888b5ea592880dd6fbe6facbc8a3" + tag: "r-c1f967206031c07e593aa2ffabb8e9cd9d52d049" dir: "DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai" credentials: "git-credentials" keystores: diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/conf/esauth4.xml b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/conf/esauth4.xml index 1699c48..9562628 100644 --- a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/conf/esauth4.xml +++ b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/conf/esauth4.xml @@ -42,6 +42,11 @@ + + + + + @@ -51,8 +56,12 @@ + + + + @@ -112,7 +121,7 @@ - + @@ -121,6 +130,37 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -128,6 +168,114 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -138,4 +286,9 @@ + + + + + diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/etc/nevis/k8s-npi-92e282d1dc2b69d9e4f91fc0.yaml b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/etc/nevis/k8s-npi-92e282d1dc2b69d9e4f91fc0.yaml index 691efb1..9b7e697 100644 --- a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/etc/nevis/k8s-npi-92e282d1dc2b69d9e4f91fc0.yaml +++ b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/etc/nevis/k8s-npi-92e282d1dc2b69d9e4f91fc0.yaml @@ -46,7 +46,7 @@ spec: podDisruptionBudget: maxUnavailable: "50%" git: - tag: "r-349deb4960bc8a877066f3a6694b305a59b3388b" + tag: "r-c1f967206031c07e593aa2ffabb8e9cd9d52d049" dir: "DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi" credentials: "git-credentials" keystores: diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/var/opt/nevisproxy/default/host-klp.agov-w.azure.adnovum.net/WEB-INF/web.xml b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/var/opt/nevisproxy/default/host-klp.agov-w.azure.adnovum.net/WEB-INF/web.xml index 7265756..1747b70 100644 --- a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/var/opt/nevisproxy/default/host-klp.agov-w.azure.adnovum.net/WEB-INF/web.xml +++ b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/var/opt/nevisproxy/default/host-klp.agov-w.azure.adnovum.net/WEB-INF/web.xml @@ -1,6 +1,71 @@ + + + SectokenVerifierCert + /var/opt/keys/trust/npi-cossa-realm-signer-trust/truststore.pem + + + + AuthenticationService_cossa_realm + ch::nevis::isiweb4::filter::auth::IdentityCreationFilter + + + AuthenticationServlet + Connector_cossa_realm + + + + BodyReadSize + 32768 + + + + EntryPointID + klp.agov-w.azure.adnovum.net + + + + InactiveInterval + 7200 + + + + InterceptionRedirect + never + + + + LoginRendererServlet + LoginRenderer_New_nevisLogrend_Instance + + + + Realm + cossa_realm + + + + RecheckAuthentication + On + + + + RenewIdentification + true + + + + StateKey + cossa_realm + + + + StoreInterceptedRequest + false + + ErrorHandler_Default @@ -24,6 +89,33 @@ + + + OAuth_Preflighted_CORS_New OAuth 2.0 Authorization Server / OpenID Provider + ch::nevis::isiweb4::filter::lua::LuaFilter + + + Script + + function inputHeader(request, response) + response:setHeader("Access-Control-Allow-Origin", "*") + response:setHeader("Access-Control-Allow-Credentials", "true") + response:setHeader("Access-Control-Allow-Methods", "GET, POST, PUT, OPTIONS") + response:setHeader("Access-Control-Allow-Headers", "Authorization") + response:setHeader("Access-Control-Expose-Headers", "*") + response:setHeader("Access-Control-Max-Age", "600") + if request:getMethod() == "OPTIONS" then + response:send(204) + end + end + + + + + Script.InputHeaderFunctionName + inputHeader + + ResponseHeader_Default @@ -38,6 +130,51 @@ + + + SessionHandler_cossa_realm + ch::nevis::nevisproxy::filter::session::SessionManagementFilter + + + Cookie.ExtraAttributes + SameSite=None + + + + Cookie.Name + Session_cossa_realm + + + + Cookie.Secure + true + + + + Identification + COOKIE + + + + MaxInactiveInterval + 600 + + + + MaxLifetime + 28800 + + + + Servlet + LocalSessionStoreServlet + + + + UpdateTimeStampMinInterval + 120 + + ErrorHandler_Default @@ -48,10 +185,241 @@ ResponseHeader_Default /* + + + OAuth_Preflighted_CORS_New OAuth 2.0 Authorization Server / OpenID Provider + /oauth/authorize + + + + OAuth_Preflighted_CORS_New OAuth 2.0 Authorization Server / OpenID Provider + /oauth/token + + + + SessionHandler_cossa_realm + /oauth/authorize + + + + SessionHandler_cossa_realm + /oauth/token + + + + AuthenticationService_cossa_realm + /oauth/authorize + + + + AuthenticationService_cossa_realm + /oauth/token + + + + ch::nevis::isiweb4::listener::SessionListener + + + + Connector_cossa_realm + + ch::nevis::isiweb4::servlet::connector::soap::esauth4::Esauth4ConnectorServlet + + + Transport.DNSCache.ttl + 60 + + + + Transport.InetAddress + nai:8991 + + + + Transport.KeepAlive.LifeTime + 30 + + + + Transport.RequestTimeout + 90000 + + + + Transport.ResourceManager.RetryTimeout + 0 + + + + Transport.SSLCACertificateFile + /var/opt/keys/trust/npi-cossa-realm-tls-trust/truststore.pem + + + + Transport.SSLCheckPeerHostname + false + + + + Transport.SSLClientCertificateFile + /var/opt/keys/own/npi-cossa-realm-identity/cert.pem + + + + Transport.SSLClientKeyFile + /var/opt/keys/own/npi-cossa-realm-identity/key.pem + + + + + Connector_cossa_realm_REST + + ch::nevis::isiweb4::servlet::connector::http::HttpsConnectorServlet + + + DNSCache.ttl + 60 + + + + InetAddress + nai:8991 + + + + KeepAlive.LifeTime + 30 + + + + MappingType + requesturi + + + + RequestTimeout + 90000 + + + + ResourceManager.RetryTimeout + 0 + + + + SSLCACertificateFile + /var/opt/keys/trust/npi-cossa-realm-tls-trust/truststore.pem + + + + SSLCheckPeerHostname + false + + + + SSLClientCertificateFile + /var/opt/keys/own/npi-cossa-realm-identity/cert.pem + + + + SSLClientKeyFile + /var/opt/keys/own/npi-cossa-realm-identity/key.pem + + + + URIPrefix + /nevisauth + + + Hosting_Default + ch::nevis::isiweb4::servlet::defaults::DefaultServlet + + + LocalSessionStoreServlet + + ch::nevis::nevisproxy::servlet::cache::local::LocalSessionStoreServlet + + + MaxInactiveInterval + 600 + + + + MaxLifetime + 28800 + + + + MemorySize + 512000000 + + + + + LoginRenderer_New_nevisLogrend_Instance + + ch::nevis::isiweb4::servlet::rendering::LoginRendererServlet + + + PropagateRemoteHeaders + Set-Cookie + + + + RenderingProvider + remote:NevisLogrendConnector_New_nevisLogrend_Instance:/nevislogrend/index.vm?logrendresourcepath=/nevislogrend + + + + + NevisLogrendConnector_New_nevisLogrend_Instance + + ch::nevis::isiweb4::servlet::connector::http::HttpConnectorServlet + + + InetAddress + nli:8988 + + + + MappingType + pathinfo + + + + ResourceManager.RetryTimeout + 0 + + + + URIPrefix + /nevislogrend + + + + + NevisLogrendConnector_New_nevisLogrend_Instance + /nevislogrend/* + + + + Hosting_Default + /oauth/authorize + + + + Connector_cossa_realm_REST + /oauth/introspect + + + + Hosting_Default + /oauth/token + Hosting_Default /*