From 9f67b134b512641596090736d18bec63f68172bd Mon Sep 17 00:00:00 2001 From: mamo Date: Mon, 18 Nov 2024 12:33:38 +0000 Subject: [PATCH] new configuration version --- .../k8s-nai-6ec6739e824c8e56d9633622.yaml | 3 +- ...e-proxy-auth-6ec6739e824c8e56d9633622.yaml | 18 -- .../opt/nevisauth/default/conf/esauth4.xml | 200 ++++++------------ .../k8s-npi-92e282d1dc2b69d9e4f91fc0.yaml | 2 +- .../WEB-INF/web.xml | 70 +----- 5 files changed, 71 insertions(+), 222 deletions(-) delete mode 100644 DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-sh4r3d-keystore-proxy-auth-6ec6739e824c8e56d9633622.yaml diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-6ec6739e824c8e56d9633622.yaml b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-6ec6739e824c8e56d9633622.yaml index 3c9d8e5..4875001 100644 --- a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-6ec6739e824c8e56d9633622.yaml +++ b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-6ec6739e824c8e56d9633622.yaml @@ -45,11 +45,10 @@ spec: podDisruptionBudget: maxUnavailable: "50%" git: - tag: "r-b6134cc4e5c3b82e00933bd3c57aa747efd989cd" + tag: "r-612de5fc83fd2311722a210577306790f282916d" dir: "DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai" credentials: "git-credentials" keystores: - - "nai-sh4r3d-keystore-proxy-auth" - "nai-default-identity" - "nai-sh4r3d-default-default-signer" truststores: diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-sh4r3d-keystore-proxy-auth-6ec6739e824c8e56d9633622.yaml b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-sh4r3d-keystore-proxy-auth-6ec6739e824c8e56d9633622.yaml deleted file mode 100644 index fee9f43..0000000 --- a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/etc/nevis/k8s-nai-sh4r3d-keystore-proxy-auth-6ec6739e824c8e56d9633622.yaml +++ /dev/null @@ -1,18 +0,0 @@ -apiVersion: "operator.nevis-security.ch/v1" -kind: "NevisKeyStore" -metadata: - name: "nai-sh4r3d-keystore-proxy-auth" - namespace: "adn-postit-tknxchng-01-dev" - labels: - deploymentTarget: "nai" - annotations: - projectKey: "DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT" - patternId: "6ec6739e824c8e56d9633622" -spec: - cn: "New_OAuth_2.0_Authorization_Server_OpenID_Provider-signer" - usage: "signer" - san: - dns: - - "nai" - - "nai.adn-postit-tknxchng-01-dev" - email: [] diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/conf/esauth4.xml b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/conf/esauth4.xml index 13ef9ad..16d8290 100644 --- a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/conf/esauth4.xml +++ b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/nai/var/opt/nevisauth/default/conf/esauth4.xml @@ -42,11 +42,6 @@ - - - - - @@ -60,14 +55,13 @@ - - + + - - + @@ -294,7 +288,7 @@ - + @@ -303,37 +297,6 @@ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - @@ -341,113 +304,70 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + - + - + - + - + - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + + + + diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/etc/nevis/k8s-npi-92e282d1dc2b69d9e4f91fc0.yaml b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/etc/nevis/k8s-npi-92e282d1dc2b69d9e4f91fc0.yaml index ff2858c..1be06d9 100644 --- a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/etc/nevis/k8s-npi-92e282d1dc2b69d9e4f91fc0.yaml +++ b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/etc/nevis/k8s-npi-92e282d1dc2b69d9e4f91fc0.yaml @@ -46,7 +46,7 @@ spec: podDisruptionBudget: maxUnavailable: "50%" git: - tag: "r-b6134cc4e5c3b82e00933bd3c57aa747efd989cd" + tag: "r-612de5fc83fd2311722a210577306790f282916d" dir: "DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi" credentials: "git-credentials" keystores: diff --git a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/var/opt/nevisproxy/default/host-cossa.agov-w.azure.adnovum.net/WEB-INF/web.xml b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/var/opt/nevisproxy/default/host-cossa.agov-w.azure.adnovum.net/WEB-INF/web.xml index be84dd5..75442da 100644 --- a/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/var/opt/nevisproxy/default/host-cossa.agov-w.azure.adnovum.net/WEB-INF/web.xml +++ b/DEFAULT-ADN-POST-IAM-TKNXCHNG-PROJECT/DEFAULT-ADN-POST-IAM-TKNXCHNG-INV/npi/var/opt/nevisproxy/default/host-cossa.agov-w.azure.adnovum.net/WEB-INF/web.xml @@ -99,33 +99,6 @@ /var/opt/nevisproxy/default/host-cossa.agov-w.azure.adnovum.net/WEB-INF/security_cossa_realm_tokenintrospection.conf - - - OAuth_Preflighted_CORS_New OAuth 2.0 Authorization Server / OpenID Provider - ch::nevis::isiweb4::filter::lua::LuaFilter - - - Script - - function inputHeader(request, response) - response:setHeader("Access-Control-Allow-Origin", "*") - response:setHeader("Access-Control-Allow-Credentials", "true") - response:setHeader("Access-Control-Allow-Methods", "GET, POST, PUT, OPTIONS") - response:setHeader("Access-Control-Allow-Headers", "Authorization") - response:setHeader("Access-Control-Expose-Headers", "*") - response:setHeader("Access-Control-Max-Age", "600") - if request:getMethod() == "OPTIONS" then - response:send(204) - end - end - - - - - Script.InputHeaderFunctionName - inputHeader - - Qos @@ -218,22 +191,7 @@ SessionHandler_cossa_realm - /oauth/authorize - - - - SessionHandler_cossa_realm - /oauth/token - - - - OAuth_Preflighted_CORS_New OAuth 2.0 Authorization Server / OpenID Provider - /oauth/authorize - - - - OAuth_Preflighted_CORS_New OAuth 2.0 Authorization Server / OpenID Provider - /oauth/token + /asdf/* @@ -248,12 +206,7 @@ AuthenticationService_cossa_realm - /oauth/authorize - - - - AuthenticationService_cossa_realm - /oauth/token + /asdf/* @@ -391,10 +344,10 @@ true - + Hosting_Default - + ch::nevis::isiweb4::servlet::defaults::DefaultServlet @@ -460,26 +413,21 @@ /nevislogrend + + + Hosting_Default + /asdf/* + NevisLogrendConnector_nli /nevislogrend/* - - - Hosting_Default - /oauth/authorize - Connector_cossa_realm_TokenIntrospection /oauth/introspect2/* - - - Hosting_Default - /oauth/token - Hosting_Default