diff --git a/Dockerfile.nginx b/Dockerfile.nginx index 269265849f1951f3afd9116a23395d25381f2648..19c4b837fca39789de369ffc7e57f46b7b49a21e 100644 --- a/Dockerfile.nginx +++ b/Dockerfile.nginx @@ -89,8 +89,8 @@ RUN touch /opt/repository/sources/lindat-aai-discovery/aai.js RUN make aai.min.js # copy certificate for clarin-dev -COPY commul-customization/certs/clarin-dev.key /etc/ssl/private/ -COPY commul-customization/certs/clarin-dev_eurac_edu.crt /etc/ssl/certs/ +# COPY commul-customization/certs/clarin-dev.key /etc/ssl/private/ +# COPY commul-customization/certs/clarin-dev_eurac_edu.crt /etc/ssl/certs/ # if deployed on clarin instead of clarin-dev comment the two lines above and uncomment the following lines diff --git a/commul-customization/default-ssl b/commul-customization/default-ssl index c9cb0ff8684820ed46ae00013877a414b1fab298..44c8c4763ecbfcefbf88b458a57cc0a9b1108937 100644 --- a/commul-customization/default-ssl +++ b/commul-customization/default-ssl @@ -18,8 +18,8 @@ server { index index.html index.htm; ssl on; - ssl_certificate /etc/ssl/certs/clarin-dev_eurac_edu.crt; - ssl_certificate_key /etc/ssl/private/clarin-dev.key; + ssl_certificate /etc/ssl/lindat/clarin-dev_eurac_edu.crt; + ssl_certificate_key /etc/ssl/lindat/clarin-dev.key; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_ciphers RC4:HIGH:!aNULL:!MD5; diff --git a/commul-customization/shibboleth2.xml b/commul-customization/shibboleth2.xml index d5721b97812f945156c78f7c20335fc29e5fd6ca..80f97804f266cd82c86fe0009e082446a30f1e60 100644 --- a/commul-customization/shibboleth2.xml +++ b/commul-customization/shibboleth2.xml @@ -70,7 +70,7 @@ <Logout>SAML2 Local</Logout> <!-- Extension service that generates "approximate" metadata based on SP configuration. --> - <Handler type="MetadataGenerator" Location="/Metadata" signing="false" template="lindat.eurac.edu.template.metadata.xml"/> + <Handler type="MetadataGenerator" Location="/Metadata" signing="false" template="clarin.eurac.edu.template.metadata.xml"/> <!-- Status reporting service. --> <Handler type="Status" Location="/Status" acl="127.0.0.1 ::1"/> @@ -148,7 +148,7 @@ <AttributeFilter type="XML" validate="true" path="attribute-policy.xml"/> <!-- Simple file-based resolver for using a single keypair. --> - <CredentialResolver type="File" key="sp-key.pem" certificate="sp-cert.pem"/> + <CredentialResolver type="File" key="certs/sp-key.pem" certificate="certs/sp-cert.pem"/> <!-- The default settings can be overridden by creating ApplicationOverride elements (see diff --git a/docker-compose.yml b/docker-compose.yml index 44d464234fe9b554dc038e55c19a7ddb9af12208..c9caac2a2be264acc5fc309697c5c09a3c068f1b 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -14,6 +14,9 @@ services: context: . dockerfile: Dockerfile.nginx image: eurac_nginx + volumes: + - ../volumes/shib-certs:/opt/shibboleth-sp-fastcgi/etc/shibboleth/certs + - ../volumes/ssl-certs:/etc/ssl/lindat hostname: clarin-dev.eurac.edu restart: always ports: