From ae35351ae0bd1c647e5f2d6990a3b0ef1a75ab5d Mon Sep 17 00:00:00 2001 From: root Date: Wed, 21 Sep 2022 18:37:46 +0000 Subject: [PATCH] update midpoint to 4.5 --- Workbench/docker-compose.yml | 4 +- Workbench/midpoint_server/Dockerfile | 2 +- .../securityPolicy/000-security-policy.xml | 62 +++++++------------ .../webproxy/container_files/httpd/index.html | 4 +- .../container_files/system/startWithMDLoad.sh | 2 +- 5 files changed, 26 insertions(+), 48 deletions(-) diff --git a/Workbench/docker-compose.yml b/Workbench/docker-compose.yml index f60b4b8..4be075c 100644 --- a/Workbench/docker-compose.yml +++ b/Workbench/docker-compose.yml @@ -224,10 +224,8 @@ services: environment: - CREATE_NEW_DATABASE=if_needed - - data_init: - image: i2incommon/midpoint:4.4 + image: i2incommon/midpoint:4.5 command: > bash -c " chmod 777 /opt/mp-pw/ ; diff --git a/Workbench/midpoint_server/Dockerfile b/Workbench/midpoint_server/Dockerfile index dadd9da..e482e0a 100644 --- a/Workbench/midpoint_server/Dockerfile +++ b/Workbench/midpoint_server/Dockerfile @@ -1,4 +1,4 @@ -FROM i2incommon/midpoint:4.4 +FROM i2incommon/midpoint:4.5 ARG CSPHOSTNAME=localhost ENV CSPHOSTNAME=$CSPHOSTNAME diff --git a/Workbench/midpoint_server/container_files/mp-home/post-initial-objects/securityPolicy/000-security-policy.xml b/Workbench/midpoint_server/container_files/mp-home/post-initial-objects/securityPolicy/000-security-policy.xml index 372d41c..3570a5b 100644 --- a/Workbench/midpoint_server/container_files/mp-home/post-initial-objects/securityPolicy/000-security-policy.xml +++ b/Workbench/midpoint_server/container_files/mp-home/post-initial-objects/securityPolicy/000-security-policy.xml @@ -1,8 +1,8 @@ - + xmlns:c="http://midpoint.evolveum.com/xml/ns/public/common/common-3" + xmlns:org="http://midpoint.evolveum.com/xml/ns/public/common/org-3"> + Default Security Policy @@ -17,55 +17,35 @@ mySamlSso My internal enterprise SAML-based SSO system. - - 10000 - 5000 - midpointdemo-shibboleth true - true - true - urn:oasis:names:tc:SAML:2.0:nameid-format:transient - - /etc/pki/mp/sp-shibboleth-keys.jks - - changeit - - signing-key - - password - - - - /etc/pki/mp/sp-shibboleth-keys.jks - - changeit - - encrypt-key - - password - - encryption - + + /etc/pki/mp/sp-shibboleth-keys.jks + + changeit + + signing-key + + password + + - - https://idptestbed/idp/shibboleth - idp-shibboleth + + https://idptestbed/idp/shibboleth /etc/shibboleth/idp-metadata.xml - true Shibboleth urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST uid - + httpHeader - https://__CSPHOSTNAME__/MPSSO/Shibboleth.sso/Logout + https://__CSPHOSTNAME__/MPSSO/Shibboleth.sso/Logout REMOTE_USER @@ -99,7 +79,7 @@ internalLoginForm - 40 + 30 sufficient @@ -151,8 +131,8 @@ sufficient - /actuator - /actuator/health + /actuator + /actuator/health @@ -166,4 +146,4 @@ - \ No newline at end of file + diff --git a/Workbench/webproxy/container_files/httpd/index.html b/Workbench/webproxy/container_files/httpd/index.html index 23c24f0..affdfe9 100644 --- a/Workbench/webproxy/container_files/httpd/index.html +++ b/Workbench/webproxy/container_files/httpd/index.html @@ -10,7 +10,7 @@

Welcome to the InCommon TAP Workbench!

@@ -35,7 +35,7 @@

Welcome to the InCommon TAP Workbench!

  • Shibboleth SPs:
  • diff --git a/Workbench/webproxy/container_files/system/startWithMDLoad.sh b/Workbench/webproxy/container_files/system/startWithMDLoad.sh index 1300403..0e158da 100755 --- a/Workbench/webproxy/container_files/system/startWithMDLoad.sh +++ b/Workbench/webproxy/container_files/system/startWithMDLoad.sh @@ -3,7 +3,7 @@ #wait for IdPUI's API, then load metadata into it pushd /mdload -./wait-for-it.sh -t 0 idp_ui_api:8443 -- ./loadMD.sh GrouperSP /mdload/grouper-sp.xml 60 && \ +./wait-for-it.sh -t 0 idp_ui_api:8443 -- ./loadMD.sh GrouperSP /mdload/grouper-sp.xml 90 && \ ./loadMD.sh midPointSP /mdload/midpoint-sp.xml 0 && \ ./loadMD.sh ProxySP /mdload/proxy-sp.xml 0 && \ ./loadMD.sh WordPressSP /mdload/wordpress-sp.xml 0 && \