Sign inSign up

dualauth/passwordless-x1280-single

By dualauth

•Updated 2 months ago

Image
15

5.6K

dualauth/passwordless-x1280-single repository overview

⁠How to use this image

⁠Start a passwordless-x1280-single instance

$ docker network create some-network
$ docker run -d --name server \
    --network some-network \
    --restart always \
    -e USE_SSL=false \
    -e DOMAIN=<your-passwordless-x1280-auth-server-domain> \
    -v auth-settings:/usr/local/tomcat/conf \
    -v auth-logs:/usr/local/tomcat/logs \
    -v user-connection-logs:/opt/x1280/connector/logs \
    -v push-request-logs:/opt/x1280/pushconnector/logs \
    -v config:/etc/opt/x1280 \
    -v database:/var/lib/mysql \
    -p 8080:8080 \
    -p 8180:8180 \
    -p 8143:8143 \
    -p 8443:8443 \
    -p 11040:11040 \
    -p 12010:12010 \
    -p 15010:15010 \
    dualauth/passwordless-x1280-single:latest

⁠Environment Variables

⁠Mandatory variables
⁠DOMAIN

This variable is for the domain name of your Passwordless X1280 server.
Example: -e DOMAIN=auth.example.com

[Important] Your DNS A record needs to be set as well.

⁠Optional variables
⁠USE_SSL (Default value is "true")

When not using SLL certificate This is used for testing environment.
Set false for development and test environment.

 -e USE_SSL=false

When using SLL certificate If you set to "USE_SSL=true", place the certificate files you want to apply in the /tmp/ssl folder and add the options below.
* cert.pem : Certificate file
* privkey.pem : Private key file
* tomcat.keystore : Keystore file

 -e SSL_CERT_PATH="/etc/opt/x1280/ssl/cert.pem" \
 -e SSL_CERT_KEY_PATH="/etc/opt/x1280/ssl/privkey.pem" \
 -e AUTH_KEYSTORE_FILE_PATH="/etc/opt/x1280/ssl/tomcat.keystore" \
 -e AUTH_KEYSTORE_PASS=Your-keystore-password \

After running docker, find the docker container ID by running the commands below. The container ID found in this way will be denoted as [containerID] from now on.

$ docker container ps -a

Make folders in the docker container for certificate files.

$ docker exec server mkdir /etc/opt/x1280
$ docker exec server mkdir /etc/opt/x1280/ssl

Copy certification files to docker container by running the commands below.

$ docker cp /tmp/ssl/cert.pem server:/etc/opt/x1280/ssl/
$ docker cp /tmp/ssl/privkey.pem server:/etc/opt/x1280/ssl/
$ docker cp /tmp/ssl/tomcat.keystore server:/etc/opt/x1280/ssl/

Restart docker again.

$ docker restart server
⁠Minimum System Requirements for Passwordless-x1280-single Version

To run Passwordless-x1280-single version, at least one CPU and 1 GB of memory must be allocated. Passwordless-x1280-single version can be installed on a separate Linux server (recommended) or an existing web application server. These minimum requirements are based on case of 100 concurrent users at the same time.

Please note that the minimum system requirements are not the recommended specifications, and it is advisable to use them only if obtaining the recommended physical system is difficult.

To apply the minimum requirements, add the following options.

--cpus=1 \
--cpuset-cpus="0" \
--cpu-shares=1024 \
--memory=1g \
--memory-swap=2g \
* Option description
--cpus=1 : Number of cpu cores
--cpuset-cpus=”0” : Docker occupies and uses the first CPU (ex: --cpuset-cpus="1,3" → Use 2 CPUs: 2nd and 4th CPU)
--cpu-shares=1024 : Uses 100% of CPU (ex: --cpu-shares=512 → uses 50% of CPU)
--memory=1g : Uses 1GB of memory
--memory-swap=2g : Swap memory is set to twice the memory

Benchmark Result⁠

⁠Firewall - Open port

⁠Open In-Bound port
* From any : 8080, 12010, 15010
* From Web application server : 11040
* From administrator Computer : 8143
⁠Open Out-Bound port
* To any (Push Request) : 14010

⁠Volumes

⁠auth-settings:/user/local/tomcat/conf

This volume contains authentication server settings.

⁠database:/var/lib/mysql

This volume contains data of database.

⁠Testing tips

When using a private certificate on your testing environment , it's necessary to import the Certificate Authority (CA) in your browser. Without importing, the browser will not recognize the private certificate as trusted, which leads to security warnings.

As a temporary workaround, you can manually bypass these warnings by visiting the Push Request server and User Connection server over HTTPS in your browser and clicking 'Continue' or 'Proceed' on the "Not Secure" warning screen. However, this is not recommended for long-term use as it compromises security.

For a more secure solution, you should manually import the Certificate Authority (CA) into your browser. Here are the general steps to import the CA in most browsers:

Step 1. Export Certificate: First, export the certificate from your private CA. (cert.pem under ssl directory in the config volume)

Step 2. Open Browser Settings: Go to the settings menu of your browser.

Step 3. Access Security/Privacy Settings: Locate the 'Security', 'Privacy & Security', or a similarly named section.

Step 4. Manage Certificates: Select 'View Certificates', 'Manage Certificates', or a similar option.

Step 5. Install Certificate: Click on 'Import Certificate', 'Install Certificate', or a similar option, then select and install the exported private CA certificate.

After completing these steps, your browser will trust the private certificate, allowing you to access the servers without encountering the "Not Secure" warning.

Passwordless Alliance is providing Passwordless X1280 software for free to B2C online services worldwide.

Join as a Passwordless Alliance member now and help create a world without passwords.


Learn more about the Passwordless Alliance.

Passwordless Alliance

https://www.passwordlessalliance.org⁠


Join the Passwordless Alliance and provide passwordless online services.

Passwordless X1280 Members

https://members.passwordlessalliance.org⁠


We provide tutorials and example projects for implementing Passwordless X1280 into online services.

Passwordless X1280 github

https://github.com/PasswordlessAlliance⁠



⁠Open Source Licenses

This container image includes the following open source software:

MariaDB source code is available at: https://mariadb.org/download/⁠

All components are used in compliance with their respective licenses.

Tag summary

Content type

Image

Digest

sha256:b89460327…

Size

267.8 MB

Last updated

2 months ago

docker pull dualauth/passwordless-x1280-single