Sign inSign up

nanofab/nginx-auth

By nanofab

•Updated about 3 years ago

Nginx built with spnego and shibboleth modules

Image
0

385

nanofab/nginx-auth repository overview

This image is built from the official Nginx repository and adds support for Kerberos (SPNEGO) and Shibboleth authentication.

⁠Kerberos/Spnego

Mount server.keytab file into /etc/nginx/server.keytab on the container

load_module modules/ngx_http_auth_spnego_module.so;

http {
    auth_gss_keytab server.keytab;
    
    server {
        listen 443 ssl;
        server_name <server_name>;
        auth_gss_on;
    }
}

⁠Shibboleth

Mount all shibboleth files into /etc/shibboleth/ folder on the container.

load_module modules/ngx_http_shibboleth_module.so;

http {
    server {
        listen 443 ssl;
        server_name <server_name>;

        # Location secured by Shibboleth
        location / {
            include shib_fastcgi_params;
            include fastcgi_params;
            more_clear_input_headers 'Variable-*' 'Shib-*' 'Remote-User' 'REMOTE_USER' 'Auth-Type' 'AUTH_TYPE';
            fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
            shib_request_set $shib_remote_user $upstream_http_variable_remote_user;
            proxy_set_header Remote-User $shib_remote_user;
            shib_request /shibauthorizer;
            proxy_http_version 1.1;
            proxy_set_header Host $host;
            proxy_set_header X-Forwarded-Host $server_name;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto https;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header Connection "";
            proxy_pass <your_proxy_pass>;
        }

        location = /shibauthorizer {
            internal;
            include fastcgi_params;
            fastcgi_pass unix:/var/run/shibboleth/shibauthorizer.sock;
        }

        # FastCGI responder for SSO
        location /Shibboleth.sso {
            include fastcgi_params;
            fastcgi_pass unix:/var/run/shibboleth/shibresponder.sock;
        }

        #Resources for the Shibboleth error pages. This can be customised.
        location /shibboleth-sp {
            alias /usr/share/shibboleth/;
        }
    }
}

Tag summary

Content type

Image

Digest

sha256:117def7ff…

Size

102.6 MB

Last updated

about 3 years ago

docker pull nanofab/nginx-auth