Nginx built with spnego and shibboleth modules
385
This image is built from the official Nginx repository and adds support for Kerberos (SPNEGO) and Shibboleth authentication.
Mount server.keytab file into /etc/nginx/server.keytab on the container
load_module modules/ngx_http_auth_spnego_module.so;
http {
auth_gss_keytab server.keytab;
server {
listen 443 ssl;
server_name <server_name>;
auth_gss_on;
}
}
Mount all shibboleth files into /etc/shibboleth/ folder on the container.
load_module modules/ngx_http_shibboleth_module.so;
http {
server {
listen 443 ssl;
server_name <server_name>;
# Location secured by Shibboleth
location / {
include shib_fastcgi_params;
include fastcgi_params;
more_clear_input_headers 'Variable-*' 'Shib-*' 'Remote-User' 'REMOTE_USER' 'Auth-Type' 'AUTH_TYPE';
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
shib_request_set $shib_remote_user $upstream_http_variable_remote_user;
proxy_set_header Remote-User $shib_remote_user;
shib_request /shibauthorizer;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Host $server_name;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto https;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header Connection "";
proxy_pass <your_proxy_pass>;
}
location = /shibauthorizer {
internal;
include fastcgi_params;
fastcgi_pass unix:/var/run/shibboleth/shibauthorizer.sock;
}
# FastCGI responder for SSO
location /Shibboleth.sso {
include fastcgi_params;
fastcgi_pass unix:/var/run/shibboleth/shibresponder.sock;
}
#Resources for the Shibboleth error pages. This can be customised.
location /shibboleth-sp {
alias /usr/share/shibboleth/;
}
}
}
Content type
Image
Digest
sha256:117def7ff…
Size
102.6 MB
Last updated
about 3 years ago
docker pull nanofab/nginx-auth