Sign inSign up

nanofab/nginx-shibboleth

By nanofab

•Updated 15 days ago

Nginx with shibboleth authentication module

Image
Web servers
0

2.7K

nanofab/nginx-shibboleth repository overview

⁠Version number

Version numbers match with official Nginx releases

⁠FIPS

The latest version which uses debian bookworm will not work if FIPS is enabled on the host server (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1014517⁠).
Disable it with fips-mode-setup --disable and restart.

⁠Shibboleth encrypt/signing keys

create container:
docker run --name nginx -d nanofab/nginx-shibboleth

Generate keys (assuming the container is named nginx)
docker exec -it nginx shib-keygen -b -h <hostname> -n "sp-signing"
docker exec -it nginx shib-keygen -b -h <hostname> -n "sp-encrypt"

then zip and copy them to your host:
docker exec -it nginx bash -c "zip -j /etc/shibboleth/shib-keys.zip /etc/shibboleth/sp-*"
docker cp nginx:/etc/shibboleth/shib-keys.zip ./
unzip shib-keys.zip

remove container:
docker rm -f nginx

⁠Shibboleth

Mount all shibboleth files into /etc/shibboleth/ folder on the container.

If using docker-compose this can be done by mounting the following files (assuming you have all the files in nginx and shibboleth folders):

services:
  nginx:
    container_name: nginx
    image: nanofab/nginx-shibboleth:1.27.1
    ports:
      - "80:80"
      - "443:443"
    volumes:
      - ./nginx/nginx.conf:/etc/nginx/nginx.conf
      - ./shibboleth/shibboleth2.xml/:/etc/shibboleth/shibboleth2.xml
      - ./shibboleth/attribute-map.xml/:/etc/shibboleth/attribute-map.xml
      - ./shibboleth/attribute-policy.xml/:/etc/shibboleth/attribute-policy.xml
      - ./shibboleth/sp-encrypt-cert.pem:/etc/shibboleth/sp-encrypt-cert.pem
      - ./shibboleth/sp-encrypt-key.pem:/etc/shibboleth/sp-encrypt-key.pem
      - ./shibboleth/sp-signing-cert.pem:/etc/shibboleth/sp-signing-cert.pem
      - ./shibboleth/sp-signing-key.pem:/etc/shibboleth/sp-signing-key.pem

⁠Nginx configuration file

load_module modules/ngx_http_shibboleth_module.so;
load_module modules/ngx_http_headers_more_filter_module.so;

http {
    server {
        listen 443 ssl;
        server_name <server_name>;

        # Location secured by Shibboleth
        location / {
            include shib_fastcgi_params;
            include fastcgi_params;
            more_clear_input_headers 'Variable-*' 'Shib-*' 'Remote-User' 'REMOTE_USER' 'Auth-Type' 'AUTH_TYPE';
            fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
            shib_request_set $shib_remote_user $upstream_http_variable_remote_user;
            proxy_set_header Remote-User $shib_remote_user;
            shib_request /shibauthorizer;
            proxy_http_version 1.1;
            proxy_set_header Host $host;
            proxy_set_header X-Forwarded-Host $server_name;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto https;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_set_header Connection "";
            proxy_pass <your_proxy_pass>;
        }

        location = /shibauthorizer {
            internal;
            include fastcgi_params;
            fastcgi_pass unix:/var/run/shibboleth/shibauthorizer.sock;
        }

        # FastCGI responder for SSO
        location /Shibboleth.sso {
            include fastcgi_params;
            fastcgi_pass unix:/var/run/shibboleth/shibresponder.sock;
        }

        #Resources for the Shibboleth error pages. This can be customized.
        location /shibboleth-sp {
            alias /usr/share/shibboleth/;
        }
    }
}

Tag summary

Content type

Image

Digest

sha256:1d3fe0702…

Size

129.8 MB

Last updated

15 days ago

docker pull nanofab/nginx-shibboleth