Nginx with shibboleth authentication module
2.7K
Version numbers match with official Nginx releases
The latest version which uses debian bookworm will not work if FIPS is enabled on the host server (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1014517).
Disable it with fips-mode-setup --disable and restart.
create container:
docker run --name nginx -d nanofab/nginx-shibboleth
Generate keys (assuming the container is named nginx)
docker exec -it nginx shib-keygen -b -h <hostname> -n "sp-signing"
docker exec -it nginx shib-keygen -b -h <hostname> -n "sp-encrypt"
then zip and copy them to your host:
docker exec -it nginx bash -c "zip -j /etc/shibboleth/shib-keys.zip /etc/shibboleth/sp-*"
docker cp nginx:/etc/shibboleth/shib-keys.zip ./
unzip shib-keys.zip
remove container:
docker rm -f nginx
Mount all shibboleth files into /etc/shibboleth/ folder on the container.
If using docker-compose this can be done by mounting the following files (assuming you have all the files in nginx and shibboleth folders):
services:
nginx:
container_name: nginx
image: nanofab/nginx-shibboleth:1.27.1
ports:
- "80:80"
- "443:443"
volumes:
- ./nginx/nginx.conf:/etc/nginx/nginx.conf
- ./shibboleth/shibboleth2.xml/:/etc/shibboleth/shibboleth2.xml
- ./shibboleth/attribute-map.xml/:/etc/shibboleth/attribute-map.xml
- ./shibboleth/attribute-policy.xml/:/etc/shibboleth/attribute-policy.xml
- ./shibboleth/sp-encrypt-cert.pem:/etc/shibboleth/sp-encrypt-cert.pem
- ./shibboleth/sp-encrypt-key.pem:/etc/shibboleth/sp-encrypt-key.pem
- ./shibboleth/sp-signing-cert.pem:/etc/shibboleth/sp-signing-cert.pem
- ./shibboleth/sp-signing-key.pem:/etc/shibboleth/sp-signing-key.pem
load_module modules/ngx_http_shibboleth_module.so;
load_module modules/ngx_http_headers_more_filter_module.so;
http {
server {
listen 443 ssl;
server_name <server_name>;
# Location secured by Shibboleth
location / {
include shib_fastcgi_params;
include fastcgi_params;
more_clear_input_headers 'Variable-*' 'Shib-*' 'Remote-User' 'REMOTE_USER' 'Auth-Type' 'AUTH_TYPE';
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
shib_request_set $shib_remote_user $upstream_http_variable_remote_user;
proxy_set_header Remote-User $shib_remote_user;
shib_request /shibauthorizer;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Host $server_name;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto https;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header Connection "";
proxy_pass <your_proxy_pass>;
}
location = /shibauthorizer {
internal;
include fastcgi_params;
fastcgi_pass unix:/var/run/shibboleth/shibauthorizer.sock;
}
# FastCGI responder for SSO
location /Shibboleth.sso {
include fastcgi_params;
fastcgi_pass unix:/var/run/shibboleth/shibresponder.sock;
}
#Resources for the Shibboleth error pages. This can be customized.
location /shibboleth-sp {
alias /usr/share/shibboleth/;
}
}
}
Content type
Image
Digest
sha256:1d3fe0702…
Size
129.8 MB
Last updated
15 days ago
docker pull nanofab/nginx-shibboleth