Sign inSign up

seclore/sdk-api-server

By seclore

•Updated about 2 years ago

A containerized environment for running the Seclore SDK APIs.

Image
0

84

seclore/sdk-api-server repository overview

⁠Seclore SDK API Server


⁠Table of Contents

  1. Overview⁠
  2. Features⁠
  3. Usage⁠
  4. Environment Variables⁠

⁠Overview

The Seclore SDK API Server Docker image provides a containerized environment for running the Seclore SDK API. This image includes all the necessary components to deploy and manage the API server efficiently.


⁠Features

  • SpringDoc Swagger UI: Swagger UI is enabled for API documentation and testing.
  • Configurable Logging and Memory: Adjust logging level and Java memory settings as needed.
  • Customizable Environment: Configure various application settings via environment variables.

⁠Usage

Set the required Environment Variables⁠ and run the container

NOTE : As Linux Environment doesnt allow square brackets('[' and ']') in environment key names. So set the environment configurations in a .env file and use the provided command with additional flag : --env-file <ENV_FILE_PATH>

To run the container, replace the following placeholders with their requested values in the provided command⁠ and execute it:

  • <HOST_MACHINE_PORT> with the your host machine port.
  • <HOST_MACHINE_VOLUME_PATH> with path to the file storage preferably a NAS.
⁠Command:
docker run -p <HOST_MACHINE_PORT>:8443 -v <HOST_MACHINE_VOLUME_PATH>:/app/data seclore/sdk-api-server:<TAG_NAME>

Now, access the following Swagger Docs URL to view the API documentation(available only if Swagger UI is enabled): http://<FQDN>:<HOST_MACHINE_PORT>/swagger-ui.html

Application logs can be viewed on console.

NOTE: Create a seclore user with id 54321 in host machine and provide it with read, write and execute permission on the <HOST_MACHINE_VOLUME_PATH> using following command:

groupadd -g 54321 seclore && \
useradd -u 54321 seclore -g seclore && \
chown -R seclore:seclore <HOST_MACHINE_VOLUME_PATH> && \
chmod -R 755 <HOST_MACHINE_VOLUME_PATH>

⁠Environment Variables

The image uses several environment variables which are easy to miss. The only variables required are app.fshelper[n].identifier and app.fshelper[n].config, the rest are optional. Here are some key options:

  • APPLICATION_LOG_LEVEL: Set the log level (default is info).
  • ENABLE_BC_FIPS: Enable or disable BC FIPS mode (default is false).
  • JAVA_MIN_MEMORY: Minimum Java memory allocation in MB (default is 1024).
  • JAVA_MAX_MEMORY: Maximum Java memory allocation in MB (default is 2048).
  • springdoc.swagger-ui.enabled: Enable/Disable Swagger UI for API documentation and testing by setting it as true or false (default is true).
  • app.fshelper[n].identifier: Unique identifier for FS helper. This will help identify which configuration to use for Seclore APIs.

NOTE: 'n' represents an integer(starting from 0 to n) for linking a FSHelper identifier with a FSHelper config.

  • app.fshelper[n].config: Base64 encoded configuration settings for FS helper. Refer the FSHelper Configuration⁠ for generating this configuration.
⁠Configurations for Advanced EA
  • app.fshelper[n].privateKey: Private key in xml. The value should be in hexadecimal format.
  • app.fshelper[n].keyId: A unique Id which is mapped to the public key part on Policy Server.
  • app.fshelper[n].keyLength: Length of the private Key.(Example - 256)
  • app.fshelper[n].padding: Padding to be used for encrypt or decrypt.(Example - PKCS1Padding)
  • app.fshelper[n].chainingMode: Chaining mode to be used for encrypt or decrypt.(Example - ECB)
⁠FSHelper Configuration

Fill the below config xml⁠ and convert it to Base64 encoded value(using any Base64 encoding tool such as https://www.base64encode.org/⁠) for app.fshelper[n].config

⁠Config xml
<?xml version="1.0" encoding="UTF-16" ?>
<!-- Configuration File (1.1.0.0). -->
<!-- This file contains the XML strcuture which should be passed
to the IFSHelperInitialize API to initialize the Library -->

<fs-helper-ps-config>
    <ps-details>
        <!-- URLs of the Policy Server. -->
        <urls>
            <!-- 
            URL of the Policy Server. Multiple such tags can be present. 
            It is recommended to put reachable URL as first URL and then 
            backup URL. 
            -->
            <url>
                <!-- 
                Parts of URL. 
                For example, if URL is https://demo.seclore.com:9443/PolicyServer,
                    server:      demo.seclore.com
                    port:        9443
                    app-name:    PolicyServer.

                    Value of 'port' is mandatory.
                -->
                <server></server>
                <port></port>
                <app-name></app-name>
            </url>
        </urls>
    </ps-details>
    
	<!-- Login details for this instance -->
	<login-details>
		<!-- 
			Login user type.
				1: Cabinet User
				2: PS End-User
		-->
		<user-type>1</user-type>

		<!-- Structure for user type Cabinet User(1) -->
		<!-- 
		Hot Folder Cabinet details. This details are used to authenticate with 
		Policy Server. 
		-->
		<hotfolder-cabinet>
			<!-- 
			Hot Folder Cabinet identifier. 
			-->
			<id></id>
			<!-- 
			Hot Folder Cabinet pass phrase. 
			-->
			<passphrase></passphrase>
			
			<!-- 
			Flag to enable advance priviledges 
			-->
			<allow-advanced-privileges>false</allow-advanced-privileges>
		</hotfolder-cabinet>
		
	</login-details>
    
    <!-- This tag defines whether inline attachment should be embedded in unprotected mail body or should be provided separately
        true : Inline attachments will get embedded in mail body.
        false : Inline attachments will be provided separately and not as mail body content.
        -->
    <include-inline-attachment-in-mail-body>false</include-inline-attachment-in-mail-body>
    
	<!-- 
		The Locale of FSHelper.
		Locale String Format : <language code>[_<country code>[_<variant code>]]
	-->
	<locale>en</locale>
	
    <!-- 
    Policy Server session pool configuration. 
    -->
    <session-pool>
        <!-- 
        Max. number of connection with Policy Server. This value is based on 
        (equal to) active concurrent users of Integrating Application deployment. 
        -->
        <max-size>50</max-size>
        <!-- 
        Policy Server session timeout in seconds. This is typically 15 minutes (900 seconds). 
		for Policy Server. Value of this tag can be found in configuration file 
		of Web Application Server (web.xml for Tomcat). 
        -->
        <default-session-timeout>900</default-session-timeout>
    </session-pool>

    <!-- 
    Details of proxy server, if required to connect to Policy Server.  
	If not required, remove the following tag itself. It is optional.
    -->
    <proxy-details>
        <server></server>
        <port></port>
        <user></user>
        <password></password>
        <!-- 
        Semicolon (;) separated list of URL patterns, just like IE bypass 
        list in Internet Explorer. 
        -->
        <bypass-list></bypass-list>
    </proxy-details>
</fs-helper-ps-config>

Tag summary

Content type

Image

Digest

sha256:606459152…

Size

143.3 MB

Last updated

about 2 years ago

docker pull seclore/sdk-api-server:3.0.0.0