Difference between revisions of "Apache Configuration for EPrints with Anubis"

From EPrints Documentation
Jump to: navigation, search
m
(Added key)
Line 1: Line 1:
 +
The following placeholders are used within these configuration files:
 +
{| class="wikitable"
 +
! Placeholder !! Description !! Example
 +
|-
 +
| '''EPRINTS_PATH''' || Path to EPrints installation. || <code>/opt/eprints3</code>
 +
|-
 +
| '''ARCHIVE_ID''' || ID of the specific EPrints repository archive. || <code>example_org</code>
 +
|-
 +
| '''HOSTNAME''' || The hostname of the EPrints repository archive. || <code>eprints.example.org</code>
 +
|-
 +
| '''ADMIN_EMAIL''' || The email address for the EPrints repository archive's administrator. || <code>eprints@example.org</code>
 +
|}
 +
 
=== HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf) ===
 
=== HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf) ===
 
* Assumes inclusion of all archives' ssl/securevhost.conf's from /etc/httpd/conf.d/eprints.conf or /etc/apache2/sites-enabled/eprints.conf.   
 
* Assumes inclusion of all archives' ssl/securevhost.conf's from /etc/httpd/conf.d/eprints.conf or /etc/apache2/sites-enabled/eprints.conf.   
* Replaces path of EPrints, ID of the archive and hostname of repository archive with EPRINTS_PATH, ARCHIVE_ID and HOSTNAME respectively.
+
 
 
* Includes Shibboleth configuration that is ultimately exempted from being proxied via Anubis
 
* Includes Shibboleth configuration that is ultimately exempted from being proxied via Anubis
 
* Logs names based on those used for RHEL-based Linux, changes may be required for Debian-based Linux (e.g Ubuntu).
 
* Logs names based on those used for RHEL-based Linux, changes may be required for Debian-based Linux (e.g Ubuntu).
Line 48: Line 61:
 
  PerlTransHandler +EPrints::Apache::Rewrite
 
  PerlTransHandler +EPrints::Apache::Rewrite
 
   
 
   
</VirtualHost>
+
</VirtualHost>
 +
 
 +
=== EPRINTS_PATH/cfg/apache_ssl/ARCHIVE_ID.conf ===
 +
 
 +
 
 +
=== EPRINTS_PATH/cfg/apache/ARCHIVE_ID.conf ===

Revision as of 09:41, 24 August 2026

The following placeholders are used within these configuration files:

Placeholder Description Example
EPRINTS_PATH Path to EPrints installation. /opt/eprints3
ARCHIVE_ID ID of the specific EPrints repository archive. example_org
HOSTNAME The hostname of the EPrints repository archive. eprints.example.org
ADMIN_EMAIL The email address for the EPrints repository archive's administrator. eprints@example.org

HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf)

  • Assumes inclusion of all archives' ssl/securevhost.conf's from /etc/httpd/conf.d/eprints.conf or /etc/apache2/sites-enabled/eprints.conf.
  • Includes Shibboleth configuration that is ultimately exempted from being proxied via Anubis
  • Logs names based on those used for RHEL-based Linux, changes may be required for Debian-based Linux (e.g Ubuntu).
<VirtualHost *:443>
 
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"

LogFormat "%h %T %l %u %t \"%r\" %>s %b \"%{Accept-Language}i\" \"%{Referer}i\" \"%{User-agent}i\" \"%{techaro.lol-anubis-cookie-verification}C\""
ErrorLog    /var/log/httpd/ssl_error_log
TransferLog /var/log/httpd/ssl_access_log
LogLevel warn

SSLEngine on
SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
SSLHonorCipherOrder on
SSLCompression off
SSLSessionTickets off
SSLCipherSuite ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE- RSA-AES128-GCM-SHA256

SSLCertificateFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.crt
SSLCertificateKeyFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.key
SSLCertificateChainFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.ca-bundle

Include EPRINTS_PATH/cfg/apache_ssl/ARCHIVE_ID.conf

Alias /shibboleth EPRINTS_PATH/archives/ARCHIVE_ID/shibboleth
<Location "/shibboleth">
  SetHandler perl-script
  PerlHandler ModPerl::Registry
  PerlSendHeader Off
  Options ExecCGI FollowSymLinks
  
  AuthType shibboleth
  ShibRequestSetting requireSession 1
  require shib-session
  PerlSetVar EPrints_ArchiveID reading
</Location>

<Location /cgi/shibboleth>
  AuthType shibboleth
  ShibRequestSetting requireSession 1
  require shib-session
</Location>

PerlTransHandler +EPrints::Apache::Rewrite

</VirtualHost>

EPRINTS_PATH/cfg/apache_ssl/ARCHIVE_ID.conf

EPRINTS_PATH/cfg/apache/ARCHIVE_ID.conf