Difference between revisions of "Apache Configuration for EPrints with Anubis"
m |
(Added key) |
||
| Line 1: | Line 1: | ||
| + | The following placeholders are used within these configuration files: | ||
| + | {| class="wikitable" | ||
| + | ! Placeholder !! Description !! Example | ||
| + | |- | ||
| + | | '''EPRINTS_PATH''' || Path to EPrints installation. || <code>/opt/eprints3</code> | ||
| + | |- | ||
| + | | '''ARCHIVE_ID''' || ID of the specific EPrints repository archive. || <code>example_org</code> | ||
| + | |- | ||
| + | | '''HOSTNAME''' || The hostname of the EPrints repository archive. || <code>eprints.example.org</code> | ||
| + | |- | ||
| + | | '''ADMIN_EMAIL''' || The email address for the EPrints repository archive's administrator. || <code>eprints@example.org</code> | ||
| + | |} | ||
| + | |||
=== HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf) === | === HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf) === | ||
* Assumes inclusion of all archives' ssl/securevhost.conf's from /etc/httpd/conf.d/eprints.conf or /etc/apache2/sites-enabled/eprints.conf. | * Assumes inclusion of all archives' ssl/securevhost.conf's from /etc/httpd/conf.d/eprints.conf or /etc/apache2/sites-enabled/eprints.conf. | ||
| − | + | ||
* Includes Shibboleth configuration that is ultimately exempted from being proxied via Anubis | * Includes Shibboleth configuration that is ultimately exempted from being proxied via Anubis | ||
* Logs names based on those used for RHEL-based Linux, changes may be required for Debian-based Linux (e.g Ubuntu). | * Logs names based on those used for RHEL-based Linux, changes may be required for Debian-based Linux (e.g Ubuntu). | ||
| Line 48: | Line 61: | ||
PerlTransHandler +EPrints::Apache::Rewrite | PerlTransHandler +EPrints::Apache::Rewrite | ||
| − | </VirtualHost> | + | </VirtualHost> |
| + | |||
| + | === EPRINTS_PATH/cfg/apache_ssl/ARCHIVE_ID.conf === | ||
| + | |||
| + | |||
| + | === EPRINTS_PATH/cfg/apache/ARCHIVE_ID.conf === | ||
Revision as of 09:41, 24 August 2026
The following placeholders are used within these configuration files:
| Placeholder | Description | Example |
|---|---|---|
| EPRINTS_PATH | Path to EPrints installation. | /opt/eprints3
|
| ARCHIVE_ID | ID of the specific EPrints repository archive. | example_org
|
| HOSTNAME | The hostname of the EPrints repository archive. | eprints.example.org
|
| ADMIN_EMAIL | The email address for the EPrints repository archive's administrator. | eprints@example.org
|
HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf)
- Assumes inclusion of all archives' ssl/securevhost.conf's from /etc/httpd/conf.d/eprints.conf or /etc/apache2/sites-enabled/eprints.conf.
- Includes Shibboleth configuration that is ultimately exempted from being proxied via Anubis
- Logs names based on those used for RHEL-based Linux, changes may be required for Debian-based Linux (e.g Ubuntu).
<VirtualHost *:443>
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
LogFormat "%h %T %l %u %t \"%r\" %>s %b \"%{Accept-Language}i\" \"%{Referer}i\" \"%{User-agent}i\" \"%{techaro.lol-anubis-cookie-verification}C\""
ErrorLog /var/log/httpd/ssl_error_log
TransferLog /var/log/httpd/ssl_access_log
LogLevel warn
SSLEngine on
SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
SSLHonorCipherOrder on
SSLCompression off
SSLSessionTickets off
SSLCipherSuite ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE- RSA-AES128-GCM-SHA256
SSLCertificateFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.crt
SSLCertificateKeyFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.key
SSLCertificateChainFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.ca-bundle
Include EPRINTS_PATH/cfg/apache_ssl/ARCHIVE_ID.conf
Alias /shibboleth EPRINTS_PATH/archives/ARCHIVE_ID/shibboleth
<Location "/shibboleth">
SetHandler perl-script
PerlHandler ModPerl::Registry
PerlSendHeader Off
Options ExecCGI FollowSymLinks
AuthType shibboleth
ShibRequestSetting requireSession 1
require shib-session
PerlSetVar EPrints_ArchiveID reading
</Location>
<Location /cgi/shibboleth>
AuthType shibboleth
ShibRequestSetting requireSession 1
require shib-session
</Location>
PerlTransHandler +EPrints::Apache::Rewrite
</VirtualHost>