Difference between revisions of "Apache Configuration for EPrints with Anubis"

From EPrints Documentation
Jump to: navigation, search
m (HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf))
(added http_to_https_redirect.conf)
Line 86: Line 86:
 
  ProxyPass / http://[::1]:8923/
 
  ProxyPass / http://[::1]:8923/
 
  ProxyPassReverse / http://[::1]:8923/
 
  ProxyPassReverse / http://[::1]:8923/
 +
 +
=== EPRINTS_PATH/cfg/apache/ARCHIVE_ID_http_to_https_redirect.conf ===
 +
#
 +
# apache.conf include file for ARCHIVE_ID
 +
#
 +
# Any changes made here will be lost if you run generate_apacheconf
 +
# or generate_apacheconf for anubis with the --replace option
 +
#
 +
 +
# The main virtual host for this repository
 +
<VirtualHost *:80>
 +
  ServerName HOSTNAME
 +
 +
  ServerAdmin ADMIN_EMAIL
 +
 +
  RedirectPermanent / https://HOSTNAME/
 +
</VirtualHost>
  
 
=== EPRINTS_PATH/cfg/apache/ARCHIVE_ID.conf ===
 
=== EPRINTS_PATH/cfg/apache/ARCHIVE_ID.conf ===

Revision as of 10:28, 24 August 2026

The following placeholders are used within these configuration files:

Placeholder Description Example
ADMIN_EMAIL The email address for the EPrints repository archive's administrator. eprints@example.org
ARCHIVE_ID ID of the specific EPrints repository archive. example_org
EPRINTS_PATH Path to EPrints installation. /opt/eprints3
HOSTNAME The hostname of the EPrints repository archive. eprints.example.org

HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf)

  • Assumes inclusion of all archives' ssl/securevhost.conf's from /etc/httpd/conf.d/eprints.conf or /etc/apache2/sites-enabled/eprints.conf.
  • Includes Shibboleth configuration that is ultimately exempted from being proxied via Anubis
  • Logs names based on those used for RHEL-based Linux, changes may be required for Debian-based Linux (e.g Ubuntu).
<VirtualHost *:443>
 
  Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"

  LogFormat "%h %T %l %u %t \"%r\" %>s %b \"%{Accept-Language}i\" \"%{Referer}i\" \"%{User-agent}i\" \"%{techaro.lol-anubis-cookie-verification}C\""
  ErrorLog    /var/log/httpd/ssl_error_log
  TransferLog /var/log/httpd/ssl_access_log
  LogLevel warn

  SSLEngine on
  SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
  SSLHonorCipherOrder on
  SSLCompression off
  SSLSessionTickets off
  SSLCipherSuite ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE- RSA-AES128-GCM-SHA256

  SSLCertificateFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.crt
  SSLCertificateKeyFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.key
  SSLCertificateChainFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.ca-bundle

  Include EPRINTS_PATH/cfg/apache_ssl/ARCHIVE_ID.conf

  Alias /shibboleth EPRINTS_PATH/archives/ARCHIVE_ID/shibboleth
  <Location "/shibboleth">
    SetHandler perl-script
    PerlHandler ModPerl::Registry
    PerlSendHeader Off
    Options ExecCGI FollowSymLinks
  
    AuthType shibboleth
    ShibRequestSetting requireSession 1
    require shib-session
    PerlSetVar EPrints_ArchiveID reading
  </Location>

  <Location /cgi/shibboleth>
    AuthType shibboleth
    ShibRequestSetting requireSession 1
    require shib-session
  </Location>

  PerlTransHandler +EPrints::Apache::Rewrite

</VirtualHost>

EPRINTS_PATH/cfg/apache_ssl/ARCHIVE_ID.conf

# HTTPS listener that forwards to Anubis

# These headers need to be set or else Anubis will
# throw an "admin misconfiguration" error.
RequestHeader set "X-Real-Ip" expr=%{REMOTE_ADDR}
RequestHeader set X-Forwarded-Proto "https"
RequestHeader set "X-Http-Version" "%{SERVER_PROTOCOL}s"

ProxyPreserveHost On

ProxyRequests Off
ProxyVia Off
ProxyTimeout 300

# don't try and proxy shibboleth.
ProxyPass /Shibboleth.sso !
ProxyPass /shibboleth !
ProxyPass /cgi/shibboleth !

# Replace 8923 with the port Anubis listens on
ProxyPass / http://[::1]:8923/
ProxyPassReverse / http://[::1]:8923/

EPRINTS_PATH/cfg/apache/ARCHIVE_ID_http_to_https_redirect.conf

#
# apache.conf include file for ARCHIVE_ID
#
# Any changes made here will be lost if you run generate_apacheconf
# or generate_apacheconf for anubis with the --replace option
#

# The main virtual host for this repository
<VirtualHost *:80>
  ServerName HOSTNAME

  ServerAdmin ADMIN_EMAIL

  RedirectPermanent / https://HOSTNAME/
</VirtualHost>

EPRINTS_PATH/cfg/apache/ARCHIVE_ID.conf

#
# apache.conf include file for ARCHIVE_ID
#
# Any changes made here will be lost if you run generate_apacheconf 
# or generate_apacheconf_for_anubis with the --replace option
#

# The main virtual host for this repository
<VirtualHost *:3000>
  ServerName HOSTNAME

  Include EPRINTS_PATH/cfg/apache/ARCHIVE_ID.logging.conf

  ServerAdmin ADMIN_EMAIL

  Include EPRINTS_PATH/cfg/perl_module_isolation_vhost.conf

  <Location "">
    PerlSetVar EPrints_ArchiveID ARCHIVE_ID
    PerlSetVar EPrints_Secure yes

    Options +ExecCGI
    <IfModule mod_authz_core.c>
       Require all granted
    </IfModule>
    <IfModule !mod_authz_core.c>
       Order allow,deny
       Allow from all
    </IfModule>
  </Location>
 
  # Set by $c->{max_upload_filesize}
  LimitRequestBody 1073741824

  # Note that PerlTransHandler can't go inside
  # a "Location" block as it occurs before the
  # Location is known.
  PerlTransHandler +EPrints::Apache::Rewrite

  # Get the real remote IP back, otherwise all accesses appear to come from ::1
  <IfModule remoteip_module>
    RemoteIPHeader X-Real-Ip
    RemoteIPTrustedProxy ::1
  </IfModule>
</VirtualHost>