Difference between revisions of "Apache Configuration for EPrints with Anubis"
(Reordered config files) |
(Adding organisation of configuration) |
||
| Line 11: | Line 11: | ||
| '''HOSTNAME''' || The hostname of the EPrints repository archive. || <code>eprints.example.org</code> | | '''HOSTNAME''' || The hostname of the EPrints repository archive. || <code>eprints.example.org</code> | ||
|} | |} | ||
| + | |||
| + | == Organisation of Configuration == | ||
| + | * /etc/httpd/conf.d/eprints.conf | ||
| + | ** EPRINTS_PATH/cfg/apache.conf | ||
| + | *** EPRINTS_PATH/cfg/apache/*.conf | ||
| + | **** EPRINTS_PATH/cfg/perl_module_isolation.conf | ||
| + | **** EPRINTS_PATH/cfg/apache/ARCHIVE_ID_http_to_https_redirect.conf | ||
| + | **** EPRINTS_PATH/cfg/apache/ARCHIVE_ID.conf | ||
| + | ** EPRINTS_PATH/archives/*/securevhost.conf | ||
| + | *** EPRINTS_PATH/cfg/apache_ssl/ARCHIVE_ID.conf | ||
| + | |||
=== Apache Level Configuration (/etc/httpd/conf.d/eprints.conf or /etc/apache2/sites-enabled/eprints.conf) === | === Apache Level Configuration (/etc/httpd/conf.d/eprints.conf or /etc/apache2/sites-enabled/eprints.conf) === | ||
| Line 28: | Line 39: | ||
# Load the perl modules & repository configurations | # Load the perl modules & repository configurations | ||
PerlSwitches -I/opt/eprints3/perl_lib | PerlSwitches -I/opt/eprints3/perl_lib | ||
| − | Include | + | Include EPRINTS_PATH/cfg/perl_module_isolation.conf |
# Load the per-repository apache configuration | # Load the per-repository apache configuration | ||
| − | Include /opt/eprints3/ | + | Include EPRINTS_PATH/cfg/apache/*.conf |
| + | |||
| + | === EPrints level Perl Module Isolation (EPRINTS_PATH/cfg/ | ||
| + | ##This file is included by apache.conf -- Do not edit this file directly. | ||
| + | ##You should edit the perl_module_isolation flag in /opt/eprints3/perl_lib/EPrints/SystemSettings.pm, then run /opt/eprints3/bin/generate_apacheconf --system --replace to regenerate this file. | ||
| + | |||
| + | ##The following two lines turn the perl_module_isolation OFF (All repositories now sharing a single perl interpreter and have access to all perl modules.) | ||
| + | PerlModule EPrints | ||
| + | PerlPostConfigHandler +EPrints::post_config_handler | ||
| − | === Archive Level HTTP VirtualHost HTTP-to-HTTPS Redirect ( | + | === Archive Level HTTP VirtualHost HTTP-to-HTTPS Redirect (ARCHIVE_ID_http_to_https_redirect.conf) === |
# | # | ||
# apache.conf include file for ARCHIVE_ID | # apache.conf include file for ARCHIVE_ID | ||
| Line 51: | Line 70: | ||
=== Archive Level HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf) === | === Archive Level HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf) === | ||
| − | |||
| − | |||
* Includes Shibboleth configuration that is ultimately exempted from being proxied via Anubis | * Includes Shibboleth configuration that is ultimately exempted from being proxied via Anubis | ||
* Logs names based on those used for RHEL-based Linux, changes may be required for Debian-based Linux (e.g Ubuntu). | * Logs names based on those used for RHEL-based Linux, changes may be required for Debian-based Linux (e.g Ubuntu). | ||
| Line 100: | Line 117: | ||
</VirtualHost> | </VirtualHost> | ||
| + | |||
=== Archive Level Internal HTTP VirtualHost (EPRINTS_PATH/cfg/apache/ARCHIVE_ID.conf) === | === Archive Level Internal HTTP VirtualHost (EPRINTS_PATH/cfg/apache/ARCHIVE_ID.conf) === | ||
| Line 150: | Line 168: | ||
RemoteIPTrustedProxy ::1 | RemoteIPTrustedProxy ::1 | ||
</IfModule> | </IfModule> | ||
| + | </VirtualHost> | ||
| + | |||
| + | === Archive Level HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf) === | ||
| + | * Includes Shibboleth configuration that is ultimately exempted from being proxied via Anubis | ||
| + | * Logs names based on those used for RHEL-based Linux, changes may be required for Debian-based Linux (e.g Ubuntu). | ||
| + | |||
| + | <VirtualHost *:443> | ||
| + | |||
| + | Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" | ||
| + | |||
| + | LogFormat "%h %T %l %u %t \"%r\" %>s %b \"%{Accept-Language}i\" \"%{Referer}i\" \"%{User-agent}i\" \"%{techaro.lol-anubis-cookie-verification}C\"" | ||
| + | ErrorLog /var/log/httpd/ssl_error_log | ||
| + | TransferLog /var/log/httpd/ssl_access_log | ||
| + | LogLevel warn | ||
| + | |||
| + | SSLEngine on | ||
| + | SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1 | ||
| + | SSLHonorCipherOrder on | ||
| + | SSLCompression off | ||
| + | SSLSessionTickets off | ||
| + | SSLCipherSuite ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE- RSA-AES128-GCM-SHA256 | ||
| + | |||
| + | SSLCertificateFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.crt | ||
| + | SSLCertificateKeyFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.key | ||
| + | SSLCertificateChainFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.ca-bundle | ||
| + | |||
| + | Include EPRINTS_PATH/cfg/apache_ssl/ARCHIVE_ID.conf | ||
| + | |||
| + | Alias /shibboleth EPRINTS_PATH/archives/ARCHIVE_ID/shibboleth | ||
| + | <Location "/shibboleth"> | ||
| + | SetHandler perl-script | ||
| + | PerlHandler ModPerl::Registry | ||
| + | PerlSendHeader Off | ||
| + | Options ExecCGI FollowSymLinks | ||
| + | |||
| + | AuthType shibboleth | ||
| + | ShibRequestSetting requireSession 1 | ||
| + | require shib-session | ||
| + | PerlSetVar EPrints_ArchiveID reading | ||
| + | </Location> | ||
| + | |||
| + | <Location /cgi/shibboleth> | ||
| + | AuthType shibboleth | ||
| + | ShibRequestSetting requireSession 1 | ||
| + | require shib-session | ||
| + | </Location> | ||
| + | |||
| + | PerlTransHandler +EPrints::Apache::Rewrite | ||
| + | |||
</VirtualHost> | </VirtualHost> | ||
Revision as of 12:42, 24 August 2026
The following placeholders are used within these configuration files:
| Placeholder | Description | Example |
|---|---|---|
| ADMIN_EMAIL | The email address for the EPrints repository archive's administrator. | eprints@example.org
|
| ARCHIVE_ID | ID of the specific EPrints repository archive. | example_org
|
| EPRINTS_PATH | Path to EPrints installation. | /opt/eprints3
|
| HOSTNAME | The hostname of the EPrints repository archive. | eprints.example.org
|
Contents
- 1 Organisation of Configuration
- 1.1 Apache Level Configuration (/etc/httpd/conf.d/eprints.conf or /etc/apache2/sites-enabled/eprints.conf)
- 1.2 EPrints level HTTP VirtualHost (EPRINTS_PATH/cfg/apache.conf)
- 1.3 Archive Level HTTP VirtualHost HTTP-to-HTTPS Redirect (ARCHIVE_ID_http_to_https_redirect.conf)
- 1.4 Archive Level HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf)
- 1.5 Archive Level Internal HTTP VirtualHost (EPRINTS_PATH/cfg/apache/ARCHIVE_ID.conf)
- 1.6 Archive Level HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf)
- 1.7 Archive Level Anubis Proxy for HTTPS VirtualHost (EPRINTS_PATH/cfg/apache_ssl/ARCHIVE_ID.conf)
Organisation of Configuration
- /etc/httpd/conf.d/eprints.conf
- EPRINTS_PATH/cfg/apache.conf
- EPRINTS_PATH/cfg/apache/*.conf
- EPRINTS_PATH/cfg/perl_module_isolation.conf
- EPRINTS_PATH/cfg/apache/ARCHIVE_ID_http_to_https_redirect.conf
- EPRINTS_PATH/cfg/apache/ARCHIVE_ID.conf
- EPRINTS_PATH/cfg/apache/*.conf
- EPRINTS_PATH/archives/*/securevhost.conf
- EPRINTS_PATH/cfg/apache_ssl/ARCHIVE_ID.conf
- EPRINTS_PATH/cfg/apache.conf
Apache Level Configuration (/etc/httpd/conf.d/eprints.conf or /etc/apache2/sites-enabled/eprints.conf)
Include EPRINTS_PATH/cfg/apache.conf Include EPRINTS_PATH/archives/*/securevhost.conf
EPrints level HTTP VirtualHost (EPRINTS_PATH/cfg/apache.conf)
# # apache.conf include file for EPrints # # Any changes made here will be lost if you run generate_apacheconf_for_anubis # # EPrints moved to be internal-only, with Anubis facing the outside world. Listen [::1]:3000 # Load the perl modules & repository configurations PerlSwitches -I/opt/eprints3/perl_lib Include EPRINTS_PATH/cfg/perl_module_isolation.conf # Load the per-repository apache configuration Include EPRINTS_PATH/cfg/apache/*.conf
=== EPrints level Perl Module Isolation (EPRINTS_PATH/cfg/
##This file is included by apache.conf -- Do not edit this file directly. ##You should edit the perl_module_isolation flag in /opt/eprints3/perl_lib/EPrints/SystemSettings.pm, then run /opt/eprints3/bin/generate_apacheconf --system --replace to regenerate this file. ##The following two lines turn the perl_module_isolation OFF (All repositories now sharing a single perl interpreter and have access to all perl modules.) PerlModule EPrints PerlPostConfigHandler +EPrints::post_config_handler
Archive Level HTTP VirtualHost HTTP-to-HTTPS Redirect (ARCHIVE_ID_http_to_https_redirect.conf)
# # apache.conf include file for ARCHIVE_ID # # Any changes made here will be lost if you run generate_apacheconf # or generate_apacheconf for anubis with the --replace option # # The main virtual host for this repository <VirtualHost *:80> ServerName HOSTNAME ServerAdmin ADMIN_EMAIL RedirectPermanent / https://HOSTNAME/ </VirtualHost>
Archive Level HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf)
- Includes Shibboleth configuration that is ultimately exempted from being proxied via Anubis
- Logs names based on those used for RHEL-based Linux, changes may be required for Debian-based Linux (e.g Ubuntu).
<VirtualHost *:443>
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
LogFormat "%h %T %l %u %t \"%r\" %>s %b \"%{Accept-Language}i\" \"%{Referer}i\" \"%{User-agent}i\" \"%{techaro.lol-anubis-cookie-verification}C\""
ErrorLog /var/log/httpd/ssl_error_log
TransferLog /var/log/httpd/ssl_access_log
LogLevel warn
SSLEngine on
SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
SSLHonorCipherOrder on
SSLCompression off
SSLSessionTickets off
SSLCipherSuite ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE- RSA-AES128-GCM-SHA256
SSLCertificateFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.crt
SSLCertificateKeyFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.key
SSLCertificateChainFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.ca-bundle
Include EPRINTS_PATH/cfg/apache_ssl/ARCHIVE_ID.conf
Alias /shibboleth EPRINTS_PATH/archives/ARCHIVE_ID/shibboleth
<Location "/shibboleth">
SetHandler perl-script
PerlHandler ModPerl::Registry
PerlSendHeader Off
Options ExecCGI FollowSymLinks
AuthType shibboleth
ShibRequestSetting requireSession 1
require shib-session
PerlSetVar EPrints_ArchiveID reading
</Location>
<Location /cgi/shibboleth>
AuthType shibboleth
ShibRequestSetting requireSession 1
require shib-session
</Location>
PerlTransHandler +EPrints::Apache::Rewrite
</VirtualHost>
Archive Level Internal HTTP VirtualHost (EPRINTS_PATH/cfg/apache/ARCHIVE_ID.conf)
#
# apache.conf include file for ARCHIVE_ID
#
# Any changes made here will be lost if you run generate_apacheconf
# or generate_apacheconf_for_anubis with the --replace option
#
# The main virtual host for this repository
<VirtualHost *:3000>
ServerName HOSTNAME
# This file configures the apache logs of EPrints itself. Only requests passed through anubis to EPrints can make it this far.
# This file will not be overwritten by generate_apacheconf_for_anubis, so you can modify it.
LogFormat "%h %T %l %u %t \"%r\" %>s %b \"%{Accept-Language}i\" \"%{Referer}i\" \"%{User-agent}i\" \"%{techaro.lol-anubis-cookie-verification}C\""
ErrorLog /var/log/httpd/eprints_internal_error_log
TransferLog /var/log/httpd/eprints_internal_access_log
ServerAdmin ADMIN_EMAIL
Include EPRINTS_PATH/cfg/perl_module_isolation_vhost.conf
<Location "">
PerlSetVar EPrints_ArchiveID ARCHIVE_ID
PerlSetVar EPrints_Secure yes
Options +ExecCGI
<IfModule mod_authz_core.c>
Require all granted
</IfModule>
<IfModule !mod_authz_core.c>
Order allow,deny
Allow from all
</IfModule>
</Location>
# Set by $c->{max_upload_filesize}
LimitRequestBody 1073741824
# Note that PerlTransHandler can't go inside
# a "Location" block as it occurs before the
# Location is known.
PerlTransHandler +EPrints::Apache::Rewrite
# Get the real remote IP back, otherwise all accesses appear to come from ::1
<IfModule remoteip_module>
RemoteIPHeader X-Real-Ip
RemoteIPTrustedProxy ::1
</IfModule>
</VirtualHost>
Archive Level HTTPS Virtualhost (EPRINTS_PATH/archives/ARCHIVE_ID/ssl/securevhost.conf)
- Includes Shibboleth configuration that is ultimately exempted from being proxied via Anubis
- Logs names based on those used for RHEL-based Linux, changes may be required for Debian-based Linux (e.g Ubuntu).
<VirtualHost *:443>
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
LogFormat "%h %T %l %u %t \"%r\" %>s %b \"%{Accept-Language}i\" \"%{Referer}i\" \"%{User-agent}i\" \"%{techaro.lol-anubis-cookie-verification}C\""
ErrorLog /var/log/httpd/ssl_error_log
TransferLog /var/log/httpd/ssl_access_log
LogLevel warn
SSLEngine on
SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
SSLHonorCipherOrder on
SSLCompression off
SSLSessionTickets off
SSLCipherSuite ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE- RSA-AES128-GCM-SHA256
SSLCertificateFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.crt
SSLCertificateKeyFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.key
SSLCertificateChainFile EPRINTS_PATH/archives/ARCHIVE_ID/ssl/HOSTNAME.ca-bundle
Include EPRINTS_PATH/cfg/apache_ssl/ARCHIVE_ID.conf
Alias /shibboleth EPRINTS_PATH/archives/ARCHIVE_ID/shibboleth
<Location "/shibboleth">
SetHandler perl-script
PerlHandler ModPerl::Registry
PerlSendHeader Off
Options ExecCGI FollowSymLinks
AuthType shibboleth
ShibRequestSetting requireSession 1
require shib-session
PerlSetVar EPrints_ArchiveID reading
</Location>
<Location /cgi/shibboleth>
AuthType shibboleth
ShibRequestSetting requireSession 1
require shib-session
</Location>
PerlTransHandler +EPrints::Apache::Rewrite
</VirtualHost>
Archive Level Anubis Proxy for HTTPS VirtualHost (EPRINTS_PATH/cfg/apache_ssl/ARCHIVE_ID.conf)
# HTTPS listener that forwards to Anubis
# These headers need to be set or else Anubis will
# throw an "admin misconfiguration" error.
RequestHeader set "X-Real-Ip" expr=%{REMOTE_ADDR}
RequestHeader set X-Forwarded-Proto "https"
RequestHeader set "X-Http-Version" "%{SERVER_PROTOCOL}s"
ProxyPreserveHost On
ProxyRequests Off
ProxyVia Off
ProxyTimeout 300
# don't try and proxy shibboleth.
ProxyPass /Shibboleth.sso !
ProxyPass /shibboleth !
ProxyPass /cgi/shibboleth !
# Replace 8923 with the port Anubis listens on
ProxyPass / http://[::1]:8923/
ProxyPassReverse / http://[::1]:8923/