--
You received this message because you are subscribed to the Google Groups "Dataverse Users Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsub...@googlegroups.com.
To post to this group, send email to dataverse-community@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/9674d03a-b0aa-4174-ac3c-e08c13c30451%40googlegroups.com.
Thanks, Don. Venki, I'm wondering if you'd be able to find someone to write a SELinux Type Enforcement (TE) file to make Shibboleth work with SELinux and contribute that file to the Shibboleth project. That's my first suggestion is this issue I just opened: https://github.com/IQSS/dataverse/issues/3406
On Thu, Oct 13, 2016 at 9:11 AM, Donald Sizemore II <don.si...@gmail.com> wrote:
Hello from Chapel Hill!
As you've noted, Shibboleth with SELinux is the sticking point, as per Phil and other members of the Dataverse IRC channel, Dataverse functions fine with SELinux enforcing.
Dataverse.unc.edu is running RHEL7 with Shibboleth 2.6, with each service (glassfish, httpd, rserve, shibd) running as separate, non-privileged users.
The machine runs a host-based firewall and sits behind a hardware firewall and our campus IDS tipping points, and our campus satellite server alerts me to security patches.
Our Apache config is pretty much identical to http://guides.dataverse.org/en/latest/installation/shibboleth.html#configure-apache though we allow an additional ProxyPassMatch for an images/ subdirectory for our Shib SP logo.
Does this help?
Donald
--
You received this message because you are subscribed to the Google Groups "Dataverse Users Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsub...@googlegroups.com.
To post to this group, send email to dataverse...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/9674d03a-b0aa-4174-ac3c-e08c13c30451%40googlegroups.com.
Thanks Phil for the suggestion. Yes my IT colleague was suggesting to me that he would check the logs and add new rules to allow those that fails when using Shibboleth. But my worry was what if the issue couldnt be resolved and I am told not to use Shibboleth. That was why I am checking now to prepare for the worst case scenario. Donald's reply would be a good response that I can share to say how others have secured their servers.
As I told Donald, will keep you all updated once I hear from my IT colleague.Thanks and Regards
Venki
On Friday, October 14, 2016 at 10:56:30 PM UTC+8, Philip Durbin wrote:
Thanks, Don. Venki, I'm wondering if you'd be able to find someone to write a SELinux Type Enforcement (TE) file to make Shibboleth work with SELinux and contribute that file to the Shibboleth project. That's my first suggestion is this issue I just opened: https://github.com/IQSS/dataverse/issues/3406
On Thu, Oct 13, 2016 at 9:11 AM, Donald Sizemore II <don.si...@gmail.com> wrote:
Hello from Chapel Hill!
As you've noted, Shibboleth with SELinux is the sticking point, as per Phil and other members of the Dataverse IRC channel, Dataverse functions fine with SELinux enforcing.
Dataverse.unc.edu is running RHEL7 with Shibboleth 2.6, with each service (glassfish, httpd, rserve, shibd) running as separate, non-privileged users.
The machine runs a host-based firewall and sits behind a hardware firewall and our campus IDS tipping points, and our campus satellite server alerts me to security patches.
Our Apache config is pretty much identical to http://guides.dataverse.org/en/latest/installation/shibboleth.html#configure-apache though we allow an additional ProxyPassMatch for an images/ subdirectory for our Shib SP logo.
Does this help?
Donald
--
You received this message because you are subscribed to the Google Groups "Dataverse Users Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsubscribe...@googlegroups.com.
To post to this group, send email to dataverse...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/9674d03a-b0aa-4174-ac3c-e08c13c30451%40googlegroups.com.
--Philip Durbin
Software Developer for http://dataverse.org
http://www.iq.harvard.edu/people/philip-durbin
--
You received this message because you are subscribed to the Google Groups "Dataverse Users Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsub...@googlegroups.com.
To post to this group, send email to dataverse-community@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/f83116b9-c8c7-4407-a066-ab4efe584b3f%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-commu...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/CABbxx8FngO7%2BudrqD-PMQY00SXddVeET5rEiL3for_3veFdnRw%40mail.gmail.com.
To post to this group, send email to dataverse-community@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/f83116b9-c8c7-4407-a066-ab4efe584b3f%40googlegroups.com.
--Philip Durbin
Software Developer for http://dataverse.org
http://www.iq.harvard.edu/people/philip-durbin
--
You received this message because you are subscribed to the Google Groups "Dataverse Users Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsub...@googlegroups.com.
To post to this group, send email to dataverse-community@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/CABbxx8FngO7%2BudrqD-PMQY00SXddVeET5rEiL3for_3veFdnRw%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Dataverse Users Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsub...@googlegroups.com.
To post to this group, send email to dataverse-community@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/F73BFC83-454A-46E1-8CC9-FC38CACA83E5%40gmail.com.
So here are the steps that he has taken on RHEL7 server to support Shibboleth while keeping SELinux in enforcing mode.
(1) Label httpd_sys_content_t
# semanage fcontext -a -t httpd_sys_content_t "/var/cache/shibboleth(/.*)?"
(2) Label httpd_sys_rw_content_t
# semanage fcontext -a -t httpd_sys_rw_content_t '/var/run/shibboleth/shibd.sock'
(3) Extend shibd.service configuration
# mkdir /etc/systemd/system/shibd.service.d/
Create new file /etc/systemd/system/shibd.service.d/extend.conf with contents:
[Service]
ExecStartPost=/sbin/restorecon -R /var/run/shibboleth /var/cache/shibboleth
# systemctl daemon-reload
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsub...@googlegroups.com.
To post to this group, send email to dataverse...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/9674d03a-b0aa-4174-ac3c-e08c13c30451%40googlegroups.com.
--Philip Durbin
Software Developer for http://dataverse.org
http://www.iq.harvard.edu/people/philip-durbin
--
You received this message because you are subscribed to the Google Groups "Dataverse Users Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsub...@googlegroups.com.
To post to this group, send email to dataverse...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/f83116b9-c8c7-4407-a066-ab4efe584b3f%40googlegroups.com.
--Philip Durbin
Software Developer for http://dataverse.org
http://www.iq.harvard.edu/people/philip-durbin
--
You received this message because you are subscribed to the Google Groups "Dataverse Users Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsub...@googlegroups.com.
To post to this group, send email to dataverse...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/CABbxx8FngO7%2BudrqD-PMQY00SXddVeET5rEiL3for_3veFdnRw%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Dataverse Users Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsub...@googlegroups.com.
To post to this group, send email to dataverse...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/F73BFC83-454A-46E1-8CC9-FC38CACA83E5%40gmail.com.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsubscribe...@googlegroups.com.
To post to this group, send email to dataverse...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/9674d03a-b0aa-4174-ac3c-e08c13c30451%40googlegroups.com.
--Philip Durbin
Software Developer for http://dataverse.org
http://www.iq.harvard.edu/people/philip-durbin
--
You received this message because you are subscribed to the Google Groups "Dataverse Users Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsubscribe...@googlegroups.com.
To post to this group, send email to dataverse...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/f83116b9-c8c7-4407-a066-ab4efe584b3f%40googlegroups.com.
--Philip Durbin
Software Developer for http://dataverse.org
http://www.iq.harvard.edu/people/philip-durbin
--
You received this message because you are subscribed to the Google Groups "Dataverse Users Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsubscribe...@googlegroups.com.
To post to this group, send email to dataverse...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/CABbxx8FngO7%2BudrqD-PMQY00SXddVeET5rEiL3for_3veFdnRw%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Dataverse Users Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsubscribe...@googlegroups.com.
To post to this group, send email to dataverse...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/F73BFC83-454A-46E1-8CC9-FC38CACA83E5%40gmail.com.
--Philip Durbin
Software Developer for http://dataverse.org
http://www.iq.harvard.edu/people/philip-durbin
--
You received this message because you are subscribed to the Google Groups "Dataverse Users Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dataverse-community+unsub...@googlegroups.com.
To post to this group, send email to dataverse-community@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dataverse-community/93c86737-36e7-44f9-9203-4ae37b640787%40googlegroups.com.