diff --git a/demw-common/overlay/etc/Chrystoki.conf.d/50-ha-slot.conf b/demw-common/overlay/etc/Chrystoki.conf.d/50-ha-slot.conf index 2a3b0f05..a6e7a8e0 100644 --- a/demw-common/overlay/etc/Chrystoki.conf.d/50-ha-slot.conf +++ b/demw-common/overlay/etc/Chrystoki.conf.d/50-ha-slot.conf @@ -1,8 +1,9 @@ VirtualToken = { VirtualToken00Label = sc_ha; VirtualToken00SN = 1462371088; - VirtualToken00Members = 462371088,462344047; + VirtualToken00Members = 462371088,610237018; } HASynchronize = { sc_ha = 1; } + diff --git a/demw-common/overlay/etc/luna/cert/server/se-fre-hsm1.sunet.seCert.pem b/demw-common/overlay/etc/luna/cert/server/se-fre-hsm1.sunet.seCert.pem deleted file mode 100644 index 61021633..00000000 --- a/demw-common/overlay/etc/luna/cert/server/se-fre-hsm1.sunet.seCert.pem +++ /dev/null @@ -1,20 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIDNTCCAh2gAwIBAgIBADANBgkqhkiG9w0BAQsFADBeMQswCQYDVQQGEwJDQTEQ -MA4GA1UECBMHT250YXJpbzEPMA0GA1UEBxMGT3R0YXdhMRYwFAYDVQQKEw1DaHJ5 -c2FsaXMtSVRTMRQwEgYDVQQDEwtzZS1mcmUtaHNtMTAeFw0xNDEyMDIxMzM4MjNa -Fw0yNDEyMDMxMzM4MjNaMF4xCzAJBgNVBAYTAkNBMRAwDgYDVQQIEwdPbnRhcmlv -MQ8wDQYDVQQHEwZPdHRhd2ExFjAUBgNVBAoTDUNocnlzYWxpcy1JVFMxFDASBgNV -BAMTC3NlLWZyZS1oc20xMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA -xHF8rOA8N1TAoo9KE1PPRThOppYyHwGZmhWccpu7uGFBBL8sHozCUvhdJq1IJyks -+OCKeu8ai5bHFLK2HvSiwqKD1W+AMoUr3EmA21J+vmybiBDyMi7hiRuimjRGMQMh -f4LCRbIr53jz499KzexO7xZruEyUbB4Dfl1KOOVvPm0WFXiuj2fV7vyFb+B3U/A6 -v1hS4KAAv4+hq3ZEXUaLzpzZr/MPrrNBfda4PwhOkNm+5qNFuMCzPhEc9IO6fQEo -kNO3DuWKwi424thIUJxCLbGLF2V4AdL13CxZOLRWPK631MhcUzZVbgIxPPTxueXx -ogwA9QS6tR/hO1xMmqYgHwIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQBQHNJK6qU8 -dSbqUOs/2hHMdgWLXaCtxlqiLE+IQ8gQ3Of8EAIXSAiucmp3lxgCzJSqCTHLybnH -/LGS2GbBstxFUdNoZR3+tAtWonQeR08I1oa/b6vZ8VSTvXnnxlCjm/BRD6OqNkCc -f4Ran2nmzVwFyNwv+fgn97cfq9oLgMOtW2hMtToegOF2nF1mvG+cs0t0aWrNrmKS -qj6tTr6REOdczrhQA3+SKhO1GyP5w1re0NsyzUecCgOPRm+sbwVg+fb5pTDTOkQa -S3whqFAx9MHVQHglKlLXLGXSCakc2Kg4USu+W/ByzTJUiy0yCZWpzy1p+bgY6VBa -Ypdn2oG8USY6 ------END CERTIFICATE----- diff --git a/demw-common/overlay/etc/luna/cert/server/se-sthb-hsm1.sunet.seCert.pem b/demw-common/overlay/etc/luna/cert/server/se-sthb-hsm1.sunet.seCert.pem new file mode 100644 index 00000000..a6367a4c --- /dev/null +++ b/demw-common/overlay/etc/luna/cert/server/se-sthb-hsm1.sunet.seCert.pem @@ -0,0 +1,20 @@ +-----BEGIN CERTIFICATE----- +MIIDNzCCAh+gAwIBAgIBADANBgkqhkiG9w0BAQsFADBfMQswCQYDVQQGEwJDQTEQ +MA4GA1UECBMHT250YXJpbzEPMA0GA1UEBxMGT3R0YXdhMRYwFAYDVQQKEw1DaHJ5 +c2FsaXMtSVRTMRUwEwYDVQQDEwxzZS1zdGhiLWhzbTEwHhcNMTkxMTE0MTAzNzQ5 +WhcNMjkxMTE1MTAzNzQ5WjBfMQswCQYDVQQGEwJDQTEQMA4GA1UECBMHT250YXJp +bzEPMA0GA1UEBxMGT3R0YXdhMRYwFAYDVQQKEw1DaHJ5c2FsaXMtSVRTMRUwEwYD +VQQDEwxzZS1zdGhiLWhzbTEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB +AQDezC8rs+iioz6L5r3Bai6hPr1oZeh5MhzHnW+pDKr7/8A1ZyDkAlQGbLjSN8ES +zhnhm8oZQ2BkVbey4WWvWNAHqVLB1xaz1iGUMyTQ2r52UHTo9TBtYhtoTAc4NB/O +ETuyaDEuB4MFHDwKsGjIEQFeCjEQurNWjDLJGtckgjyIFnLxd1DZk1xmG2SJMpNU +2yLGYo72QW3jwnrTDb6/U6tiwfTCI42obNQmtp4Q7h8KaJLkYIQf45ZT+kvx3MED +SwnylvDc3egakE8r1op+nrhoujfUhXbzeSreH6h16ZshZ565CPyebIFTmuqNzAc9 ++7yZVY8WFc8662wmWGOpnu4DAgMBAAEwDQYJKoZIhvcNAQELBQADggEBALOh6xgt ++i93/1ewiBeDyaBxsYUmx4DQQCfL6Ia3FYC1CradvJpA8Y/O8MPpgZAjI0Sw8PFd +yKaBg4H8dv7ePfFD9BjSXjzMj8VC/4mk9k1XRRTjM8e0ZKPmIG0ul5MJ+IF93Ote +lzNBJg5uiXeSNcc/GNt3oO7ZbwGORiISMu0Lf5I6onubjepbbPc1LTEcUJn9tejT +WMDMcuZEu8ZydZP5fWgCZZ/yO6BGTwk9FPQ5rZbUw9CCebfeQuGd8Emgx3VTz6F3 +D0N5iUR0S1RY69WGYf8GvJPfI11+f3mrZAiI7bS+P9nE7NwUk+8JB2+RHhDdrN2B +54nRGITJJFyFwf4= +-----END CERTIFICATE----- diff --git a/eidas-connector-common/overlay/etc/eidas-connector/eidas-connector.conf b/eidas-connector-common/overlay/etc/eidas-connector/eidas-connector.conf index 909577e7..394d3787 100644 --- a/eidas-connector-common/overlay/etc/eidas-connector/eidas-connector.conf +++ b/eidas-connector-common/overlay/etc/eidas-connector/eidas-connector.conf @@ -25,6 +25,10 @@ export IDP_PROCESS_SYSLOG_PORT=514 export IDP_AUDIT_SYSLOG_FACILITY=LOCAL0 +export IDP_STATS_SYSLOG_HOST=log-1.sveidas.se +export IDP_STATS_SYSLOG_PORT=514 +export IDP_STATS_SYSLOG_FACILITY=LOCAL4 + export IDP_FTICKS_FEDERATION_ID=eIDAS export IDP_FTICKS_SYSLOG_FACILITY=LOCAL1 export IDP_PROCESS_SYSLOG_FACILITY=LOCAL2 @@ -76,11 +80,11 @@ export TOMCAT_TLS_SERVER_KEY=$TOMCAT_CREDENTIALS/tomcat-key.pem export TOMCAT_TLS_SERVER_CERTIFICATE=$TOMCAT_CREDENTIALS/tomcat-cert.pem export TOMCAT_TLS_SERVER_CERTIFICATE_CHAIN=$TOMCAT_CREDENTIALS/tomcat-chain.pem -FEDERATION_METADATA_URL=https://md.swedenconnect.se/entities -FEDERATION_METADATA_VALIDATION_CERT=/etc/eidas-connector/credentials/swedenconnect-signer.crt +export FEDERATION_METADATA_URL=https://md.swedenconnect.se/entities +export FEDERATION_METADATA_VALIDATION_CERT=/etc/eidas-connector/credentials/swedenconnect-signer.crt -EIDAS_METADATA_SERVICE_LIST_URL=https://md.eidas.swedenconnect.se/mdservicelist-aggregate.xml -EIDAS_METADATA_SERVICE_LIST_VALIDATION_CERT=/etc/eidas-connector/credentials/swedenconnect-signer.crt +unset EIDAS_METADATA_SERVICE_LIST_URL=https://md.eidas.swedenconnect.se/mdservicelist-aggregate.xml +unset EIDAS_METADATA_SERVICE_LIST_VALIDATION_CERT=/etc/eidas-connector/credentials/swedenconnect-signer.crt EIDAS_METADATA_URL=https://md.eidas.swedenconnect.se/role/idp.xml EIDAS_METADATA_VALIDATION_CERT=/etc/eidas-connector/credentials/swedenconnect-signer.crt diff --git a/global/overlay/etc/cosmos/keys/SaluUpadhyay-7B44FE7C.pub b/global/overlay/etc/cosmos/keys/SaluUpadhyay-7B44FE7C.pub index f0f90769..0babda59 100644 --- a/global/overlay/etc/cosmos/keys/SaluUpadhyay-7B44FE7C.pub +++ b/global/overlay/etc/cosmos/keys/SaluUpadhyay-7B44FE7C.pub @@ -6,48 +6,139 @@ X/cn4pkMwYBS0NtHtg0yvdMSdK0oj6OGDyprh529cwJVqiehG+5rEN+JHrO1imuL W6eT6ERvyo5qbVwi21v4xZITisKjTQoVNcMA2FF/2kaLlCDpwWOvfF2BeCaYUk5X yIUas306HhPKWA/FOoD66r4LskDNKuPuUZx7P24V2JVExuDy6gt56EdZPH039WI1 E+YuJqaJBlDcIzLAqRSAT+n2gZm9u/1L/83NABEBAAG0HVNhbHUgVXBhZGh5YXkg -PHNhbHVAc3VuZXQuc2U+iQE+BBMBAgAoBQJVUJm7AhsDBQkB4TOABgsJCAcDAgYV -CAIJCgsEFgIDAQIeAQIXgAAKCRCcUc0xe0T+fKpoCACNLSBsjLUoJ57n8p9YsEj0 -vHKFzZYNj85W7ZQsc9IxdqytbEW30SAI76CIW2vTeK4ZKFlRpnRnB4MdJhvz/djk -X4tQeekVeMjUzKApUgbhxrNlTO6JEjKg8ivXpKXM0jCq679XYO0SMwZXkNknT3Xj -p4sFNP+LHByA0J3c32as9RjFa6m1fGoR68fKsqu8Hn13oM63iZu4r9cSLinAN25J -khZxhhgHwLtzepr2xKrbFBu/+rraI/Kwd0FLvDRiuj7rGPrDtI7zJT34FHVmvdyX -7QJpEppJ8THfWwyhfzSTTw6wrlsCPH+2NrBdWiL6oU5Rk6izUDL7guiAHQxkLUCC -iQEcBBABAgAGBQJVWuc9AAoJEEtOTYqCoxOy9FwIALAjXWqTtpT+zNxpyXSOTDA6 -dnlFpoyy4e9iU0ml3dEJHMlEzGCU18K1NEeQ+jMU+HZFtI91j/uuf7uz2dzqgAda -tKNsKEJGwRBohXbBuUbjo5SXwKbYREp/8ovkXOqdhq/5HuvE09l3n/fMR8G01MqR -v4CAOyl29xdoMPeqZa9/1Yec5nnuWHQMQWlD4EVPCXfeJgEcjAl1sFl+ljfpneNi -U7F0Ci3qus8fQYJKDNmu+4I1+r011N8z+JtW4M8KpVj+LjmP+BZUvFYWjkx2bH9e -wSQX5q7uTA652nSMiOE3EPO2CKTQi4JcjPnUoNRKawR5/d7ho9Djqt2f1lWhKM6J -ARwEEAEIAAYFAlVsFFAACgkQGXVB7D7k5scobAgAgDa/WXtNgAxX0cjbo4pzRIzo -W8n4CUht/9BJaUgOLlzVBk2VA5/gLgnmiW2rvi5UQFPXvmoSWE9KJ6dEdrUL9IJH -vI1GxLPe6S3DPvoY1DbWT95eyzpNWKN0WXDnTv3b/rmbC1yO02Q0ep6CPRT0fNUU -7GoIpwLXpIgW3YqdLDdeqCzqh7yWHLc+hgWcvBqNQzotNKgipThVXXSIZlLiLyxg -7b+fAKBMfMNb+9OIroaXnunFVqnLKueYubk1DnHVxVFxUIb/TiuWxcYZFgDQ/jxg -UFIAh5oTWrOxHjqeooj6Kc2S01QOIiuwIj23nFk6mYIx/S7AWOUuxy9nEi4KyrkB -DQRVUJm7AQgApnrl64lSIukGAvfgRMXmtcKVX26NCjExbHOTHnfE/8BlLZzasBcv -hgbvcY4J2+V5QQ5paXbnTrx9rKZLgPA0zgBefajx4gDjad91sUFWgOnhIj6PFuGd -2vX8FI6S/K3qrkuxP0mQO63fDe8UCQ3NnCZjedewI/R64yfKT4kBZi3Y/I0AF+RR -no3LSB2l9MhRtIAqcGW+vbR8JcHOXWmFbVqo36iUH1XwF4fsTxIlWtaAlcFmqYq5 -IMDy9p6i8BkqOb5/NtfvoEtdBvI03/oXAiN7IH2xhkkOuZUcSCZVzhFjLrVj5CJl -6AyKi8ONIoizZMIITWPbC8o/zcQkNp/y0wARAQABiQElBBgBAgAPBQJVUJm7AhsM -BQkB4TOAAAoJEJxRzTF7RP58WPoIAJyYt8RkCx2OqpNf6kkPxUrGW098v81kxp8D -IJ2MTusaHxJW5mFUajcTWZRumAJSwyv2KgAXPFDvZOCDElWnl6fWO4UP4zdWyW/1 -+9ukQJS1qloDN2MH31ib/71TiBGv+p+um8CGuCDZi+gHOGOLnmcLZWgvJT67mCiD -712kGeI7twg5Vwi7s9B2/JX+rL+U47eV+JSXIzf0I8D2dBv8wfAP4A8+1aN9p+/f -nUV+WyrTflSn6IT56GKLwEpGaxluZKEdWCWZknPNihJImfI38B8gEwlvaRXryuk6 -dSv2Fo6o6twhKWQeOB0u+Aezk6FsDSieVwiUNc2vZEwOcbOnLgS5AQ0EVVCaBQEI -AN6mnTa3r+g2c7+oom0H5TbItZRr51ijgQKxtf8MY6CvUxjOG0hs/XyBQBfQ830e -PjRd2ZjkS0AllqYxYIuLQSKNqeE4sMLPDmzSHOL+BjKyYRF4tHGGqrimmNmFKPYc -XT1rpGrVNOSd0b2ZjNNhOR07I6qZ01yYhlFG8kPQETVQGQRGtREaED7xg+cejERV -Sp0QMwVfuceY2XhDluuPuk1doG/fk+xUiXMNJ+W2A3vIQ0Xp2/wW7ufGMpn6v0Ce -tvmsISIGc6Q0BvAQx8y+NFF6Ftj02/PUISfRw/xKy1sthB8FC4J4lbfD0/KAs39r -Rqy9rS22ZWGmtudJ5m0qabcAEQEAAYkBJQQYAQIADwUCVVCaBQIbIAUJAeEzgAAK -CRCcUc0xe0T+fN6JB/9J60No4grm6fkfALkK7EO3kaLShGAziUBDGepelxJ0eHmJ -AUB15+mh6BZFKeSSi3Ebb99bE++jzBI3IPkc/rUcB31ea2ioRQVPUispRAm+rHbt -zzNmVb//Be2Q0QQ16FVMe21oskiH+0csuyuVbxfXmeRrztSmVc/RJ4bN59cC8hut -9CYZW5Ov8Jou82CIpDd3Cx3UdcyUlbI9h9hi4Zx5Kk3ZqxvRQJsEUv14JyPz/4y4 -vznY5M4KNwXuUhzHZod0LQLtBtduCV51jMomcCV92zdDB/TNdN7HLgy2RyL+0MPq -4+9RWJyzjhsLHJCz4WgTnJefHufqqt/hsH5g3SVr -=M9Eh +PHNhbHVAc3VuZXQuc2U+iQEcBBABAgAGBQJVWuc9AAoJEEtOTYqCoxOy9FwIALAj +XWqTtpT+zNxpyXSOTDA6dnlFpoyy4e9iU0ml3dEJHMlEzGCU18K1NEeQ+jMU+HZF +tI91j/uuf7uz2dzqgAdatKNsKEJGwRBohXbBuUbjo5SXwKbYREp/8ovkXOqdhq/5 +HuvE09l3n/fMR8G01MqRv4CAOyl29xdoMPeqZa9/1Yec5nnuWHQMQWlD4EVPCXfe +JgEcjAl1sFl+ljfpneNiU7F0Ci3qus8fQYJKDNmu+4I1+r011N8z+JtW4M8KpVj+ +LjmP+BZUvFYWjkx2bH9ewSQX5q7uTA652nSMiOE3EPO2CKTQi4JcjPnUoNRKawR5 +/d7ho9Djqt2f1lWhKM6JARwEEAEKAAYFAlZF230ACgkQ/GOIMgEC2g66lQf/eKkE +C7xbcsivEECnRFjrAJEyGTPmybJRRqYoCEH0X8iRGEdW1nhJQ8I78/BzpUVX0TuZ +7BscsYwIUyYaZ7Lg7f3swZ/IUoyU56rq5SC78GoDGEEcHs5bZycYZZBINn7o4sWa ++izlr+S5UfwcqvOeRglW1oiti4QJOwdT9pskFu+MpYp+LI3tqc8adBSZb6yR0stz +GfWdd3sahW56ELmjHHvvsYrrItzFsLHx2Qbt9ek06AAkxIHQmC/GLkmWOwheHnD5 +dIGxyjkfQ0OaxKkZQW/1fIObN9F8MLqXnfT0R1Osx8Terg9ekJAcVCqiTxH5ZMfa +0QLO8vUtFkLTJPin8IkBHAQTAQIABgUCVkXYdgAKCRCTG9sDOO2oUJLsCACdojna ++s2plpDjhhmZ1Ozfy8PJIYe0+vOrtX3pUzWEEl5LhfMdLkAWcDn7xR8IZ8te4fXT +H9HHAUYAaz9KeMRZ0j9haio7UIpUW8mBmZBNPPndxVNlCHSkUoy0pM56HbTN4tDB +hxWqYU/4dpgZIiMINCfQROk+H/vsEjPqEos/ayd8kRHv8u7D6UO2K9r9VkEGwf0s +AaU0P6VDvNGSyWsbSxpHwspXLSdo0KKcB+Y2gEq64t9nyEr4IYL3hBg2H3wuPH2A +VRaRcwezDa+p+TcJg98v/Huy99YJqsgoj5lple4AJw31BG9WtBYw1R27srOLSOXf +PiYtVwomTaXsVoM4iQFVBBMBCgA/AhsDBgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIX +gBYhBIeZITBZGGJXEXRpzpxRzTF7RP58BQJdAOKLBQkNXotrAAoJEJxRzTF7RP58 +gSkH/icIkRxLcQiyYH/uTwtHXzgGbQsWRTIiRM7tfRmRpmGYCQjUOS9QgcXZF2nk +LQs23gpS8iOmbYwNZsgHcozx6GK93IXz+BLuLJeI0eLwp7x8vbO5RpYic39s6s48 +C6vIf0fPjD7cavK1/tilc8rvVUjJeE9OHP13WSJcR1q0G032FVf7LfYOWke0W1pY +fufnEpc5InHb3YqbsbQKPsJuqKpJCeEUnAHtSE/F7mijzKjwSXnzVgfmwjyaD4bD +alJX0BdKcfa4fZ0srsNN+VcQDqROZhtfumA61OGHjRFdrz4shoBLJJADC7U9U+x3 +5MGVuYCS4p83Sm+yIQ4mz3cMYJGJAT4EEwECACgFAlVQmbsCGwMFCQHhM4AGCwkI +BwMCBhUIAgkKCwQWAgMBAh4BAheAAAoJEJxRzTF7RP58qmgIAI0tIGyMtSgnnufy +n1iwSPS8coXNlg2PzlbtlCxz0jF2rK1sRbfRIAjvoIhba9N4rhkoWVGmdGcHgx0m +G/P92ORfi1B56RV4yNTMoClSBuHGs2VM7okSMqDyK9ekpczSMKrrv1dg7RIzBleQ +2SdPdeOniwU0/4scHIDQndzfZqz1GMVrqbV8ahHrx8qyq7wefXegzreJm7iv1xIu +KcA3bkmSFnGGGAfAu3N6mvbEqtsUG7/6utoj8rB3QUu8NGK6PusY+sO0jvMlPfgU +dWa93JftAmkSmknxMd9bDKF/NJNPDrCuWwI8f7Y2sF1aIvqhTlGTqLNQMvuC6IAd +DGQtQIKJAhwEEAEKAAYFAlfS118ACgkQE6D159p8CZusnw//Wo0i0Y+ZmobyZ+T/ +d8FfCiXD6UjwreyUvoV0aYIQFn0WNjEOcO91qQ2UoiXOmLTNUJQPS7lDZFoVnhOF +wcLFvt8DxKICWTSK/W2j/BsAlBO1UnHTQpsb1rGAxDKvySFLBUY3fi+TDMA7baTz +ATeCJfkUYagtZsrZG3S2roXf5/OdQZoErFw+YwECa+e8BZDg9JuNNxt5XuyV9f4g +QmAFqFcIvFbsYUbobBiCVU3EkjR0mjQz+PJpmoFrmRGjzDlSJIrq5uxxCV/RoQqo +FiXN0MbzsXXTG6PXdbSC5QjcTLxx7m2BNPf04D+YoD6x+iIEpg8ldehJ393usBbp +voXZgg/QWX6y4w0oc5nNwMOQ4Dd+KQwKo/EIAeyKWEYcoSlspQ9+G+sCCr+63WbF +focv5k3sYNLJykMvGb7uM9lAgp7WMmDr63etd+UB8UxDuei38v/i1JqfevBKEwcl +8F8TAX5bgg4CEx5hxzPT2vo8N1R2nz0lybDIQ30WK6I8Sdt8yb02dR4pCFqrAJLk +XvQk6kQnF+e/+7jKtj0+SIBziIUDy80y8no1ajoGTCXe04NkY++fHCIrJb6kvIJe +dV4+oRwCqMCEIvR0/ieASFPbPS1k6pYdZyKn5FBpPo9h9FmtvXAh34/8Rw5/f1RK +GmieLblfRvWSj62UZcvTtdUbuj2JAT4EEwECACgCGwMGCwkIBwMCBhUIAgkKCwQW +AgMBAh4BAheABQJXOy8uBQkFrPxuAAoJEJxRzTF7RP58CHoH/iMgJzdUygWJXsgA +FP1Z+2IIv3JKxiEtl4o0I0gAWIevDarmwMKYTU9pcJpMIth0iUbDjZDUAa8Ei5RC +8RuZ3jgcpoj8KHL1B7PqvrZQ9R1vV6GZd6NaCJr9va9bFlt6pi7ZzQ3gibV2TorN +tTXN8Id9l/Z5EdFZOdg04WZ/9XI1eEUemtNuM3774eDnt+C4enaImHMIwVDapKaA +RWDILh9q3TrDGjk7rNlzsGLVGw24dks9E09KJfSroTjxgD0RqCO2I/J+CCl2X4Gm +7EM/V/70QDqi5OppK3yZTUYRJQLgG35/Ekghv8ktGJ29wazQ18GxqF8p2Ot/ikg0 +vrc/14OJAVUEEwEKAD8CGwMGCwkIBwMCBhUIAgkKCwQWAgMBAh4BAheAFiEEh5kh +MFkYYlcRdGnOnFHNMXtE/nwFAlrpvxQFCQd6WNkACgkQnFHNMXtE/nwamQf+JGAN +xuKs6SQQyh/CWc6v2I5Ndhv5KzHr3+4J8dxPQumi7Ark5M7CuPvvTuDNn79zWnS0 +I7IEvnuECeBw5h/VyomqO6zJYcvIlDB1zXHaMHAomuGMZshkK30Z8SoD2qiuuMwU +DznQAciI09eYa8hTVvb7ohhHz0Cpy76Vo8mBj2cWmSLDUmRgk3NTpAXrBbXAdBNp +H1wTh+9HEdYEZc4ADJDsMCv9YsUAvMi/ZaPtgxVPqQQq9AG3zh7Um+QNoZ8WNjCA +5fO503Wd+uLCWaJj2vEH1t6UyA1ueLKYU6Hl4A7Eul8HFiW0po3TPmTRsGSFL7ew +TUtPNXWXgS3kVSESu7QeU2FsdSBVcGFkaHlheSA8c2FsdUBub3JkdS5uZXQ+iQEc +BBABCgAGBQJWRdt5AAoJEPxjiDIBAtoOxA0IAJ3S4wQFFUXzKmxD2KndSk17ifM1 +Z2D4pBRTF1ck3KgVaIGoYqwvLJ7IaIg52WFEGsycD3hUsu7hfm/m5Tue6p+yxOPG +29jR9ndyfHoQgGmF+KkdMFgNXRDHDIYCBnRkKd2rbx1KFnFteV9cY4lmkwUzJ5ii +qHS8ewa4dzrVCeajoArgWlXsyJNLOWxYCgMk4XoJ/Q97VmRLm3Towc6XvgBLM2CO +/puYmw43z9cRGxNHNt2vnatdjnQxexjMHhX8OHHTY34c7+TE8YLdwL6DHTykRF4j +z38UnovYbuuFupop7cx73Y9EpRdZrNbusxnH9rNyQOmuMfQLBvWwqF+lVXaJARwE +EwECAAYFAlZF2HYACgkQkxvbAzjtqFA9wwf+L28gCmlWW/LTaFSq1P9VIotJ5IhL +FO0EbyJvZySNkNcZD1oAzNGmsfYwuAXbWfNmEC6zVw6tj1hJHq/S9Hpb/oJ7Jn0L +TzF1Mp31ZcmTMTIbHzYdTlSltxiGYLBfOrMVFTnQdB1tS1lQjd9ZUAe46dqQqvEW +UAGFIkw3PVMJfWUXcN5z+X56l59+7yFVzi+kCpkNgbw8ZeKjjMJQFbUUGY8eB2C1 +EeVO7qKW5BknzUP4sePGLkk+XJ91WV2K34ZUdseldE7PJXEJnasYciGc7NaUSzLj +h1+K9mzXOLfIid29cjeBnXmZlnMh53a+bzhj3aZi6AWtja7anlJTjDNlQ4kBVAQT +AQoAPgIbAwULCQgHAwUVCgkICwUWAgMBAAIeAQIXgBYhBIeZITBZGGJXEXRpzpxR +zTF7RP58BQJdAOKGBQkNXotrAAoJEJxRzTF7RP58yCcH/RxVZO9xNUI8xjIx1pQd +srVKQCJCohM+xg61Lz+jWtdGT31eoSrmgl1bqaO3DBdf3sH99yarMMaDB0x4ZQqd +UFfR8uK68zg9K+0rnds76o0SgoyBd7DRuio1oP6CN61uRgrdoaVHT+2HcrPaX8KL +v8AIocpG6eePFupyC36VOzrahoQefshdxRUbAnKzmV3p6BLwiCAE/IrEWT+Qm1JM +MbtDD9Mx0TCxEKjOU6eKDsHN7zgOCm61s8/EDApzcWuwU/xPfv0/p+PEEZlA9lt8 +en3kvdFYPABOHr7sIdlh0WwSB/xIpTGavdomGByoh5CbcWJb7kO0iW3NrCrw27Ik +a9GJAT0EEwEIACcFAlVd2K0CGwMFCQHhM4AFCwkIBwMFFQoJCAsFFgIDAQACHgEC +F4AACgkQnFHNMXtE/nwNcQf/RZ6GaMGR9wu6A8MJ7jQlU3zgfJT5+QMFPzIg3obQ +7PdL+5PdXWe/LvT7GUR7IrzlNjLayRXKAd0frEJR4wqoN3PfJIQWoNgpHHUVMLHy +kMELiDWZwNqcb8rnS61A14KrjWizcpWrwXuFzZ2jWKO0yftM9Htck8J3gIFadCYp +OvV8gblzOjPwd6Q6x4r+xu8UpfYVAvvrhHZTrTdWOe3Ab54A/Qi9FQXTfb9bCpwA +JKeYPHzizMzfzLCBaiRBa7cLCZycJzzpx26BU08SIz/yTzhMotnPEd0V6WVyT28B +82Bagf3AIy2WexcqmkGvi4QRxZxmjT3pxklOQc8ED40BRokCHAQQAQoABgUCV9LX +YwAKCRAToPXn2nwJm8beD/9yYwwYt70zemGCcAtWX84dcc3jskQCshfSPJ3fn+qn +JdLmL3k5o+joje8pW6vCp7qC4nP7qHMg/e0WwgflS/3gC3iRNOS0gJgTe3hP5o3x +y54leMsCrD0b6q4N/bm9unQcM8zkBEO6e6Oz7sZQS7lghgu/uT3RD7lI5yr1mUU2 +a1kKwk+ga5rdYGUxJ80sxESbprIq7v0LTpbct19+n7AjDUJLx0oVrUI6OxUm5sCI +qkL4pjUbWI2QShMJb+wPN72Pc9rSs31CJ6BcUFVZ8d/yeiLrcvV7aqw/JNoASRPq +dflWA6hvIJxrgnBQhZKSnv+hBusFyfwaeOnxPpZZblRdqufcA5uTuCcclJLhkJf/ +Xwq4qnYUuTWAZqB0gef74ajJo5JU0OV4VbfOcZ51MVbuj3R4nlZr9DKQRNwyAy3v +tYBpeokZWth//EuYZwJjI7TUM2zT1Gj7yjlrJQt57+YwQN13EIKWd8YEzDvUGRNX +8ke1FDiDIDNnAfin4/RjO0snzYveqY4TXCg2IDsjgKfgAkBsy24z8vnh2Z34nclv +yyGtwxcCEpWAInAbXfdw/ZiXNvCgFptTT7YxFHVQUmi5YTeJ9+79buSey4Tylaph +NHsG0Xl+P2dH1Gtq0Tupu/CEsnBlE9BulHZprpVQMnggzjrkPJIR6Kq0XQkmefYx +v4kBPQQTAQgAJwIbAwULCQgHAwUVCgkICwUWAgMBAAIeAQIXgAUCVzsvKQUJBaz8 +bgAKCRCcUc0xe0T+fMCBB/0QX0JouN4KS1mY55fS/w4vASkEf8L6KUz2v4ILAvw5 +Zvd/hpYHQYD1KHeXAtTHzFIkKcXjRe4ILDhatdzBuTllebvIK+LyIejYfpt/VCm7 +ZcYKzLvNPqoQDfPlYpishZY/hbkkuYMtvM2iapKoR0RcHfQOkx966iNbzzCrBgpq +Cg//QgYx8uBqRi52F34XsM6JPrtu6qn8zjVvNhWuTL2Gi6cDNr4/y82NokgQdPLj +uEU9w+Z2gdsUgWg5WT121k4kyK2Hy3J+Af1oAOU18zl6aKnmv/pSbzR8snnwSY8V +W4dE54afDpRoTqstBtVymXV906GMzv1UJcTGg1udt7aZiQFUBBMBCgA+AhsDBQsJ +CAcDBRUKCQgLBRYCAwEAAh4BAheAFiEEh5khMFkYYlcRdGnOnFHNMXtE/nwFAlrp +vxsFCQd6WNkACgkQnFHNMXtE/ny8agf/XqUZCyLcucyhzkF8n9mopDwFTbYEPCFD +Rlrx7Q4ovY02uPPc/sq6QZ4d0Y4WN0eqNxyFikgQCs+yOT7OnJTr3SbJbnPjVJF0 +pyJsplTE2VrZzdg1tT0vOmbX70eIBg+NdrhS3oxC7I0/a7l9ye7CxIBxYaFbbdfB +rahfuAG8weLdvz/f/Cucdeu3J97o5l8jJKC8MlsBbu7G+xNE1lOTw2fBZdQibWzA +0kd47MZxPTneBnvGOPkMV/tfx7BoCAgRIJldwhYjJmzXMLiUEUTlCmZAo+dA0+yX +nD/y5A/FtQbbQeLmEhLwcZhQegYqwC1pwTwSOeEh1XB1YdP3voZAd7kBDQRVUJm7 +AQgApnrl64lSIukGAvfgRMXmtcKVX26NCjExbHOTHnfE/8BlLZzasBcvhgbvcY4J +2+V5QQ5paXbnTrx9rKZLgPA0zgBefajx4gDjad91sUFWgOnhIj6PFuGd2vX8FI6S +/K3qrkuxP0mQO63fDe8UCQ3NnCZjedewI/R64yfKT4kBZi3Y/I0AF+RRno3LSB2l +9MhRtIAqcGW+vbR8JcHOXWmFbVqo36iUH1XwF4fsTxIlWtaAlcFmqYq5IMDy9p6i +8BkqOb5/NtfvoEtdBvI03/oXAiN7IH2xhkkOuZUcSCZVzhFjLrVj5CJl6AyKi8ON +IoizZMIITWPbC8o/zcQkNp/y0wARAQABiQE8BBgBCgAmAhsMFiEEh5khMFkYYlcR +dGnOnFHNMXtE/nwFAl0A4sQFCQ1ei6kACgkQnFHNMXtE/nx+yggAl4oapwJxPrkk +g2GAuFoMqfgefA3Yv7ApPGgfOJDN75Z15y5LSw4fl2KCGGiizlANd0s5p+7u1BvF +uTjXUrLPTxKFJKaGvWdeq59cYRVNi1jtrVsurF8xl5S/uy6ZgPntdUfZKt80hmvi +9DQYxvh/33zvQP+ail3UGb8eC9pHlf6TFlNCh6o9wwjXAMJ+b+w2NanL3RMb8ArL +s5bVdmauaR6tW8J29uaFaTnzDEz5ukF2Ms8/FDajOO4/Qgggh6LtF7qOinsVXua6 +8EBtoYR8gEhYldU2ySdb8QRQjjUOOfM0fL4fOsijMm1rYnPva3pJxo8o2OA5y1A4 +OcS6bGLoZbkBDQRVUJoFAQgA3qadNrev6DZzv6iibQflNsi1lGvnWKOBArG1/wxj +oK9TGM4bSGz9fIFAF9DzfR4+NF3ZmORLQCWWpjFgi4tBIo2p4Tiwws8ObNIc4v4G +MrJhEXi0cYaquKaY2YUo9hxdPWukatU05J3RvZmM02E5HTsjqpnTXJiGUUbyQ9AR +NVAZBEa1ERoQPvGD5x6MRFVKnRAzBV+5x5jZeEOW64+6TV2gb9+T7FSJcw0n5bYD +e8hDRenb/Bbu58Yymfq/QJ62+awhIgZzpDQG8BDHzL40UXoW2PTb89QhJ9HD/ErL +Wy2EHwULgniVt8PT8oCzf2tGrL2tLbZlYaa250nmbSpptwARAQABiQE8BBgBCgAm +AhsgFiEEh5khMFkYYlcRdGnOnFHNMXtE/nwFAl0A4tUFCQ1ei3AACgkQnFHNMXtE +/nzdVggAhx1I847eHBZgBJvD56cs8tOmqLMI8JZFeu19uFgiM9AgIUSr/wTxErp+ +msdv2OeY07aai0Bb+iIX5rDxmVsA/RdAdWbXberXzv1Njb3QwTGseouMMUUWef9I +WzhfYOkTD+eehmNP1QLIkzKQW6C3Qm9xgSIHGAI76NDzel18aVWTUODv3m1VQMJV +Auo6ybrrEBrKqQhIJ0IMqKJm9GM+iJaee7CbvGVxzyJTUSe+HQONPO502DD3K99N +pKk4ZNFT5/cNGSWgDY9XW8qPW6IZWEwDUYCFIkCRoQGg9AQwKDKMr+EiV+tfUUUV +D7nz1Wr/OzBgm/XenetxH/2+tfwUOw== +=tASZ -----END PGP PUBLIC KEY BLOCK----- diff --git a/global/overlay/etc/puppet/cosmos-db.yaml b/global/overlay/etc/puppet/cosmos-db.yaml index 6db3a290..63675969 100644 --- a/global/overlay/etc/puppet/cosmos-db.yaml +++ b/global/overlay/etc/puppet/cosmos-db.yaml @@ -67,7 +67,7 @@ classes: autoupdate: null common: null eid::dockerhost: null - eidas_connector: &id003 {hostname: connector.eidas.swedenconnect.se, version: 1.5.4} + eidas_connector: &id003 {hostname: connector.eidas.swedenconnect.se, version: 1.6.0} entropyclient: null infra_ca_rp: null konsulter: null @@ -1116,7 +1116,7 @@ classes: sunet::server: *id002 sunet_iaas_cloud: null sunetops: null - swedenconnect_refidp: {hostname: qa.test.swedenconnect.se, version: 1.2.0} + swedenconnect_refidp: {hostname: qa.test.swedenconnect.se, version: 1.2.1} test-1.qa.sveidas.se: autoupdate: null common: null diff --git a/global/overlay/etc/puppet/cosmos-rules.yaml b/global/overlay/etc/puppet/cosmos-rules.yaml index 900f86a8..d469bf9b 100644 --- a/global/overlay/etc/puppet/cosmos-rules.yaml +++ b/global/overlay/etc/puppet/cosmos-rules.yaml @@ -658,7 +658,7 @@ md-eu1.qa.komreg.net: konsulter: autoupdate: swedenconnect_refidp: - version: 1.2.0 + version: 1.2.1 hostname: qa.test.swedenconnect.se sunet::frontend::register_sites: sites: @@ -690,7 +690,7 @@ md-eu1.qa.komreg.net: konsulter: autoupdate: eidas_connector: - version: 1.5.4 + version: 1.6.0 hostname: connector.eidas.swedenconnect.se sunet::frontend::register_sites: sites: diff --git a/global/overlay/etc/puppet/manifests/cosmos-site.pp b/global/overlay/etc/puppet/manifests/cosmos-site.pp index 41da8dc8..212bc3f2 100644 --- a/global/overlay/etc/puppet/manifests/cosmos-site.pp +++ b/global/overlay/etc/puppet/manifests/cosmos-site.pp @@ -923,6 +923,8 @@ class nagios_monitor { $allowed_hosts = join($nrpe_clients," "); $web_admin_pw = safe_hiera('nagios_nagiosadmin_password'); $web_admin_user = 'nagiosadmin'; + + package { 'libxml2-utils': ensure => installed} class { 'webserver': } class { 'nagioscfg': @@ -1109,19 +1111,34 @@ class nagios_monitor { check_command => 'check_website!https://md.swedenconnect.se/', description => 'check metadata for Sweden Connect', contact_groups => ['alerts'], - } - nagioscfg::service {'check_connector': + } + nagioscfg::service {'check_connector': host_name => ['connector.eidas.swedenconnect.se'], check_command => 'check_website!https://connector.eidas.swedenconnect.se/idp/metadata/sp', description => 'check metadata for Sweden Connect', contact_groups => ['alerts'], } - nagioscfg::service {'check_metadata_DE_middleware': + nagioscfg::service {'check_metadata_DE_middleware': host_name => ['demw.eidas.swedenconnect.se'], check_command => 'check_website!https://demw.eidas.swedenconnect.se/eidas-middleware/Metadata', description => 'check metadata for DE middleware', contact_groups => ['alerts'], } + nagioscfg::command {'check_country_count': + command_line => "/usr/lib/nagios/plugins/check_eidas_country_count.sh '\$ARG1\$' '\$ARG2\$' '\$ARG3\$' '\$ARG4\$'" + } + nagioscfg::service {'check_country_eIDAS_QA': + host_name => ['qa.md.eidas.swedenconnect.se'], + check_command => 'check_country_count!qa.md.eidas.swedenconnect.se!23!2!3', + description => 'check number of countries in eIDAS QA', + contact_groups => ['alerts'], + } + nagioscfg::service {'check_country_eIDAS': + host_name => ['md.eidas.swedenconnect.se'], + check_command => 'check_country_count!md.eidas.swedenconnect.se!7!1!2', + description => 'check number of countries in eIDAS', + contact_groups => ['alerts'], + } } class redis_cluster_node { diff --git a/global/overlay/etc/puppet/modules/eid/templates/eidas_logs/eidas_logs.erb b/global/overlay/etc/puppet/modules/eid/templates/eidas_logs/eidas_logs.erb index 738e6627..d2a1b4ab 100644 --- a/global/overlay/etc/puppet/modules/eid/templates/eidas_logs/eidas_logs.erb +++ b/global/overlay/etc/puppet/modules/eid/templates/eidas_logs/eidas_logs.erb @@ -18,7 +18,10 @@ su root syslog } -/var/log/eidas_*.log { +/var/log/eidas_audit.log +/var/log/eidas_process.log +/var/log/eidas_proxy.log +{ rotate 7 daily missingok @@ -26,4 +29,4 @@ delaycompress compress su root syslog -} +} \ No newline at end of file diff --git a/log-1.sveidas.se/overlay/etc/rsyslog.d/99-audit.conf b/log-1.sveidas.se/overlay/etc/rsyslog.d/99-audit.conf index 49c0237f..35a34468 100644 --- a/log-1.sveidas.se/overlay/etc/rsyslog.d/99-audit.conf +++ b/log-1.sveidas.se/overlay/etc/rsyslog.d/99-audit.conf @@ -2,3 +2,5 @@ local0.* -/var/log/eidas_audit.log local1.* -/var/log/eidas_fticks.log local2.* -/var/log/eidas_process.log local3.* -/var/log/eidas_proxy.log +$template messageOnly,"{\"type\":%msg%\n" +local4.* -/var/log/eidas_stats.log; messageOnly diff --git a/log-2.sveidas.se/overlay/etc/rsyslog.d/99-audit.conf b/log-2.sveidas.se/overlay/etc/rsyslog.d/99-audit.conf index 53c6af95..56e9b454 100644 --- a/log-2.sveidas.se/overlay/etc/rsyslog.d/99-audit.conf +++ b/log-2.sveidas.se/overlay/etc/rsyslog.d/99-audit.conf @@ -2,3 +2,5 @@ local0.* -/var/log/eidas_audit.log local1.* -/var/log/eidas_fticks.log local2.* -/var/log/eidas_process.log local3.* -/var/log/eidas_proxy.log +$template messageOnly,"{\"type\":%msg%\n" +local4.* -/var/log/eidas_stats.log; messageOnly