This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
docpublic:systemes:ssocas:cas4install [2015/07/01 22:04] procacci@tem-tsp.eu [clearPass] |
docpublic:systemes:ssocas:cas4install [2015/07/01 22:20] (current) procacci@tem-tsp.eu |
||
---|---|---|---|
Line 682: | Line 682: | ||
</ | </ | ||
- | ===== clearPass ===== | ||
- | ref http:// | + | ===== redeploiement |
- | + | ||
- | < | + | |
- | [disi@cas4 simple-cas4-overlay-template]$ git diff 4a0275d pom.xml | + | |
- | diff --git a/pom.xml b/pom.xml | + | |
- | index 8e4621a..716a2f4 100755 | + | |
- | --- a/pom.xml | + | |
- | +++ b/pom.xml | + | |
- | @@ -51,12 +51,22 @@ | + | |
- | < | + | |
- | </ | + | |
- | + | ||
- | + < | + | |
- | < | + | |
- | < | + | |
- | < | + | |
- | < | + | |
- | </ | + | |
- | + | ||
- | + < | + | |
- | + < | + | |
- | + < | + | |
- | + < | + | |
- | + < | + | |
- | + < | + | |
- | + </ | + | |
- | + | + | |
- | + | + | |
- | </ | + | |
- | + | ||
- | < | + | |
- | </ | + | |
- | + | ||
- | + | ||
- | Single Node Configuration | + | |
- | + | ||
- | on part d'un web.xml du target qu'on copie dans notre src car le maven overlay Unicon n'en avait pas par defaut, puis on ajoute le filter et servlet-mapping | + | |
- | + | ||
- | < | + | |
- | [disi@cas4 simple-cas4-overlay-template]$ cp ./ | + | |
- | + | ||
- | [disi@cas4 simple-cas4-overlay-template]$ diff -ur ./ | + | |
- | --- ./ | + | |
- | +++ ./ | + | |
- | @@ -64,6 +64,19 @@ | + | |
- | < | + | |
- | </ | + | |
- | + | ||
- | +<!-- JP clearpass servlet mapping --> | + | |
- | + | + | |
- | +< | + | |
- | + < | + | |
- | + < | + | |
- | +</ | + | |
- | + | + | |
- | +< | + | |
- | + < | + | |
- | + < | + | |
- | +</ | + | |
- | + | + | |
- | + | + | |
- | < | + | |
- | - Loads the CAS ApplicationContext. | + | |
- | - The deployer choice here is how to handle Throwables thrown by Spring' | + | |
- | @@ -169,6 +182,13 @@ | + | |
- | < | + | |
- | </ | + | |
- | + | ||
- | +<!-- JP clearpass servlet mapping --> | + | |
- | + < | + | |
- | + < | + | |
- | + < | + | |
- | + </ | + | |
- | + | + | |
- | + | + | |
- | < | + | |
- | < | + | |
- | < | + | |
- | </ | + | |
- | + | ||
- | + | ||
- | idem , on recopie un modele de clearpass-configuration.xml | + | |
- | + | ||
- | < | + | |
- | [disi@cas4 simple-cas4-overlay-template]$ cp ./ | + | |
- | </ | + | |
- | + | ||
- | et on en modifie le contenu pour y ajouter la list des services autoriser (exact match) a faire du clearpass | + | |
- | + | ||
- | < | + | |
- | | + | |
- | --- ./ | + | |
- | +++ ./ | + | |
- | @@ -95,4 +95,17 @@ | + | |
- | + | ||
- | < | + | |
- | + | ||
- | -</ | + | |
- | \ Pas de fin de ligne à la fin du fichier | + | |
- | + <!-- JP list urls --> | + | |
- | + | + | |
- | + <bean id=" | + | |
- | + < | + | |
- | + < | + | |
- | + < | + | |
- | + < | + | |
- | + < | + | |
- | + </ | + | |
- | + </ | + | |
- | + </ | + | |
- | + | + | |
- | + | + | |
- | +</ | + | |
- | </ | + | |
- | + | ||
- | + | ||
- | dernier fichier a modifier | + | |
- | + | ||
- | < | + | |
- | [disi@cas4 simple-cas4-overlay-template]$ cp ./ | + | |
- | [disi@cas4 simple-cas4-overlay-template]$ diff -ur ./ | + | |
- | --- ./ | + | |
- | +++ ./ | + | |
- | @@ -28,7 +28,8 @@ | + | |
- | </ | + | |
- | + | ||
- | < | + | |
- | - <bean id=" | + | |
- | + <!-- JP comment <bean id=" | + | |
- | + <bean id=" | + | |
- | + | ||
- | | + | |
- | | + | |
- | @@ -44,4 +45,4 @@ | + | |
- | | + | |
- | | + | |
- | | + | |
- | -</ | + | |
- | \ Pas de fin de ligne à la fin du fichier | + | |
- | +</ | + | |
- | </ | + | |
- | + | ||
- | + | ||
- | ===== deploiement cas + clearPass | + | |
On reconstruit a nouveau Cas | On reconstruit a nouveau Cas | ||
Line 845: | Line 701: | ||
</ | </ | ||
- | un test sur le service clearPass: | ||
- | https:// | ||
- | retourne bien depuis cette url autorisé | ||
- | < | ||
- | < | ||
- | < | ||
- | < | ||
- | </ | ||
- | </ | ||
- | </ | ||
- | |||
- | |||
- | |||
- | ==== debug pb clearPass ==== | ||
- | |||
- | il faut bien s' | ||
- | et que le nom du server est concordant dans la partie ssl d' | ||
- | |||
- | < | ||
- | [root@cas4 conf]# grep cas4.tem / | ||
- | ServerName cas4.tem-tsp.eu | ||
- | ServerAlias cas4.tem-tsp.eu | ||
- | </ | ||
- | |||
- | autrement on a des soucis type https pas redirigé correctement vers du https mais du http+8080 : | ||
- | |||
- | < | ||
- | 2015-07-01 23: | ||
- | Ticket ' | ||
- | </ | ||
- | |||
- | ou des interpretations de code html d' | ||
- | |||
- | < | ||
- | 2015-07-01 23: | ||
- | </ | ||
- | |||
- | qui en fait correspond a une reponse http dont la premiere ligne | ||
- | |||
- | < | ||
- | < | ||
- | </ | ||
- | Cette ligne fait 50 caractères pile ! d'où le message " | ||