summaryrefslogtreecommitdiffstats
path: root/base/server
diff options
context:
space:
mode:
authorEndi S. Dewata <edewata@redhat.com>2017-02-21 22:02:22 +0100
committerEndi S. Dewata <edewata@redhat.com>2017-02-21 22:41:17 +0100
commit72b24a41691cc87068ff156100a0865c794038df (patch)
tree76fd2fb4874f7c8533e5d3ccce6fd47f354d37d8 /base/server
parent961b0138dbc0f5e6af1195f61e36a42ad67baaa7 (diff)
downloadpki-72b24a41691cc87068ff156100a0865c794038df.tar.gz
pki-72b24a41691cc87068ff156100a0865c794038df.tar.xz
pki-72b24a41691cc87068ff156100a0865c794038df.zip
Secured PKI UI main page.
A web.xml has been added to /pki web application to require SSL connection to access the PKI UI main page at /pki/ui. https://fedorahosted.org/pki/ticket/2582
Diffstat (limited to 'base/server')
-rw-r--r--base/server/share/webapps/pki/WEB-INF/web.xml22
1 files changed, 22 insertions, 0 deletions
diff --git a/base/server/share/webapps/pki/WEB-INF/web.xml b/base/server/share/webapps/pki/WEB-INF/web.xml
new file mode 100644
index 000000000..9afb41825
--- /dev/null
+++ b/base/server/share/webapps/pki/WEB-INF/web.xml
@@ -0,0 +1,22 @@
+<?xml version="1.0" encoding="ISO-8859-1"?>
+<!DOCTYPE web-app
+ PUBLIC "-//Sun Microsystems, Inc.//DTD Web Application 2.3//EN" "file:///usr/share/pki/setup/web-app_2_3.dtd">
+<web-app>
+
+ <display-name>PKI</display-name>
+
+ <security-constraint>
+ <web-resource-collection>
+ <web-resource-name>PKI UI</web-resource-name>
+ <url-pattern>/ui/*</url-pattern>
+ </web-resource-collection>
+ <user-data-constraint>
+ <transport-guarantee>CONFIDENTIAL</transport-guarantee>
+ </user-data-constraint>
+ </security-constraint>
+
+ <session-config>
+ <session-timeout>30</session-timeout>
+ </session-config>
+
+</web-app>