From 258072c54a3201f1cb3c77ef20907fc2bd6d048c Mon Sep 17 00:00:00 2001 From: Kay Joosten Date: Fri, 4 Sep 2026 10:13:08 +0200 Subject: [PATCH 1/7] ci(stepup-behat): generate HAProxy dev certificate before compose up Commit 2291d6f stopped committing core/haproxy/haproxy.pem and moved its generation into core/scripts/create_dev_ca.sh, invoked only by start-dev-env.sh. The stepup-behat workflow runs 'docker compose up' directly, so haproxy.pem was missing; Docker created it as a directory and the haproxy container failed to start, taking down TLS routing and every Behat scenario with it. Run create_dev_ca.sh in the Init step, matching start-dev-env.sh's guard. --- .github/workflows/stepup-behat.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/stepup-behat.yml b/.github/workflows/stepup-behat.yml index 783b49e..57bdfc4 100644 --- a/.github/workflows/stepup-behat.yml +++ b/.github/workflows/stepup-behat.yml @@ -28,6 +28,9 @@ jobs: cd stepup cp .env.test .env cp gateway/surfnet_yubikey.yaml.dist gateway/surfnet_yubikey.yaml + if [ ! -f ../core/haproxy/haproxy.pem ]; then + ../core/scripts/create_dev_ca.sh + fi ${DOCKER_COMPOSE} up -d - name: Install composer dependencies on the Behat container run: | From 74b46496ac924e76249409e2b985a5449752498d Mon Sep 17 00:00:00 2001 From: Kay Joosten Date: Tue, 8 Sep 2026 14:40:15 +0200 Subject: [PATCH 2/7] ci(stepup-behat): distribute dev CA cert to app containers Since the CA became dynamically generated (2291d6f) the app containers no longer trust the HAProxy TLS certificate: the static stepup/haproxy/haproxy.crt that used to be committed is gone, and only start-dev-env.sh copies the freshly generated one into place. CI skipped that copy, so every inter-service HTTPS call failed with 'cURL error 60: self signed certificate in certificate chain', cascading into ~100 Behat failures. Copy core/haproxy/haproxy.crt to stepup/haproxy/haproxy.crt before compose up; the base image imports /config/haproxy/haproxy.crt and runs update-ca-certificates on startup. --- .github/workflows/stepup-behat.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/stepup-behat.yml b/.github/workflows/stepup-behat.yml index 57bdfc4..c379505 100644 --- a/.github/workflows/stepup-behat.yml +++ b/.github/workflows/stepup-behat.yml @@ -31,6 +31,10 @@ jobs: if [ ! -f ../core/haproxy/haproxy.pem ]; then ../core/scripts/create_dev_ca.sh fi + # Distribute the dev CA to the app containers: the base image imports + # /config/haproxy/haproxy.crt on startup so services trust each other + # over HAProxy TLS. start-dev-env.sh does this copy; CI must too. + cp ../core/haproxy/haproxy.crt haproxy/haproxy.crt ${DOCKER_COMPOSE} up -d - name: Install composer dependencies on the Behat container run: | From 4faa6946051509d1f6cf2995d0a709eabbca38e8 Mon Sep 17 00:00:00 2001 From: Kay Joosten Date: Tue, 8 Sep 2026 15:20:50 +0200 Subject: [PATCH 3/7] fix(stepup-selfservice): keep logout redirects local Mount a selfservice parameters override so logout redirects stay inside the dev/CI environment instead of following the baked-in www.surf.nl URLs. Update the Behat expectation to assert the local test SP target. --- stepup/docker-compose.yml | 1 + stepup/selfservice/parameters.yaml | 95 +++++++++++++++++++ .../features/bootstrap/SelfServiceContext.php | 4 +- 3 files changed, 98 insertions(+), 2 deletions(-) create mode 100644 stepup/selfservice/parameters.yaml diff --git a/stepup/docker-compose.yml b/stepup/docker-compose.yml index 9f09d5f..1471f18 100644 --- a/stepup/docker-compose.yml +++ b/stepup/docker-compose.yml @@ -162,6 +162,7 @@ services: openconextdev: volumes: - ${PWD}/:/config + - ${PWD}/selfservice/parameters.yaml:/var/www/html/config/openconext/parameters.yaml:ro extra_hosts: - "host.docker.internal:host-gateway" hostname: selfservice.docker diff --git a/stepup/selfservice/parameters.yaml b/stepup/selfservice/parameters.yaml new file mode 100644 index 0000000..cf1e9eb --- /dev/null +++ b/stepup/selfservice/parameters.yaml @@ -0,0 +1,95 @@ +parameters: + trusted_proxies: ~ + + app_env: prod + app_debug: false + app_secret: NotSoSecretReplaceMe! + + default_locale: en_GB + locales: [nl_NL, en_GB] + locale_cookie_domain: dev.openconext.local + secret: NotSoSecretReplaceMe! + + debug_toolbar: true + debug_redirects: false + + gateway_api_url: https://gateway.dev.openconext.local/ + gateway_api_username: ss + gateway_api_password: sa_secret + + middleware_credentials_username: ss + middleware_credentials_password: sa_secret + middleware_url_command_api: https://middleware.dev.openconext.local/command + middleware_url_api: https://middleware.dev.openconext.local/ + + sms_originator: OpenConext + sms_otp_expiry_interval: 900 # 15 minutes + sms_maximum_otp_requests: 3 + + saml_sp_publickey: /config/selfservice/selfservice_saml_sp.crt + saml_sp_privatekey: /config/selfservice/selfservice_saml_sp.key + saml_metadata_publickey: /config/selfservice/selfservice_saml_sp.crt + saml_metadata_privatekey: /config/selfservice/selfservice_saml_sp.key + + saml_remote_idp_entity_id: https://gateway.dev.openconext.local/authentication/metadata + saml_remote_idp_sso_url: https://gateway.dev.openconext.local/authentication/single-sign-on + saml_remote_idp_certificate: 'MIIDwTCCAqmgAwIBAgIUYuSUugwc4J4NyW9WGqYJ/liwM4owDQYJKoZIhvcNAQELBQAwcDELMAkGA1UEBhMCTkwxEDAOBgNVBAgMB1V0cmVjaHQxEDAOBgNVBAcMB1V0cmVjaHQxJzAlBgNVBAoMHkRldmVsb3BtZW50IERvY2tlciBlbnZpcm9ubWVudDEUMBIGA1UEAwwLR2F0ZXdheSBJRFAwHhcNMjMwNTE3MTIxNTEyWhcNMzMwNTE0MTIxNTEyWjBwMQswCQYDVQQGEwJOTDEQMA4GA1UECAwHVXRyZWNodDEQMA4GA1UEBwwHVXRyZWNodDEnMCUGA1UECgweRGV2ZWxvcG1lbnQgRG9ja2VyIGVudmlyb25tZW50MRQwEgYDVQQDDAtHYXRld2F5IElEUDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM2ulQVs5WpbJOAf7Cv/VPDTJqbWHVdUxAmdwZJlcNTRKNFVp4aJzQ3dpiyiGghI5odnzU0/BWBoHZFNYPU/OFr/gzn6iJGxL63L9+mFgE8PR9HpkV5TaRnr21+nZ0EXWjDZk9Px0enERicCItTeQzAUJeA0A9miIcK5IKIz/zSBSR3c802SGD/VelUqY7Z2/UJM97cT92L+4Fz+4zhxxoThbPbrR0CweiROIt82grdwg7zf0+b62MOuVtqFh0yPLRAFfLc4LjHuxFUdUvOHVta7x74dwdmHikqfujM10XN+sNns3LDJde2yPWchU6ktq7cjgbYfIW/vzVzafP1Jk40CAwEAAaNTMFEwHQYDVR0OBBYEFGYn6LWRDZa7+YryUncIlwJB2VorMB8GA1UdIwQYMBaAFGYn6LWRDZa7+YryUncIlwJB2VorMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJ57lcOF6PWWW56mS2s5gKFImtfRFzlfiyHsF14L7+nQ5NjfOhpU0wRpnTjK91KP0wCwlxzGFXR8yfqfBFJryIV7aDdYPH/RIkwVaNBI0fsD/ozlYb18seieDEGLvQtTlrmc0UNHtWz6FW3L2geM3ENaqpOATl1Ywp4EPML7Dh0CbhhyM8PnPCEsdclouIeP5/B9Swfk3omXehof6bkFbntqA03msFBiW50twkfKeKULcJGXo667hto27KNxZUauqtPbnAGpUQmge8nxSQlN8RPwlvygVM4LVMF9qP9YxloTH0xVNwN4noZUhfMNsKoJ7Hg5Xulaok8oCqmzEiSroEg=' + + asset_version: 1 + + second_factor_test_idp_entity_id: https://gateway.dev.openconext.local/authentication/metadata + second_factor_test_idp_sso_url: https://gateway.dev.openconext.local/authentication/single-sign-on + second_factor_test_idp_certificate: 'MIIDwTCCAqmgAwIBAgIUYuSUugwc4J4NyW9WGqYJ/liwM4owDQYJKoZIhvcNAQELBQAwcDELMAkGA1UEBhMCTkwxEDAOBgNVBAgMB1V0cmVjaHQxEDAOBgNVBAcMB1V0cmVjaHQxJzAlBgNVBAoMHkRldmVsb3BtZW50IERvY2tlciBlbnZpcm9ubWVudDEUMBIGA1UEAwwLR2F0ZXdheSBJRFAwHhcNMjMwNTE3MTIxNTEyWhcNMzMwNTE0MTIxNTEyWjBwMQswCQYDVQQGEwJOTDEQMA4GA1UECAwHVXRyZWNodDEQMA4GA1UEBwwHVXRyZWNodDEnMCUGA1UECgweRGV2ZWxvcG1lbnQgRG9ja2VyIGVudmlyb25tZW50MRQwEgYDVQQDDAtHYXRld2F5IElEUDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM2ulQVs5WpbJOAf7Cv/VPDTJqbWHVdUxAmdwZJlcNTRKNFVp4aJzQ3dpiyiGghI5odnzU0/BWBoHZFNYPU/OFr/gzn6iJGxL63L9+mFgE8PR9HpkV5TaRnr21+nZ0EXWjDZk9Px0enERicCItTeQzAUJeA0A9miIcK5IKIz/zSBSR3c802SGD/VelUqY7Z2/UJM97cT92L+4Fz+4zhxxoThbPbrR0CweiROIt82grdwg7zf0+b62MOuVtqFh0yPLRAFfLc4LjHuxFUdUvOHVta7x74dwdmHikqfujM10XN+sNns3LDJde2yPWchU6ktq7cjgbYfIW/vzVzafP1Jk40CAwEAAaNTMFEwHQYDVR0OBBYEFGYn6LWRDZa7+YryUncIlwJB2VorMB8GA1UdIwQYMBaAFGYn6LWRDZa7+YryUncIlwJB2VorMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJ57lcOF6PWWW56mS2s5gKFImtfRFzlfiyHsF14L7+nQ5NjfOhpU0wRpnTjK91KP0wCwlxzGFXR8yfqfBFJryIV7aDdYPH/RIkwVaNBI0fsD/ozlYb18seieDEGLvQtTlrmc0UNHtWz6FW3L2geM3ENaqpOATl1Ywp4EPML7Dh0CbhhyM8PnPCEsdclouIeP5/B9Swfk3omXehof6bkFbntqA03msFBiW50twkfKeKULcJGXo667hto27KNxZUauqtPbnAGpUQmge8nxSQlN8RPwlvygVM4LVMF9qP9YxloTH0xVNwN4noZUhfMNsKoJ7Hg5Xulaok8oCqmzEiSroEg=' + + stepup_loa_loa1: http://dev.openconext.local/assurance/loa1 + stepup_loa_loa2: http://dev.openconext.local/assurance/loa2 + stepup_loa_loa3: http://dev.openconext.local/assurance/loa3 + stepup_loa_self_asserted: 'http://dev.openconext.local/assurance/loa1.5' + + logout_redirect_url: + nl_NL: https://ssp.dev.openconext.local/simplesaml/sp.php + en_GB: https://ssp.dev.openconext.local/simplesaml/sp.php + + enabled_second_factors: + - sms + - yubikey + - tiqr + - demo_gssp + - webauthn + - azuremfa + enabled_generic_second_factors: + azuremfa: + loa: 2 + tiqr: + loa: 2 + webauthn: + loa: 3 + demo_gssp: + loa: 3 + + tiqr_app_android_url: https://play.google.com/store/apps/details?id=org.tiqr.authenticator&hl=en + tiqr_app_ios_url: https://itunes.apple.com/us/app/tiqr/id430838214?mt=8&ls=1 + + session_max_absolute_lifetime: 3600 # 1 hours * 60 minutes * 60 seconds + session_max_relative_lifetime: 600 # 10 minutes * 60 seconds + + preferred_activation_flow_name: activate + preferred_activation_flow_options: [ra, self] + activation_flow_attribute_name: urn:mace:dir:attribute-def:eduPersonEntitlement + activation_flow_attributes: + ra: urn:mace:surf.nl:surfsecureid:activation:ra + self: urn:mace:surf.nl:surfsecureid:activation:self + + # Self-asserted tokens: enable/disable recovery methods + # + # One of the two options should be enabled to have a fully functioning + # Self-asserted token registration process. + recovery_method_sms_enabled: true + recovery_method_safe_store_code_enabled: true + + authentication_context_class_ref: ~ + +when@test: + parameters: + app_secret: $ecretf0rt3st + app_env: test diff --git a/stepup/tests/behat/features/bootstrap/SelfServiceContext.php b/stepup/tests/behat/features/bootstrap/SelfServiceContext.php index c912cf9..b6dae22 100644 --- a/stepup/tests/behat/features/bootstrap/SelfServiceContext.php +++ b/stepup/tests/behat/features/bootstrap/SelfServiceContext.php @@ -78,9 +78,9 @@ public function logoutOfSelfService() $this->minkContext->pressButton('Sign out'); - $expectBaseUrl = 'https://www.surf.nl/'; + $expectBaseUrl = 'https://ssp.dev.openconext.local/'; if (substr($this->minkContext->getSession()->getCurrentUrl(), 0, strlen($expectBaseUrl)) !== $expectBaseUrl) { - throw new Exception("after logout we should be redirected to the surf domain"); + throw new Exception("after logout we should be redirected to the local test SP domain"); } } From 4713eb443650ff2cda3d6ce11640e6ab9a7115e3 Mon Sep 17 00:00:00 2001 From: Kay Joosten Date: Wed, 9 Sep 2026 11:37:31 +0200 Subject: [PATCH 4/7] fix(stepup-selfservice): merge logout redirect override --- stepup/docker-compose.yml | 2 +- stepup/selfservice/entrypoint.sh | 43 ++++++++++ stepup/selfservice/parameters.override.yaml | 4 + stepup/selfservice/parameters.yaml | 95 --------------------- 4 files changed, 48 insertions(+), 96 deletions(-) create mode 100755 stepup/selfservice/entrypoint.sh create mode 100644 stepup/selfservice/parameters.override.yaml delete mode 100644 stepup/selfservice/parameters.yaml diff --git a/stepup/docker-compose.yml b/stepup/docker-compose.yml index 1471f18..bf131e2 100644 --- a/stepup/docker-compose.yml +++ b/stepup/docker-compose.yml @@ -156,13 +156,13 @@ services: selfservice: image: ghcr.io/openconext/stepup-selfservice/stepup-selfservice:${STEPUP_VERSION:-prod} + entrypoint: /config/selfservice/entrypoint.sh environment: - APP_ENV=${APP_ENV:-prod} networks: openconextdev: volumes: - ${PWD}/:/config - - ${PWD}/selfservice/parameters.yaml:/var/www/html/config/openconext/parameters.yaml:ro extra_hosts: - "host.docker.internal:host-gateway" hostname: selfservice.docker diff --git a/stepup/selfservice/entrypoint.sh b/stepup/selfservice/entrypoint.sh new file mode 100755 index 0000000..9becd52 --- /dev/null +++ b/stepup/selfservice/entrypoint.sh @@ -0,0 +1,43 @@ +#!/usr/bin/env sh + +set -eu + +OVERRIDE_FILE="/config/selfservice/parameters.override.yaml" + +if [ -f "$OVERRIDE_FILE" ]; then + # Keep the image's base config intact and override only the local keys we need. + php <<'PHP' + $values) { + if (!is_array($values)) { + $parameters[$section] = $values; + continue; + } + + $currentValues = $parameters[$section] ?? []; + if (!is_array($currentValues)) { + $currentValues = []; + } + + $parameters[$section] = array_replace_recursive($currentValues, $values); +} + +file_put_contents( + $parametersPath, + Yaml::dump($parameters, 99, 4, Yaml::DUMP_MULTI_LINE_LITERAL_BLOCK) +); +PHP +fi + +exec /entrypoint.sh "$@" diff --git a/stepup/selfservice/parameters.override.yaml b/stepup/selfservice/parameters.override.yaml new file mode 100644 index 0000000..5f96753 --- /dev/null +++ b/stepup/selfservice/parameters.override.yaml @@ -0,0 +1,4 @@ +parameters: + logout_redirect_url: + nl_NL: https://ssp.dev.openconext.local/simplesaml/sp.php + en_GB: https://ssp.dev.openconext.local/simplesaml/sp.php diff --git a/stepup/selfservice/parameters.yaml b/stepup/selfservice/parameters.yaml deleted file mode 100644 index cf1e9eb..0000000 --- a/stepup/selfservice/parameters.yaml +++ /dev/null @@ -1,95 +0,0 @@ -parameters: - trusted_proxies: ~ - - app_env: prod - app_debug: false - app_secret: NotSoSecretReplaceMe! - - default_locale: en_GB - locales: [nl_NL, en_GB] - locale_cookie_domain: dev.openconext.local - secret: NotSoSecretReplaceMe! - - debug_toolbar: true - debug_redirects: false - - gateway_api_url: https://gateway.dev.openconext.local/ - gateway_api_username: ss - gateway_api_password: sa_secret - - middleware_credentials_username: ss - middleware_credentials_password: sa_secret - middleware_url_command_api: https://middleware.dev.openconext.local/command - middleware_url_api: https://middleware.dev.openconext.local/ - - sms_originator: OpenConext - sms_otp_expiry_interval: 900 # 15 minutes - sms_maximum_otp_requests: 3 - - saml_sp_publickey: /config/selfservice/selfservice_saml_sp.crt - saml_sp_privatekey: /config/selfservice/selfservice_saml_sp.key - saml_metadata_publickey: /config/selfservice/selfservice_saml_sp.crt - saml_metadata_privatekey: /config/selfservice/selfservice_saml_sp.key - - saml_remote_idp_entity_id: https://gateway.dev.openconext.local/authentication/metadata - saml_remote_idp_sso_url: https://gateway.dev.openconext.local/authentication/single-sign-on - saml_remote_idp_certificate: 'MIIDwTCCAqmgAwIBAgIUYuSUugwc4J4NyW9WGqYJ/liwM4owDQYJKoZIhvcNAQELBQAwcDELMAkGA1UEBhMCTkwxEDAOBgNVBAgMB1V0cmVjaHQxEDAOBgNVBAcMB1V0cmVjaHQxJzAlBgNVBAoMHkRldmVsb3BtZW50IERvY2tlciBlbnZpcm9ubWVudDEUMBIGA1UEAwwLR2F0ZXdheSBJRFAwHhcNMjMwNTE3MTIxNTEyWhcNMzMwNTE0MTIxNTEyWjBwMQswCQYDVQQGEwJOTDEQMA4GA1UECAwHVXRyZWNodDEQMA4GA1UEBwwHVXRyZWNodDEnMCUGA1UECgweRGV2ZWxvcG1lbnQgRG9ja2VyIGVudmlyb25tZW50MRQwEgYDVQQDDAtHYXRld2F5IElEUDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM2ulQVs5WpbJOAf7Cv/VPDTJqbWHVdUxAmdwZJlcNTRKNFVp4aJzQ3dpiyiGghI5odnzU0/BWBoHZFNYPU/OFr/gzn6iJGxL63L9+mFgE8PR9HpkV5TaRnr21+nZ0EXWjDZk9Px0enERicCItTeQzAUJeA0A9miIcK5IKIz/zSBSR3c802SGD/VelUqY7Z2/UJM97cT92L+4Fz+4zhxxoThbPbrR0CweiROIt82grdwg7zf0+b62MOuVtqFh0yPLRAFfLc4LjHuxFUdUvOHVta7x74dwdmHikqfujM10XN+sNns3LDJde2yPWchU6ktq7cjgbYfIW/vzVzafP1Jk40CAwEAAaNTMFEwHQYDVR0OBBYEFGYn6LWRDZa7+YryUncIlwJB2VorMB8GA1UdIwQYMBaAFGYn6LWRDZa7+YryUncIlwJB2VorMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJ57lcOF6PWWW56mS2s5gKFImtfRFzlfiyHsF14L7+nQ5NjfOhpU0wRpnTjK91KP0wCwlxzGFXR8yfqfBFJryIV7aDdYPH/RIkwVaNBI0fsD/ozlYb18seieDEGLvQtTlrmc0UNHtWz6FW3L2geM3ENaqpOATl1Ywp4EPML7Dh0CbhhyM8PnPCEsdclouIeP5/B9Swfk3omXehof6bkFbntqA03msFBiW50twkfKeKULcJGXo667hto27KNxZUauqtPbnAGpUQmge8nxSQlN8RPwlvygVM4LVMF9qP9YxloTH0xVNwN4noZUhfMNsKoJ7Hg5Xulaok8oCqmzEiSroEg=' - - asset_version: 1 - - second_factor_test_idp_entity_id: https://gateway.dev.openconext.local/authentication/metadata - second_factor_test_idp_sso_url: https://gateway.dev.openconext.local/authentication/single-sign-on - second_factor_test_idp_certificate: 'MIIDwTCCAqmgAwIBAgIUYuSUugwc4J4NyW9WGqYJ/liwM4owDQYJKoZIhvcNAQELBQAwcDELMAkGA1UEBhMCTkwxEDAOBgNVBAgMB1V0cmVjaHQxEDAOBgNVBAcMB1V0cmVjaHQxJzAlBgNVBAoMHkRldmVsb3BtZW50IERvY2tlciBlbnZpcm9ubWVudDEUMBIGA1UEAwwLR2F0ZXdheSBJRFAwHhcNMjMwNTE3MTIxNTEyWhcNMzMwNTE0MTIxNTEyWjBwMQswCQYDVQQGEwJOTDEQMA4GA1UECAwHVXRyZWNodDEQMA4GA1UEBwwHVXRyZWNodDEnMCUGA1UECgweRGV2ZWxvcG1lbnQgRG9ja2VyIGVudmlyb25tZW50MRQwEgYDVQQDDAtHYXRld2F5IElEUDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM2ulQVs5WpbJOAf7Cv/VPDTJqbWHVdUxAmdwZJlcNTRKNFVp4aJzQ3dpiyiGghI5odnzU0/BWBoHZFNYPU/OFr/gzn6iJGxL63L9+mFgE8PR9HpkV5TaRnr21+nZ0EXWjDZk9Px0enERicCItTeQzAUJeA0A9miIcK5IKIz/zSBSR3c802SGD/VelUqY7Z2/UJM97cT92L+4Fz+4zhxxoThbPbrR0CweiROIt82grdwg7zf0+b62MOuVtqFh0yPLRAFfLc4LjHuxFUdUvOHVta7x74dwdmHikqfujM10XN+sNns3LDJde2yPWchU6ktq7cjgbYfIW/vzVzafP1Jk40CAwEAAaNTMFEwHQYDVR0OBBYEFGYn6LWRDZa7+YryUncIlwJB2VorMB8GA1UdIwQYMBaAFGYn6LWRDZa7+YryUncIlwJB2VorMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJ57lcOF6PWWW56mS2s5gKFImtfRFzlfiyHsF14L7+nQ5NjfOhpU0wRpnTjK91KP0wCwlxzGFXR8yfqfBFJryIV7aDdYPH/RIkwVaNBI0fsD/ozlYb18seieDEGLvQtTlrmc0UNHtWz6FW3L2geM3ENaqpOATl1Ywp4EPML7Dh0CbhhyM8PnPCEsdclouIeP5/B9Swfk3omXehof6bkFbntqA03msFBiW50twkfKeKULcJGXo667hto27KNxZUauqtPbnAGpUQmge8nxSQlN8RPwlvygVM4LVMF9qP9YxloTH0xVNwN4noZUhfMNsKoJ7Hg5Xulaok8oCqmzEiSroEg=' - - stepup_loa_loa1: http://dev.openconext.local/assurance/loa1 - stepup_loa_loa2: http://dev.openconext.local/assurance/loa2 - stepup_loa_loa3: http://dev.openconext.local/assurance/loa3 - stepup_loa_self_asserted: 'http://dev.openconext.local/assurance/loa1.5' - - logout_redirect_url: - nl_NL: https://ssp.dev.openconext.local/simplesaml/sp.php - en_GB: https://ssp.dev.openconext.local/simplesaml/sp.php - - enabled_second_factors: - - sms - - yubikey - - tiqr - - demo_gssp - - webauthn - - azuremfa - enabled_generic_second_factors: - azuremfa: - loa: 2 - tiqr: - loa: 2 - webauthn: - loa: 3 - demo_gssp: - loa: 3 - - tiqr_app_android_url: https://play.google.com/store/apps/details?id=org.tiqr.authenticator&hl=en - tiqr_app_ios_url: https://itunes.apple.com/us/app/tiqr/id430838214?mt=8&ls=1 - - session_max_absolute_lifetime: 3600 # 1 hours * 60 minutes * 60 seconds - session_max_relative_lifetime: 600 # 10 minutes * 60 seconds - - preferred_activation_flow_name: activate - preferred_activation_flow_options: [ra, self] - activation_flow_attribute_name: urn:mace:dir:attribute-def:eduPersonEntitlement - activation_flow_attributes: - ra: urn:mace:surf.nl:surfsecureid:activation:ra - self: urn:mace:surf.nl:surfsecureid:activation:self - - # Self-asserted tokens: enable/disable recovery methods - # - # One of the two options should be enabled to have a fully functioning - # Self-asserted token registration process. - recovery_method_sms_enabled: true - recovery_method_safe_store_code_enabled: true - - authentication_context_class_ref: ~ - -when@test: - parameters: - app_secret: $ecretf0rt3st - app_env: test From 856a4ee418d3ddd0c13954d47d7a23dfccadd561 Mon Sep 17 00:00:00 2001 From: Kay Joosten Date: Wed, 9 Sep 2026 12:39:14 +0200 Subject: [PATCH 5/7] Revert incorrect selfservice config merge change The previous commit assumed the docker-compose bind mount of the full stepup/selfservice/parameters.yaml onto the container's config was a bug that clobbered the image's baked-in configuration, and replaced it with a partial merge against that baked-in config via an entrypoint script. That assumption was wrong. The full local parameters.yaml is the intentional, correct pattern already used for this dev/behat environment: it supplies the gateway, middleware and SAML values this environment actually needs (dev URLs, dev SAML certificates and credentials), which are not present in the image's baked-in config at all. Replacing it with a partial merge dropped all of those values and broke the SAML login redirect, which is why the Behat suite started failing (22 scenarios) right after that change. This reverts back to mounting the full local parameters.yaml, which is the state the Behat suite was passing against before. --- stepup/docker-compose.yml | 2 +- stepup/selfservice/entrypoint.sh | 43 ---------- stepup/selfservice/parameters.override.yaml | 4 - stepup/selfservice/parameters.yaml | 95 +++++++++++++++++++++ 4 files changed, 96 insertions(+), 48 deletions(-) delete mode 100755 stepup/selfservice/entrypoint.sh delete mode 100644 stepup/selfservice/parameters.override.yaml create mode 100644 stepup/selfservice/parameters.yaml diff --git a/stepup/docker-compose.yml b/stepup/docker-compose.yml index bf131e2..1471f18 100644 --- a/stepup/docker-compose.yml +++ b/stepup/docker-compose.yml @@ -156,13 +156,13 @@ services: selfservice: image: ghcr.io/openconext/stepup-selfservice/stepup-selfservice:${STEPUP_VERSION:-prod} - entrypoint: /config/selfservice/entrypoint.sh environment: - APP_ENV=${APP_ENV:-prod} networks: openconextdev: volumes: - ${PWD}/:/config + - ${PWD}/selfservice/parameters.yaml:/var/www/html/config/openconext/parameters.yaml:ro extra_hosts: - "host.docker.internal:host-gateway" hostname: selfservice.docker diff --git a/stepup/selfservice/entrypoint.sh b/stepup/selfservice/entrypoint.sh deleted file mode 100755 index 9becd52..0000000 --- a/stepup/selfservice/entrypoint.sh +++ /dev/null @@ -1,43 +0,0 @@ -#!/usr/bin/env sh - -set -eu - -OVERRIDE_FILE="/config/selfservice/parameters.override.yaml" - -if [ -f "$OVERRIDE_FILE" ]; then - # Keep the image's base config intact and override only the local keys we need. - php <<'PHP' - $values) { - if (!is_array($values)) { - $parameters[$section] = $values; - continue; - } - - $currentValues = $parameters[$section] ?? []; - if (!is_array($currentValues)) { - $currentValues = []; - } - - $parameters[$section] = array_replace_recursive($currentValues, $values); -} - -file_put_contents( - $parametersPath, - Yaml::dump($parameters, 99, 4, Yaml::DUMP_MULTI_LINE_LITERAL_BLOCK) -); -PHP -fi - -exec /entrypoint.sh "$@" diff --git a/stepup/selfservice/parameters.override.yaml b/stepup/selfservice/parameters.override.yaml deleted file mode 100644 index 5f96753..0000000 --- a/stepup/selfservice/parameters.override.yaml +++ /dev/null @@ -1,4 +0,0 @@ -parameters: - logout_redirect_url: - nl_NL: https://ssp.dev.openconext.local/simplesaml/sp.php - en_GB: https://ssp.dev.openconext.local/simplesaml/sp.php diff --git a/stepup/selfservice/parameters.yaml b/stepup/selfservice/parameters.yaml new file mode 100644 index 0000000..cf1e9eb --- /dev/null +++ b/stepup/selfservice/parameters.yaml @@ -0,0 +1,95 @@ +parameters: + trusted_proxies: ~ + + app_env: prod + app_debug: false + app_secret: NotSoSecretReplaceMe! + + default_locale: en_GB + locales: [nl_NL, en_GB] + locale_cookie_domain: dev.openconext.local + secret: NotSoSecretReplaceMe! + + debug_toolbar: true + debug_redirects: false + + gateway_api_url: https://gateway.dev.openconext.local/ + gateway_api_username: ss + gateway_api_password: sa_secret + + middleware_credentials_username: ss + middleware_credentials_password: sa_secret + middleware_url_command_api: https://middleware.dev.openconext.local/command + middleware_url_api: https://middleware.dev.openconext.local/ + + sms_originator: OpenConext + sms_otp_expiry_interval: 900 # 15 minutes + sms_maximum_otp_requests: 3 + + saml_sp_publickey: /config/selfservice/selfservice_saml_sp.crt + saml_sp_privatekey: /config/selfservice/selfservice_saml_sp.key + saml_metadata_publickey: /config/selfservice/selfservice_saml_sp.crt + saml_metadata_privatekey: /config/selfservice/selfservice_saml_sp.key + + saml_remote_idp_entity_id: https://gateway.dev.openconext.local/authentication/metadata + saml_remote_idp_sso_url: https://gateway.dev.openconext.local/authentication/single-sign-on + saml_remote_idp_certificate: 'MIIDwTCCAqmgAwIBAgIUYuSUugwc4J4NyW9WGqYJ/liwM4owDQYJKoZIhvcNAQELBQAwcDELMAkGA1UEBhMCTkwxEDAOBgNVBAgMB1V0cmVjaHQxEDAOBgNVBAcMB1V0cmVjaHQxJzAlBgNVBAoMHkRldmVsb3BtZW50IERvY2tlciBlbnZpcm9ubWVudDEUMBIGA1UEAwwLR2F0ZXdheSBJRFAwHhcNMjMwNTE3MTIxNTEyWhcNMzMwNTE0MTIxNTEyWjBwMQswCQYDVQQGEwJOTDEQMA4GA1UECAwHVXRyZWNodDEQMA4GA1UEBwwHVXRyZWNodDEnMCUGA1UECgweRGV2ZWxvcG1lbnQgRG9ja2VyIGVudmlyb25tZW50MRQwEgYDVQQDDAtHYXRld2F5IElEUDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM2ulQVs5WpbJOAf7Cv/VPDTJqbWHVdUxAmdwZJlcNTRKNFVp4aJzQ3dpiyiGghI5odnzU0/BWBoHZFNYPU/OFr/gzn6iJGxL63L9+mFgE8PR9HpkV5TaRnr21+nZ0EXWjDZk9Px0enERicCItTeQzAUJeA0A9miIcK5IKIz/zSBSR3c802SGD/VelUqY7Z2/UJM97cT92L+4Fz+4zhxxoThbPbrR0CweiROIt82grdwg7zf0+b62MOuVtqFh0yPLRAFfLc4LjHuxFUdUvOHVta7x74dwdmHikqfujM10XN+sNns3LDJde2yPWchU6ktq7cjgbYfIW/vzVzafP1Jk40CAwEAAaNTMFEwHQYDVR0OBBYEFGYn6LWRDZa7+YryUncIlwJB2VorMB8GA1UdIwQYMBaAFGYn6LWRDZa7+YryUncIlwJB2VorMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJ57lcOF6PWWW56mS2s5gKFImtfRFzlfiyHsF14L7+nQ5NjfOhpU0wRpnTjK91KP0wCwlxzGFXR8yfqfBFJryIV7aDdYPH/RIkwVaNBI0fsD/ozlYb18seieDEGLvQtTlrmc0UNHtWz6FW3L2geM3ENaqpOATl1Ywp4EPML7Dh0CbhhyM8PnPCEsdclouIeP5/B9Swfk3omXehof6bkFbntqA03msFBiW50twkfKeKULcJGXo667hto27KNxZUauqtPbnAGpUQmge8nxSQlN8RPwlvygVM4LVMF9qP9YxloTH0xVNwN4noZUhfMNsKoJ7Hg5Xulaok8oCqmzEiSroEg=' + + asset_version: 1 + + second_factor_test_idp_entity_id: https://gateway.dev.openconext.local/authentication/metadata + second_factor_test_idp_sso_url: https://gateway.dev.openconext.local/authentication/single-sign-on + second_factor_test_idp_certificate: 'MIIDwTCCAqmgAwIBAgIUYuSUugwc4J4NyW9WGqYJ/liwM4owDQYJKoZIhvcNAQELBQAwcDELMAkGA1UEBhMCTkwxEDAOBgNVBAgMB1V0cmVjaHQxEDAOBgNVBAcMB1V0cmVjaHQxJzAlBgNVBAoMHkRldmVsb3BtZW50IERvY2tlciBlbnZpcm9ubWVudDEUMBIGA1UEAwwLR2F0ZXdheSBJRFAwHhcNMjMwNTE3MTIxNTEyWhcNMzMwNTE0MTIxNTEyWjBwMQswCQYDVQQGEwJOTDEQMA4GA1UECAwHVXRyZWNodDEQMA4GA1UEBwwHVXRyZWNodDEnMCUGA1UECgweRGV2ZWxvcG1lbnQgRG9ja2VyIGVudmlyb25tZW50MRQwEgYDVQQDDAtHYXRld2F5IElEUDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM2ulQVs5WpbJOAf7Cv/VPDTJqbWHVdUxAmdwZJlcNTRKNFVp4aJzQ3dpiyiGghI5odnzU0/BWBoHZFNYPU/OFr/gzn6iJGxL63L9+mFgE8PR9HpkV5TaRnr21+nZ0EXWjDZk9Px0enERicCItTeQzAUJeA0A9miIcK5IKIz/zSBSR3c802SGD/VelUqY7Z2/UJM97cT92L+4Fz+4zhxxoThbPbrR0CweiROIt82grdwg7zf0+b62MOuVtqFh0yPLRAFfLc4LjHuxFUdUvOHVta7x74dwdmHikqfujM10XN+sNns3LDJde2yPWchU6ktq7cjgbYfIW/vzVzafP1Jk40CAwEAAaNTMFEwHQYDVR0OBBYEFGYn6LWRDZa7+YryUncIlwJB2VorMB8GA1UdIwQYMBaAFGYn6LWRDZa7+YryUncIlwJB2VorMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJ57lcOF6PWWW56mS2s5gKFImtfRFzlfiyHsF14L7+nQ5NjfOhpU0wRpnTjK91KP0wCwlxzGFXR8yfqfBFJryIV7aDdYPH/RIkwVaNBI0fsD/ozlYb18seieDEGLvQtTlrmc0UNHtWz6FW3L2geM3ENaqpOATl1Ywp4EPML7Dh0CbhhyM8PnPCEsdclouIeP5/B9Swfk3omXehof6bkFbntqA03msFBiW50twkfKeKULcJGXo667hto27KNxZUauqtPbnAGpUQmge8nxSQlN8RPwlvygVM4LVMF9qP9YxloTH0xVNwN4noZUhfMNsKoJ7Hg5Xulaok8oCqmzEiSroEg=' + + stepup_loa_loa1: http://dev.openconext.local/assurance/loa1 + stepup_loa_loa2: http://dev.openconext.local/assurance/loa2 + stepup_loa_loa3: http://dev.openconext.local/assurance/loa3 + stepup_loa_self_asserted: 'http://dev.openconext.local/assurance/loa1.5' + + logout_redirect_url: + nl_NL: https://ssp.dev.openconext.local/simplesaml/sp.php + en_GB: https://ssp.dev.openconext.local/simplesaml/sp.php + + enabled_second_factors: + - sms + - yubikey + - tiqr + - demo_gssp + - webauthn + - azuremfa + enabled_generic_second_factors: + azuremfa: + loa: 2 + tiqr: + loa: 2 + webauthn: + loa: 3 + demo_gssp: + loa: 3 + + tiqr_app_android_url: https://play.google.com/store/apps/details?id=org.tiqr.authenticator&hl=en + tiqr_app_ios_url: https://itunes.apple.com/us/app/tiqr/id430838214?mt=8&ls=1 + + session_max_absolute_lifetime: 3600 # 1 hours * 60 minutes * 60 seconds + session_max_relative_lifetime: 600 # 10 minutes * 60 seconds + + preferred_activation_flow_name: activate + preferred_activation_flow_options: [ra, self] + activation_flow_attribute_name: urn:mace:dir:attribute-def:eduPersonEntitlement + activation_flow_attributes: + ra: urn:mace:surf.nl:surfsecureid:activation:ra + self: urn:mace:surf.nl:surfsecureid:activation:self + + # Self-asserted tokens: enable/disable recovery methods + # + # One of the two options should be enabled to have a fully functioning + # Self-asserted token registration process. + recovery_method_sms_enabled: true + recovery_method_safe_store_code_enabled: true + + authentication_context_class_ref: ~ + +when@test: + parameters: + app_secret: $ecretf0rt3st + app_env: test From c758bb475eb5a2f844aadede4e2000f007dce48d Mon Sep 17 00:00:00 2001 From: Kay Joosten Date: Thu, 17 Sep 2026 14:59:51 +0200 Subject: [PATCH 6/7] ci(stepup-behat): also guard on missing haproxy CA cert create_dev_ca.sh always produces haproxy.pem and haproxy.crt together, but the regeneration check only looked at haproxy.pem. Check both so the CA cert copy step right after can't run against a missing haproxy.crt. --- .github/workflows/stepup-behat.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/stepup-behat.yml b/.github/workflows/stepup-behat.yml index c379505..db1894d 100644 --- a/.github/workflows/stepup-behat.yml +++ b/.github/workflows/stepup-behat.yml @@ -28,7 +28,7 @@ jobs: cd stepup cp .env.test .env cp gateway/surfnet_yubikey.yaml.dist gateway/surfnet_yubikey.yaml - if [ ! -f ../core/haproxy/haproxy.pem ]; then + if [ ! -f ../core/haproxy/haproxy.pem ] || [ ! -f ../core/haproxy/haproxy.crt ]; then ../core/scripts/create_dev_ca.sh fi # Distribute the dev CA to the app containers: the base image imports From 5295ca0cfaebd05f57b2246bcdd18f86c5b8a5d4 Mon Sep 17 00:00:00 2001 From: Kay Joosten Date: Thu, 17 Sep 2026 16:07:29 +0200 Subject: [PATCH 7/7] fix(stepup-selfservice): drop local parameters.yaml override The upstream fix in Stepup-SelfService (parameters.yaml.dist now points logout_redirect_url at the local dev domain, matching every other URL in that file) is merged and published in the :test image, so this stack no longer needs its own bind-mounted parameters.yaml. selfservice now behaves like gateway/middleware/ra: no devconf-side config override needed. --- stepup/docker-compose.yml | 1 - stepup/selfservice/parameters.yaml | 95 ------------------------------ 2 files changed, 96 deletions(-) delete mode 100644 stepup/selfservice/parameters.yaml diff --git a/stepup/docker-compose.yml b/stepup/docker-compose.yml index 1471f18..9f09d5f 100644 --- a/stepup/docker-compose.yml +++ b/stepup/docker-compose.yml @@ -162,7 +162,6 @@ services: openconextdev: volumes: - ${PWD}/:/config - - ${PWD}/selfservice/parameters.yaml:/var/www/html/config/openconext/parameters.yaml:ro extra_hosts: - "host.docker.internal:host-gateway" hostname: selfservice.docker diff --git a/stepup/selfservice/parameters.yaml b/stepup/selfservice/parameters.yaml deleted file mode 100644 index cf1e9eb..0000000 --- a/stepup/selfservice/parameters.yaml +++ /dev/null @@ -1,95 +0,0 @@ -parameters: - trusted_proxies: ~ - - app_env: prod - app_debug: false - app_secret: NotSoSecretReplaceMe! - - default_locale: en_GB - locales: [nl_NL, en_GB] - locale_cookie_domain: dev.openconext.local - secret: NotSoSecretReplaceMe! - - debug_toolbar: true - debug_redirects: false - - gateway_api_url: https://gateway.dev.openconext.local/ - gateway_api_username: ss - gateway_api_password: sa_secret - - middleware_credentials_username: ss - middleware_credentials_password: sa_secret - middleware_url_command_api: https://middleware.dev.openconext.local/command - middleware_url_api: https://middleware.dev.openconext.local/ - - sms_originator: OpenConext - sms_otp_expiry_interval: 900 # 15 minutes - sms_maximum_otp_requests: 3 - - saml_sp_publickey: /config/selfservice/selfservice_saml_sp.crt - saml_sp_privatekey: /config/selfservice/selfservice_saml_sp.key - saml_metadata_publickey: /config/selfservice/selfservice_saml_sp.crt - saml_metadata_privatekey: /config/selfservice/selfservice_saml_sp.key - - saml_remote_idp_entity_id: https://gateway.dev.openconext.local/authentication/metadata - saml_remote_idp_sso_url: https://gateway.dev.openconext.local/authentication/single-sign-on - saml_remote_idp_certificate: 'MIIDwTCCAqmgAwIBAgIUYuSUugwc4J4NyW9WGqYJ/liwM4owDQYJKoZIhvcNAQELBQAwcDELMAkGA1UEBhMCTkwxEDAOBgNVBAgMB1V0cmVjaHQxEDAOBgNVBAcMB1V0cmVjaHQxJzAlBgNVBAoMHkRldmVsb3BtZW50IERvY2tlciBlbnZpcm9ubWVudDEUMBIGA1UEAwwLR2F0ZXdheSBJRFAwHhcNMjMwNTE3MTIxNTEyWhcNMzMwNTE0MTIxNTEyWjBwMQswCQYDVQQGEwJOTDEQMA4GA1UECAwHVXRyZWNodDEQMA4GA1UEBwwHVXRyZWNodDEnMCUGA1UECgweRGV2ZWxvcG1lbnQgRG9ja2VyIGVudmlyb25tZW50MRQwEgYDVQQDDAtHYXRld2F5IElEUDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM2ulQVs5WpbJOAf7Cv/VPDTJqbWHVdUxAmdwZJlcNTRKNFVp4aJzQ3dpiyiGghI5odnzU0/BWBoHZFNYPU/OFr/gzn6iJGxL63L9+mFgE8PR9HpkV5TaRnr21+nZ0EXWjDZk9Px0enERicCItTeQzAUJeA0A9miIcK5IKIz/zSBSR3c802SGD/VelUqY7Z2/UJM97cT92L+4Fz+4zhxxoThbPbrR0CweiROIt82grdwg7zf0+b62MOuVtqFh0yPLRAFfLc4LjHuxFUdUvOHVta7x74dwdmHikqfujM10XN+sNns3LDJde2yPWchU6ktq7cjgbYfIW/vzVzafP1Jk40CAwEAAaNTMFEwHQYDVR0OBBYEFGYn6LWRDZa7+YryUncIlwJB2VorMB8GA1UdIwQYMBaAFGYn6LWRDZa7+YryUncIlwJB2VorMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJ57lcOF6PWWW56mS2s5gKFImtfRFzlfiyHsF14L7+nQ5NjfOhpU0wRpnTjK91KP0wCwlxzGFXR8yfqfBFJryIV7aDdYPH/RIkwVaNBI0fsD/ozlYb18seieDEGLvQtTlrmc0UNHtWz6FW3L2geM3ENaqpOATl1Ywp4EPML7Dh0CbhhyM8PnPCEsdclouIeP5/B9Swfk3omXehof6bkFbntqA03msFBiW50twkfKeKULcJGXo667hto27KNxZUauqtPbnAGpUQmge8nxSQlN8RPwlvygVM4LVMF9qP9YxloTH0xVNwN4noZUhfMNsKoJ7Hg5Xulaok8oCqmzEiSroEg=' - - asset_version: 1 - - second_factor_test_idp_entity_id: https://gateway.dev.openconext.local/authentication/metadata - second_factor_test_idp_sso_url: https://gateway.dev.openconext.local/authentication/single-sign-on - second_factor_test_idp_certificate: 'MIIDwTCCAqmgAwIBAgIUYuSUugwc4J4NyW9WGqYJ/liwM4owDQYJKoZIhvcNAQELBQAwcDELMAkGA1UEBhMCTkwxEDAOBgNVBAgMB1V0cmVjaHQxEDAOBgNVBAcMB1V0cmVjaHQxJzAlBgNVBAoMHkRldmVsb3BtZW50IERvY2tlciBlbnZpcm9ubWVudDEUMBIGA1UEAwwLR2F0ZXdheSBJRFAwHhcNMjMwNTE3MTIxNTEyWhcNMzMwNTE0MTIxNTEyWjBwMQswCQYDVQQGEwJOTDEQMA4GA1UECAwHVXRyZWNodDEQMA4GA1UEBwwHVXRyZWNodDEnMCUGA1UECgweRGV2ZWxvcG1lbnQgRG9ja2VyIGVudmlyb25tZW50MRQwEgYDVQQDDAtHYXRld2F5IElEUDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM2ulQVs5WpbJOAf7Cv/VPDTJqbWHVdUxAmdwZJlcNTRKNFVp4aJzQ3dpiyiGghI5odnzU0/BWBoHZFNYPU/OFr/gzn6iJGxL63L9+mFgE8PR9HpkV5TaRnr21+nZ0EXWjDZk9Px0enERicCItTeQzAUJeA0A9miIcK5IKIz/zSBSR3c802SGD/VelUqY7Z2/UJM97cT92L+4Fz+4zhxxoThbPbrR0CweiROIt82grdwg7zf0+b62MOuVtqFh0yPLRAFfLc4LjHuxFUdUvOHVta7x74dwdmHikqfujM10XN+sNns3LDJde2yPWchU6ktq7cjgbYfIW/vzVzafP1Jk40CAwEAAaNTMFEwHQYDVR0OBBYEFGYn6LWRDZa7+YryUncIlwJB2VorMB8GA1UdIwQYMBaAFGYn6LWRDZa7+YryUncIlwJB2VorMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAJ57lcOF6PWWW56mS2s5gKFImtfRFzlfiyHsF14L7+nQ5NjfOhpU0wRpnTjK91KP0wCwlxzGFXR8yfqfBFJryIV7aDdYPH/RIkwVaNBI0fsD/ozlYb18seieDEGLvQtTlrmc0UNHtWz6FW3L2geM3ENaqpOATl1Ywp4EPML7Dh0CbhhyM8PnPCEsdclouIeP5/B9Swfk3omXehof6bkFbntqA03msFBiW50twkfKeKULcJGXo667hto27KNxZUauqtPbnAGpUQmge8nxSQlN8RPwlvygVM4LVMF9qP9YxloTH0xVNwN4noZUhfMNsKoJ7Hg5Xulaok8oCqmzEiSroEg=' - - stepup_loa_loa1: http://dev.openconext.local/assurance/loa1 - stepup_loa_loa2: http://dev.openconext.local/assurance/loa2 - stepup_loa_loa3: http://dev.openconext.local/assurance/loa3 - stepup_loa_self_asserted: 'http://dev.openconext.local/assurance/loa1.5' - - logout_redirect_url: - nl_NL: https://ssp.dev.openconext.local/simplesaml/sp.php - en_GB: https://ssp.dev.openconext.local/simplesaml/sp.php - - enabled_second_factors: - - sms - - yubikey - - tiqr - - demo_gssp - - webauthn - - azuremfa - enabled_generic_second_factors: - azuremfa: - loa: 2 - tiqr: - loa: 2 - webauthn: - loa: 3 - demo_gssp: - loa: 3 - - tiqr_app_android_url: https://play.google.com/store/apps/details?id=org.tiqr.authenticator&hl=en - tiqr_app_ios_url: https://itunes.apple.com/us/app/tiqr/id430838214?mt=8&ls=1 - - session_max_absolute_lifetime: 3600 # 1 hours * 60 minutes * 60 seconds - session_max_relative_lifetime: 600 # 10 minutes * 60 seconds - - preferred_activation_flow_name: activate - preferred_activation_flow_options: [ra, self] - activation_flow_attribute_name: urn:mace:dir:attribute-def:eduPersonEntitlement - activation_flow_attributes: - ra: urn:mace:surf.nl:surfsecureid:activation:ra - self: urn:mace:surf.nl:surfsecureid:activation:self - - # Self-asserted tokens: enable/disable recovery methods - # - # One of the two options should be enabled to have a fully functioning - # Self-asserted token registration process. - recovery_method_sms_enabled: true - recovery_method_safe_store_code_enabled: true - - authentication_context_class_ref: ~ - -when@test: - parameters: - app_secret: $ecretf0rt3st - app_env: test