The steps for Kron PAM Server (within the Secure Zone) and Kron PAM Mobile App Server (on the DMZ)
1) ((PAM)) All required PAM services (including auth) should be started and the mobile-api service should be stopped on 10.10.0.1 (PAM server).
2) ((DMZ)) All required PAM services (including auth) should be stopped and the mobile-api service should be started on 10.10.0.2 (mobile app server).
3) ((PAM)) On the System Configuration Man. page of the Kron PAM Web GUI (10.10.0.1), mobile.tomcat.url should be set with Kron PAM Mobile App Server’s info. (E.g., https://10.10.0.2:9443/mobile-api/rest)
4) ((PAM)) The following jobs related to push notification system should be defined on the Kron PAM Web GUI (10.10.0.1): SCPolicyNotifierJob, SendPushMessageJob.
5) ((DMZ)) The following lines should be changed on .env file on 10.10.0.2.
6) ((DMZ)) The following docker-compose.yml configuration should be used on 10.10.0.2 under /pam/docker-mgmt/.
networks:
default:
driver: bridge
kron-network:
name: kron-network # creates this named network if it doesn’t already exist
driver: bridge
services:
# pam services
mobile-api:
extends:
service: mobile-api
file: docker-compose-pam.yml7) ((DMZ)) The following docker-compose-base-pam.yml configuration should be used on 10.10.0.2 under /pam/docker-mgmt/.
x-pam-common-directories: &pam-common-directories
CONFIG_REPO_DIR: ${APP_INT_CONFIG_REPO_DIR}
LOG_CONFIG_FILE_PATH: ${APP_INT_LOG_CONFIG_FILE_PATH}
LICENSE_PATH: ${APP_INT_LICENSE_PATH}/${LICENSE_FILE_NAME}
SECURITY_CONFIG_PATH: ${APP_INT_SECURITY_CONFIG_PATH}
x-pam-common-variables: &pam-common-variables
<<: *pam-common-directories
INSTANCE_NAME: ${INSTANCE_NAME}
TZ: ${TIME_ZONE}
SPRING_PROFILES_ACTIVE: ${ACTIVE_SPRING_PROFILES}
# Config Server Environment Values
###-------------------------------
###CHANGE THIS: CONFIG_SERVER_URI
###-------------------------------
CONFIG_SERVER_URI: https://10.10.0.1:8001
CONFIG_USER: aioc
CONFIG_PASSWORD: aioc
# SSL Environment Values
SSL_ENABLE: true
SSL_KEY_STORE_TYPE: PKCS12
KEY_ALIAS: aioc
KEY_STORE: file:${APP_INT_CERTS_PATH}/aioc.jks
TRUST_STORE: file:${APP_INT_CERTS_PATH}/aioc.p12
#KRON_COMMON_SERVICE_URLs
SPRING_BOOT_ADMIN_URL: ${APP_INT_SPRING_BOOT_ADMIN_URL}
# PAM
PAM_URL: ${APP_INT_PAM_APPLICATION_URL}
# MOBILE APP
MOBILE_API_SSL_ENABLE: ${PAM_MOBILE_API_SSL_ENABLE}
MOBILE_API_SSL_KEY_STORE: file:${APP_INT_PAM_CERTS_PATH}/${PAM_CERT_FILE}
MOBILE_API_SSL_ALIAS: ${PAM_CERT_FILE_ALIAS}
MOBILE_API_SSL_STORE_TYPE: ${PAM_CERT_FILE_STORE_TYPE}
MOBILE_API_SSL_STORE_PASSWORD: ${PAM_CERT_FILE_STORE_PASSWORD}
MOBILE_API_SSL_PASSWORD: ${PAM_CERT_FILE_PASSWORD}
x-pam-db-variables: &pam-common-db-variables
<<: *pam-common-variables
DB_URL: ${PAM_DB_URL}
DB_USERNAME: ${PAM_DB_USERNAME}
DB_PASSWORD: ${PAM_DB_PASSWORD}
DB_SCHEMA: ${PAM_DB_SCHEMA}
DB_DRIVER: org.postgresql.Driver
BASE_URL: ${APP_INT_PAM_APPLICATION_URL}
x-healthcheck-java: &healthcheck-java
test: java -cp /app/libs/kron-runtime-tools* com.kron.tools.runtime.HealthCheck https://localhost:8443/actuator/health || exit 1
interval: 6s
retries: 20
start_period: 8s
timeout: 5s
x-deploy-resource: &deploy-resource
resources:
limits:
cpus: "0.70"
memory: ${CONTAINER_MEMORY}
reservations:
cpus: "0.50"
memory: ${MIN_MEMORY}
services:
mobile-api:
image: dockerhub.kron.com.tr/pam/mobile-api:3.8.0
container_name: mobile-api
environment: *pam-common-db-variables
deploy: *deploy-resource
profiles:
- pam
ports:
- "${PAM_MOBILE_API_PORT}:8443"
volumes:
- ${CONFIG_REPO_DIRECTORY}:${APP_INT_CONFIG_REPO_DIR}
- ${LOG4J2_PATH}:${APP_INT_LOG_CONFIG_FILE_PATH}
- ${APPLICATION_CERTS_DIRECTORY}:${APP_INT_CERTS_PATH}
- ${PAM_CERTS_DIRECTORY}:${APP_INT_PAM_CERTS_PATH}
- ${DATABASE_CERTS_DIRECTORY}:${APP_INT_DB_CERTS_PATH}
- ${SECURITY_FILES_DIRECTORY}:${APP_INT_SECURITY_CONFIG_PATH}
- ${LOG_DIRECTORY_PATH}:${APP_INT_LOG_DIRECTORY_PATH}
- ${COLD_LOG_DIRECTORY_PATH}:${APP_INT_COLD_LOG_DIRECTORY_PATH}
- ${LICENSE_FILE_DIRECTORY}:${APP_INT_LICENSE_PATH}
healthcheck: *healthcheck-java
restart: on-failure:5
dns:
- ${DNS_F}
extra_hosts:
- "host.docker.internal:${HOST_GATEWAY}"
- ""{PAM-INSTANCE NAME of 10.10.0.1}:10.10.0.1"
networks:
- kron-network
###-------------------------------
###CHANGE THIS: extra_hosts: e.g., - “pam-01:10.10.0.1”
###-------------------------------
networks:
kron-network:
name: kron-network # creates this named network if it doesn’t already exist
driver: bridge8) ((DMZ)) If the customer has their own valid certificate for mobile service:
If the customer uses its own certificate for accessing mobile URL, the certificate should be uploaded to /pam/gui/conf/cert (e.g., kron.com.tr.jks). Note that, the purpose of using this certificate is different from the self signed certificate to access a specific docker service on the Kron PAM Server.
· Put the jks (e.g. kron.com.tr.jks) file to /pam/gui/conf/cert on 10.10.0.2.
· Edit the following lines of mobile-api-default.properties located under /pam/docker-mgmt/config-repo/ on 10.10.0.2:
E.g.:
9) ((PAM)) Using the RSA key pair created with the aioc alias, the environment configurations (kron-commons-config) in the Docker container on the Kron PAM server can be accessed by the Kron PAM Mobile App Server. For this, instead of using the customer's existing key pair, a self-signed certificate is used. This RSA key pair is stored in different formats and keystore files (PKCS#12 and JKS) but with the same alias (aioc). The jks and p12 files located at /pam/docker-mgmt/cert should be recreated with keytool commands, in this scenario. (If the Kron PAM server and Kron PAM Mobile App Server are installed on the same server, these files should stand as is).
*LISTING the certificates’ configurations: on 10.10.0.1
JKS:
P12:
*DELETING the certificates’ configurations: on 10.10.0.1
JKS:
P12:
*DELETING the certificate files: (Take the backup for these files) on 10.10.0.1
JKS:
P12:
*CREATING the certificate files and configurations: on 10.10.0.1
JKS:
P12:
10) ((PAM)) Using the RSA key pair created with the aioc alias, the environment configurations (kron-commons-config) in the Docker container on the Kron PAM server can be accessed by the Kron PAM Mobile App Server. For this, instead of using the customer's existing key pair, a self-signed certificate is used. This RSA key pair is stored in different formats and keystore files (PKCS#12 and JKS) but with the same alias (aioc). The jks and p12 files located at /pam/docker-mgmt/cert should be recreated with keytool commands, in this scenario. (If the Kron PAM server and Kron PAM Mobile App Server are installed on the same server, these files should stand as is).
*LISTING the certificates’ configurations: on 10.10.0.1
-JKS: sudo keytool -list -v -keystore /pam/docker-mgmt/cert/aioc.jks -storepass krondev10
-P12: sudo keytool -list -v -keystore /pam/docker-mgmt/cert/aioc.p12 -storepass krondev10 -storetype PKCS12
*DELETING the certificates’ configurations: on 10.10.0.1
-JKS: sudo keytool -delete -alias aioc -keystore /pam/docker-mgmt/cert/aioc.jks -storepass krondev10
-P12: sudo keytool -delete -alias aioc -keystore /pam/docker-mgmt/cert/aioc.p12 -storepass krondev10
*DELETING the certificate files: (Take the backup for these files) on 10.10.0.1
-JKS: rm -rf /pam/docker-mgmt/cert/aioc.jks
-P12: rm -rf /pam/docker-mgmt/cert/aioc.p12
*CREATING the certificate files and configurations: on 10.10.0.1
-JKS:
sudo keytool \
-genkeypair -alias aioc -keyalg RSA -keysize 2048 \
-dname "CN=localhost,OU=Kron,O=Kron,C=TR" \
-ext "SAN:c=DNS:localhost,DNS:kron-commons-alfred,DNS:kron-commons-auth,DNS:kron-commons-license,DNS:kron-commons-network,DNS:kron-commons-notification,DNS:kron-commons-config,DNS:pta,DNS:auth,DNS:redis,DNS:uba,DNS:mobile-api,DNS:superset,DNS:nginx,DNS:tcp-proxy,DNS:kron-commons-aggregator,DNS:kron-dam-metadata,DNS:kron-dam-portal,IP:127.0.0.1,IP:10.10.0.1,IP:10.10.0.2" \
-storepass krondev10 -keypass krondev10 -keystore /pam/docker-mgmt/cert/aioc.jks -validity 3650
-P12:
sudo keytool \
-genkeypair -alias aioc -keyalg RSA -keysize 2048 \
-storetype PKCS12 -dname "CN=localhost,OU=Kron,O=Kron,C=TR" \
-ext "SAN:c=DNS:localhost,DNS:kron-commons-alfred,DNS:kron-commons-auth,DNS:kron-commons-license,DNS:kron-commons-network,DNS:kron-commons-notification,DNS:kron-commons-config,DNS:pta,DNS:auth,DNS:redis,DNS:uba,DNS:mobile-api,DNS:superset,DNS:nginx,DNS:tcp-proxy,DNS:kron-commons-aggregator,DNS:kron-dam-metadata,DNS:kron-dam-portal,IP:127.0.0.1,IP:10.10.0.1,IP:10.10.0.2" \
-storepass krondev10 -keypass krondev10 -keystore /pam/docker-mgmt/cert/aioc.p12 -validity 3650
11)((PAM)) The following keytool command should be executed to import certificate on 10.10.0.1:
12) ((PAM)) The ownership and mode configurations should be changed for these files on 10.10.0.1:
13)((PAM)) All of the docker services on the Kron PAM server should be restarted, and the mobile-api service should be stopped on 10.10.0.1:
14)((PAM)) The certificate files (jks and p12) created in the 9th step (10.10.0.1) should be transferred to Kron PAM Mobile App Server (10.10.0.2).
Note that, jks and p12 files should be identical on both environments. To check this, the following commands should be run on both environments:
! If the files are not identical due to the 3rd party SSH/SFTP tool (e.g. MobaXterm) usage, sshpass command can be used for file transfer:
15)((DMZ)) After the file transfer from Kron PAM server to Kron PAM Mobile App Server, ownership and mode configurations should be changed for these files on 10.10.0.2:
16)((DMZ)) Lastly, all of the docker services on the Kron PAM Mobile App Server should be stopped and the mobile-api service should be started on 10.10.0.2: