For those people who are running an elog instance at CERN and need to "hide" it behind the CERN Single Sign On (SSO), I've attached a working nginx.conf file to be used with OKD/PaaS at CERN.
Ideally, you can then configure the elog similar to the below, which will still allow people to register for individual elogs and be approved by an admin user. The usernames are then the CERN SSO usernames...
;
; admin
;
Admin user = lgaffney
Password file = /elog-nfs-2/ids_sso.passwd
Authentication = Webserver, File
allow password change = 0
Login expiration = 0
Self register = 3
|