<div dir="ltr"><div dir="ltr"><div class="gmail_default" style="font-family:georgia,serif">Agreed. Thanks!</div><div class="gmail_default" style="font-family:georgia,serif">I viewed the access-control.xml file from the running container and see that it is indeed allowing localhost.<br><br> <entry key="AccessByIPAddress"><br> <bean id="AccessByIPAddress" parent="shibboleth.IPRangeAccessControl"<br> p:allowedRanges="#{ {'<a href="http://127.0.0.1/32" target="_blank">127.0.0.1/32</a>', '::1/128'} }" /><br> </entry><br></div><div class="gmail_default" style="font-family:georgia,serif"><br></div><div class="gmail_default" style="font-family:georgia,serif">I don't want to allow more hosts than necessary. I do want to check the installation before moving forward.</div><div class="gmail_default" style=""><span style="font-family:georgia,serif">It might be what Paul mentioned earlier in the thread about NAT. The status page might be viewable only from within the container's localhost. I'm seeing a new </span><font face="monospace">podman0</font><font face="georgia, serif"> interface, but I get a 404 from a tomcat instance when I hit that interface. It's at least not an access denied message. I don't have tomcat running at the VM level, so I think I'm hitting tomcat inside the container.</font></div><div><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><p style="background-image:initial;background-position:initial;background-repeat:initial"><b><span style="font-family:Arial,sans-serif;color:rgb(102,102,102);background-image:initial;background-position:initial;background-repeat:initial">David Dellinger </span></b><span style="font-family:Arial,sans-serif;color:rgb(102,102,102);background-image:initial;background-position:initial;background-repeat:initial">| Sr. Systems Administrator</span><span style="font-family:Arial,sans-serif;color:rgb(89,89,89);background-image:initial;background-position:initial;background-repeat:initial"><br></span><b><span style="font-family:Arial,sans-serif;color:rgb(255,153,0)">Information Technology Services<br></span></b><span style="font-family:Arial,sans-serif;color:rgb(89,89,89)"><a href="mailto:ddellinger@oxy.edu" target="_blank">ddellinger@oxy.edu</a> </span><span style="font-family:Arial,sans-serif;color:rgb(102,102,102)">| T 323-259-1315</span><b><span style="font-family:Arial,sans-serif;color:rgb(255,153,0)"></span></b></p><p style="margin:0in 0in 0.0001pt;font-size:11pt;font-family:Calibri,sans-serif"></p><p style="background-image:initial;background-position:initial;background-repeat:initial"><b><span style="font-family:Arial,sans-serif;color:rgb(255,153,0);background-image:initial;background-position:initial;background-repeat:initial">OXY</span></b><b><span style="font-family:Arial,sans-serif;color:rgb(102,102,102);background-image:initial;background-position:initial;background-repeat:initial"> </span></b><b><span style="font-family:Arial,sans-serif;color:rgb(102,102,102);background-image:initial;background-position:initial;background-repeat:initial">Occidental College<br></span></b><span style="font-family:Arial,sans-serif;color:rgb(102,102,102)">Mary Norton Clapp Library | 1600 Campus Road | Los Angeles, California 90041<br></span><span style="font-family:Arial,sans-serif"><a href="http://oxy.edu/its" target="_blank">oxy.edu/its</a><span> </span></span></p></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, Aug 14, 2023 at 9:06 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">> The container config burn-in doesn't have access-control as one of the items<br>
> that are available, at least in the vanilla build from/for InCommon.<br>
<br>
That approach in no way constrains your ability, and in fact need, to be able to customize any and all configuration files.<br>
<br>
The entire configuration is, and always must be, entirely controlled by you.<br>
<br>
-- Scott<br>
<br>
<br>
</blockquote></div>
</div>