Creating and using a container to execute older versions of java. Example use case is with old iDrac viewer.jnlp files that require unsecure cipher suite
Need to pull and create an older version of fedora which has in it's repos older version of java
- Building the container with
buildahwith the following Dockerfile
FROM fedora:26
RUN yum -y install xorg-x11-apps
RUN yum -y install icedtea-web
CMD [ "/usr/bin/xclock" ]
[mmethot@localhost tmp]$ cat Dockerfile
FROM fedora:26
RUN yum -y install xorg-x11-apps
RUN yum -y install icedtea-web
CMD [ "/usr/bin/xclock" ]
Note: xclock command is only used to validate if the process works.
- building the image with
buildah bud -t xclockimage . - selinux may give you gripes, in the past
setenforce 0needed to be applied to avoid some fuss
First download a new viewer.jnlp (iDrac example) file from the BMC, once done we start the container with the following:
podman run -ti -e DISPLAY --privileged --rm \
-v /run/user/${UID}/gdm/Xauthority:/run/user/0/gdm/Xauthority:Z \
-v /home/${USER}/Downloads/viewer.jnlp:/root/viewer.jnlp:Z \
--net=host \
localhost/xclockimage javaws.itweb /root/viewer.jnlp
Parameters:
-e DISPLAYis the env variable to forward a display--piveledgedis required to avoid selinux denying access tojavato open aunix_stream_socket-v ...Xauthoritybinds a volume (file) to the container, this file is the display cookie--net=hostis the easiest path to simply using host's network to connect to the iDrac hostlocalhost/xclockimageis the repo/imageNamejavaws.itweb /root/viewer.jnlpis the command to run
- selinux should be checked, test setting it to Permissive
- stale session token in the
viewer.jnlpfile. The ERROR should be something like "Login failed with an access denied error." - Simply relogin to the BMC and redownload a new console file.