← Back to plugin index

HTTP Signature Verification Credential Extractor

Description
Verifies the HTTP Signature from the "Signature" header of the HTTP request according to Signing HTTP Messages. If valid, extracts the credential according to the configured extractor.
Type name
HttpSignatureVerificationCredentialExtractor
Class
com.airlock.iam.authentication.application.configuration.oneshot.HttpSignatureVerificationCredentialExtractorConfig
May be used by
Properties
Digest (digest)
Description
The HTTP Instance Digest verification according to RFC 3230. If configured, requests with body must include a digest.
Attributes
Plugin-Link
Optional
Assignable plugins
Signature Headers Verifications (signatureHeadersVerifications)
Description
Allows to define verifications on the HTTP signature. The headers parameter defines the signed data and is passed with the request to each of the configured verifications. If any of the verifications fail, the request will be rejected.

This allows to enforce certain data to be included/excluded in the signature.

Attributes
Plugin-List
Optional
Assignable plugins
Request Line Header (requestLineHeader)
Description
The name of the header containing the request line of the original HTTP request. This must be added on the Airlock Gateway (WAF) mapping's Apache Expert Settings with
RequestHeader set AL_ENV_REQUEST_LINE expr=%{THE_REQUEST}
Attributes
String
Optional
Default value
AL_ENV_REQUEST_LINE
HTTP Signature Certificate Loader (httpSignatureCertificateLoader)
Description
How to load the certificate that is used to verify the signature.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Trust Store Path (trustStorePath)
Description
Keystore file name containing certificates of trusted issuers. Certificates from the loader must be directly issued by one of the issuers in this keystore. The keystore can be of type:
  • JKS
  • PKCS12
Attributes
File/Path
Mandatory
Trust Store Password (trustStorePassword)
Description
The password used verify the authenticity of the trust store.

Depending on the keystore type, leaving this property empty (or undefined) has a different effect:

  • JKS: the keystore can be opened and used but the integrity of the keystore is not checked.
  • PKCS12: an error occurs.

Attributes
String
Optional
Sensitive
Certificate Status Checkers (certificateStatusCheckers)
Description
A list of certificate status checkers used to check the revocation status of the HTTP signature verification certificate. If more than one checker is configured, all of them are consulted and the certificate is considered revoked if at least one of them tells so.

Security warning: The revocation status is only checked for the leaf certificate. Issuer certificates are not checked for revocation. If revocation checks for issuer certificates are required, these must be performed by the administrative process that manages the IAM truststore, see property 'Trust Store Path'.

Attributes
Plugin-List
Optional
Assignable plugins
HTTP Signature Algorithm Verifier (httpSignatureAlgorithmVerifier)
Description
Verifies the signature algorithms being used. If not configured, all algorithms are allowed and therefore all supported algorithms that can be used with the certificate's key material will pass the signature verification.
Attributes
Plugin-Link
Optional
Assignable plugins
Credential Verifier (credentialVerifier)
Description
Client credential verification against the used HTTP signature signing certificate. If not configured, no verification of the credential will be performed.
Attributes
Plugin-Link
Optional
Assignable plugins
Audit Logger (auditLogger)
Description
Enables logging of signature verification information. Certificate, algorithm, signing string and the signature will be logged in case the verification was successful. This allows to verify signatures at a later point in time.

Security Warning: Signing strings contain request headers which often contain sensitive information and should therefore not be logged. If this feature is enabled, it is highly recommended that these logs are redirected to a special destination using the Logger Name.

Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: HttpSignatureVerificationCredentialExtractor
id: HttpSignatureVerificationCredentialExtractor-xxxxxx
displayName: 
comment: 
properties:
  auditLogger:
  certificateStatusCheckers:
  credentialExtractor:
  credentialVerifier:
  digest:
  httpSignatureAlgorithmVerifier:
  httpSignatureCertificateLoader:
  requestLineHeader: AL_ENV_REQUEST_LINE
  signatureHeadersVerifications:
  trustStorePassword:
  trustStorePath: