Digest (digest)
Description
The HTTP Instance Digest verification according to
RFC 3230. If configured, requests with body must include a digest.
Attributes
Assignable plugins
Signature Headers Verifications (signatureHeadersVerifications)
Description
Allows to define verifications on the HTTP signature. The headers parameter defines the signed data and is passed with the request to each of the configured verifications. If any of the verifications fail, the request will be rejected.
This allows to enforce certain data to be included/excluded in the signature.
Attributes
Assignable plugins
Request Line Header (requestLineHeader)
Description
The name of the header containing the request line of the original HTTP request. This must be added on the Airlock Gateway (WAF) mapping's Apache Expert Settings with
RequestHeader set AL_ENV_REQUEST_LINE expr=%{THE_REQUEST}
Attributes
Default value
AL_ENV_REQUEST_LINE
HTTP Signature Certificate Loader (httpSignatureCertificateLoader)
Description
How to load the certificate that is used to verify the signature.
Attributes
Assignable plugins
Trust Store Path (trustStorePath)
Description
Keystore file name containing certificates of trusted issuers. Certificates from the loader must be
directly issued by one of the issuers in this keystore. The keystore can be of type:
Attributes
Trust Store Password (trustStorePassword)
Description
The password used verify the authenticity of the trust store.
Depending on the keystore type, leaving this property empty (or undefined) has a different effect:
- JKS: the keystore can be opened and used but the integrity of the keystore is not checked.
- PKCS12: an error occurs.
Attributes
String
Optional
Sensitive
Certificate Status Checkers (certificateStatusCheckers)
Description
A list of certificate status checkers used to check the revocation status of the HTTP signature verification certificate. If more than one checker is configured, all of them are consulted and the certificate is considered revoked if at least one of them tells so.
Security warning: The revocation status is only checked for the leaf certificate. Issuer certificates are not checked for revocation. If revocation checks for issuer certificates are required, these must be performed by the administrative process that manages the IAM truststore, see property 'Trust Store Path'.
Attributes
Assignable plugins
Credential Extractor (credentialExtractor)
Description
The client credential extractor.
Attributes
Assignable plugins
HTTP Signature Algorithm Verifier (httpSignatureAlgorithmVerifier)
Description
Verifies the signature algorithms being used. If not configured, all algorithms are allowed and therefore all supported algorithms that can be used with the certificate's key material will pass the signature verification.
Attributes
Assignable plugins
Credential Verifier (credentialVerifier)
Description
Client credential verification against the used HTTP signature signing certificate. If not configured, no verification of the credential will be performed.
Attributes
Assignable plugins
Audit Logger (auditLogger)
Description
Enables logging of signature verification information. Certificate, algorithm, signing string and the signature will be logged in case the verification was successful. This allows to verify signatures at a later point in time.
Security Warning: Signing strings contain request headers which often contain sensitive information and should therefore not be logged. If this feature is enabled, it is highly recommended that these logs are redirected to a special destination using the Logger Name.
Attributes
Assignable plugins