HTTP Signature X.509 Certificate URL Loader
Description
Loads the certificate for an HTTP signature keyId. The keyId must be an HTTP(S) URL indicating where the certificate is located. The HTTP response body must contain a PEM, DER or base64-encoded DER X.509 certificate. Certificates will be cached in memory, hence once a certificate is loaded it will remain in the cache until IAM is restarted, a configuration is activated or the maximum cache size is reached.
May be used by
Properties
HTTP Client (
httpClientConfig) Description
HTTP client used for the requests. It is recommended to use a trust store containing trusted certificates for HTTPs connections.
Attributes
Plugin-Link
Optional
Assignable plugins
Maximum Cache Size (
maximumCacheSize) Description
Defines the maximum number of certificates that reside in the cache. This will limit the memory usage of this feature but may also have a performance trade-off. A regular X.509 certificate has a size of approximately 3kB. If the maximum number of certificates in the cache is reached, certificates that haven't been used recently or very often will be removed from the cache to make space for the newly cached certificate.
A maximum cache size of 0 disables the cache.
Attributes
Integer
Optional
Default value
1000
YAML Template (with default values)
type: HttpSignatureX509CertificateHttpUrlLoader
id: HttpSignatureX509CertificateHttpUrlLoader-xxxxxx
displayName:
comment:
properties:
httpClientConfig:
maximumCacheSize: 1000