HTTP Password Service
passwordChangeUrl) See note in plug-in description when using SSL (HTTPS instead of HTTP).
httpParamUsername) userPersister) userDataParams) staticParams) In many cases, the submit button value must be sent to an application to make it think that the button has been pressed.
httpParamOldPassword) httpParamNewPassword) expectedResponseStatusCode) The response status code is always being checked on password changes. A password change is successful if the response status code equals the expected status code. Additionally a pattern can be searched in the response body using the "expected response body pattern" configuration property.
expectedResponseBodyPattern) allowOnlyTrustedCerts) Only allow connections to servers whose certificate is trusted. See documentation of property "Trust Store Path" for more information about what certificates are trusted.
Security warning: Trusting all certificates allows connections to adversarial hosts. Only disable this property for testing and integration setups.
verifyServerHostname) Enables hostname verification, i.e. the actual hostname must be the same as in the server certificate.
Security warning: Not verifying the hostname may allow connections to adversarial hosts, e.g. if they employ DNS spoofing. Only disable this property for testing and integration setups.
trustStorePath) If this property is not defined the following certificate issuers are trusted:
- The list of issuers known to the Java VM if the system property "javax.net.ssl.trustStore" is not defined.
- The list of issuers in a keystore referenced by system property "javax.net.ssl.trustStore" if defined in instance.properties using iam.java.opts
If this property is defined then the following certificate issuers are trusted:
- The list of issuers in the referenced truststore file and no others.
This property is only relevant if the property "Allow Only Trusted Certs" is enabled.
trustStoreType) trustStorePassword) Depending on the keystore type, leaving this property empty (or undefined) has a different effect:
- JKS: the keystore can be opened and used but the integrity of the keystore is not checked.
- PKCS12: an error occurs.
connectTimeout) correlationIdHeaderName) When configured, all requests sent contain a header with the correlation ID with the configured name. If no value or an empty value is specified, the correlation ID header is not sent.
If the correlation ID is not defined, the correlation ID header is not included in sent requests.
proxyHost) proxyPort) proxyLoginUser) proxyLoginPassword)
type: HttpPasswordService
id: HttpPasswordService-xxxxxx
displayName:
comment:
properties:
allowOnlyTrustedCerts: true
connectTimeout: 10
correlationIdHeaderName:
expectedResponseBodyPattern:
expectedResponseStatusCode: 200
httpParamNewPassword:
httpParamOldPassword:
httpParamUsername:
passwordChangeUrl:
proxyHost:
proxyLoginPassword:
proxyLoginUser:
proxyPort:
staticParams:
trustStorePassword:
trustStorePath:
trustStoreType: JKS
userDataParams:
userPersister:
verifyServerHostname: true