URL CRL Fetcher
url) basicAuthUsername) basic-auth-password. basicAuthPassword) basic-auth-username. proxyHost) proxyPort) proxyLoginUser) proxyLoginPassword) allowOnlyTrustedCerts) Only allow connections to servers whose certificate is trusted. See documentation of property "Trust Store Path" for more information about what certificates are trusted.
Security warning: Trusting all certificates allows connections to adversarial hosts. Only disable this property for testing and integration setups.
verifyServerHostname) Enables hostname verification, i.e. the actual hostname must be the same as in the server certificate.
Security warning: Not verifying the hostname may allow connections to adversarial hosts, e.g. if they employ DNS spoofing. Only disable this property for testing and integration setups.
trustStorePath) If this property is not defined the following certificate issuers are trusted:
- The list of issuers known to the Java VM if the system property "javax.net.ssl.trustStore" is not defined.
- The list of issuers in a keystore referenced by system property "javax.net.ssl.trustStore" if defined in instance.properties using iam.java.opts
If this property is defined then the following certificate issuers are trusted:
- The list of issuers in the referenced truststore file and no others.
This property is only relevant if the property "Allow Only Trusted Certs" is enabled.
trustStoreType) trustStorePassword) Depending on the keystore type, leaving this property empty (or undefined) has a different effect:
- JKS: the keystore can be opened and used but the integrity of the keystore is not checked.
- PKCS12: an error occurs.
connectTimeout) correlationIdHeaderName) When configured, all requests sent contain a header with the correlation ID with the configured name. If no value or an empty value is specified, the correlation ID header is not sent.
If the correlation ID is not defined, the correlation ID header is not included in sent requests.
type: UrlCrlFetcher
id: UrlCrlFetcher-xxxxxx
displayName:
comment:
properties:
allowOnlyTrustedCerts: true
basicAuthPassword:
basicAuthUsername:
connectTimeout: 5
correlationIdHeaderName:
proxyHost:
proxyLoginPassword:
proxyLoginUser:
proxyPort:
trustStorePassword:
trustStorePath:
trustStoreType: JKS
url:
verifyServerHostname: true