← Back to plugin index

URL CRL Fetcher

Description
CRL (certificate revocation list) fetcher that reads the latest CRL from a URL by performing a HTTP GET request. If more than one X509 objects are encoded in returned data, only the first X509 CRL is returned.
Type name
UrlCrlFetcher
Class
com.airlock.iam.core.misc.impl.cert.crl.UrlCrlFetcher
May be used by
Properties
URL (url)
Description
The URL to get the CRL from.
Attributes
String
Mandatory
Example
https://localhost:8080/mypki/clients.crl
Example
http://crl.verisign.com/Class3InternationalServer.crl
Basic Auth Username (basicAuthUsername)
Description
Username used to fetch the CRL when a basic authentication is required the access the URL. Used in conjunction with property basic-auth-password.
Attributes
String
Optional
Example
johndoe
Basic Auth Password (basicAuthPassword)
Description
Password used to fetch the CRL when basic authentication is required to access the URL. Used in conjunction with property basic-auth-username.
Attributes
String
Optional
Sensitive
Proxy Host (proxyHost)
Description
The http proxy host if connections to the specified URL must be made using a http proxy.
Attributes
String
Optional
Example
gw.foo.bar
Example
192.168.12.13
Proxy Port (proxyPort)
Description
The http proxy port if connections to the specified URL must be made using a http proxy.
Attributes
Integer
Optional
Proxy Login User (proxyLoginUser)
Description
The user for authentication at the http proxy server. Using a http proxy does not necessarily make this property necessary. This depends on the proxy configuration.
Attributes
String
Optional
Example
felix
Example
jdoe
Proxy Login Password (proxyLoginPassword)
Description
The password for authentication at the http proxy server. Using a http proxy does not necessarily make this property necessary. This depends on the proxy configuration.
Attributes
String
Optional
Sensitive
Allow Only Trusted Certs (allowOnlyTrustedCerts)
Description

Only allow connections to servers whose certificate is trusted. See documentation of property "Trust Store Path" for more information about what certificates are trusted.

Security warning: Trusting all certificates allows connections to adversarial hosts. Only disable this property for testing and integration setups.

Attributes
Boolean
Optional
Default value
true
Verify Server Hostname (verifyServerHostname)
Description

Enables hostname verification, i.e. the actual hostname must be the same as in the server certificate.

Security warning: Not verifying the hostname may allow connections to adversarial hosts, e.g. if they employ DNS spoofing. Only disable this property for testing and integration setups.

Attributes
Boolean
Optional
Default value
true
Trust Store Path (trustStorePath)
Description
Keystore file name containing trusted certificate issuers (and trusted certificates).

If this property is not defined the following certificate issuers are trusted:

  • The list of issuers known to the Java VM if the system property "javax.net.ssl.trustStore" is not defined.
  • The list of issuers in a keystore referenced by system property "javax.net.ssl.trustStore" if defined in instance.properties using iam.java.opts

If this property is defined then the following certificate issuers are trusted:

  • The list of issuers in the referenced truststore file and no others.

This property is only relevant if the property "Allow Only Trusted Certs" is enabled.

Attributes
File/Path
Optional
Trust Store Type (trustStoreType)
Description
Identifies the type of the keystore.
Attributes
String
Optional
Default value
JKS
Allowed values
JKS, PKCS12
Trust Store Password (trustStorePassword)
Description
The password used verify the authenticity of the trust store.

Depending on the keystore type, leaving this property empty (or undefined) has a different effect:

  • JKS: the keystore can be opened and used but the integrity of the keystore is not checked.
  • PKCS12: an error occurs.

Attributes
String
Optional
Sensitive
Connect/Read Timeout [s] (connectTimeout)
Description
The connection and read timeout in seconds. A timeout value of zero is interpreted as 60 seconds.
Attributes
Integer
Optional
Default value
5
Correlation ID Header Name (correlationIdHeaderName)
Description

When configured, all requests sent contain a header with the correlation ID with the configured name. If no value or an empty value is specified, the correlation ID header is not sent.

If the correlation ID is not defined, the correlation ID header is not included in sent requests.

Attributes
String
Optional
Validation RegEx: [a-zA-Z0-9_-]+
Suggested values
X-Correlation-ID
YAML Template (with default values)

type: UrlCrlFetcher
id: UrlCrlFetcher-xxxxxx
displayName: 
comment: 
properties:
  allowOnlyTrustedCerts: true
  basicAuthPassword:
  basicAuthUsername:
  connectTimeout: 5
  correlationIdHeaderName:
  proxyHost:
  proxyLoginPassword:
  proxyLoginUser:
  proxyPort:
  trustStorePassword:
  trustStorePath:
  trustStoreType: JKS
  url:
  verifyServerHostname: true