← Back to plugin index

HTTP Client With Client Certificate

Description
A HTTP client for HTTPS connections where both the server and the client are authenticated using certificates (also known as mutual authentication).
Type name
HttpClientWithClientAuth
Class
com.airlock.iam.core.misc.util.httpclient.HttpClientWithClientAuthConfig
May be used by
Properties
Key Store Path (keyStorePath)
Description
The keystore file name containing the client certificate including both private and public key.
Attributes
File/Path
Mandatory
Key Store Type (keyStoreType)
Description
Identifies the type of the keystore.
Attributes
Enum
Optional
Default value
JKS
Key Store Password (keyStorePassword)
Description
The password used to check the integrity of the keystore, or to unlock the keystore.

The password must be provided if a key store is specified.

Attributes
String
Optional
Sensitive
Private Key Password (privateKeyPassword)
Description
The password to access the private key in the keystore stored at the key store path, in case the private key is password protected.
Attributes
String
Optional
Sensitive
Connect Timeout [s] (connectTimeout)
Description
The connection and read timeout in seconds. A timeout value of zero is interpreted as 60 seconds.
Attributes
Integer
Optional
Default value
30
Read Timeout [s] (readTimeout)
Description
The read timeout in seconds. This property defines the time the client is waiting for an answer on an already established connection.
Attributes
Integer
Optional
Default value
60
Basic Auth Credentials (basicAuthCredentials)
Description
The credentials for HTTP Basic Authentication. If configured, a Basic Authentication header is sent with each request. Note that the Basic Authentication header is not sent preemptively, it is expected that the server requests it by replying with a 401 status code and a "WWW-Authenticate: Basic" header to unauthenticated requests.
Attributes
Plugin-Link
Optional
Assignable plugins
Preemptive Basic Auth (preemptiveBasicAuth)
Description
Whether the HTTP client should perform preemptive basic authentication. If set to true, the HTTP Client will automatically add the Authorization header to the HTTP request. If set to false, the HTTP client will only send the Authorization header when it receices an unauthorized response from the server. Setting this property only has an impact if the property Basic Auth Credentials is set.
Attributes
Boolean
Optional
Default value
false
Bearer Token (bearerToken)
Description
The Bearer Token to send with each request.
Attributes
String
Optional
Sensitive
Verify Server Hostname (verifyServerHostname)
Description

Enables hostname verification, i.e. the actual hostname must be the same as in the server certificate.

Security warning: Not verifying the hostname may allow connections to adversarial hosts, e.g. if they employ DNS spoofing. Only disable this property for testing and integration setups.

Attributes
Boolean
Optional
Default value
true
Trust Store Path (trustStorePath)
Description
Keystore file name containing trusted certificate issuers (and trusted certificates).

If this property is not defined the following certificate issuers are trusted:

  • The list of issuers known to the Java VM if the system property "javax.net.ssl.trustStore" is not defined.
  • The list of issuers in a keystore referenced by system property "javax.net.ssl.trustStore" if defined in instance.properties using iam.java.opts

If this property is defined then the following certificate issuers are trusted:

  • The list of issuers in the referenced truststore file and no others.

This property is only relevant if the property "Allow Only Trusted Certs" is enabled.

Attributes
File/Path
Optional
Trust Store Type (trustStoreType)
Description
Identifies the type of the keystore.
Attributes
Enum
Optional
Default value
JKS
Trust Store Password (trustStorePassword)
Description
The password used to check the integrity of the trust store, or to unlock the trust store.

The password must be provided if a trust store is specified.

Attributes
String
Optional
Sensitive
Proxy Host (proxyHost)
Description
The hostname of the HTTP proxy server (if any).
Attributes
String
Optional
Example
proxy.company.com
Proxy Port (proxyPort)
Description
The port of the HTTP proxy server (if any).
Attributes
Integer
Optional
Proxy Login User (proxyLoginUser)
Description
Username for the HTTP proxy if proxy authentication is used.
Attributes
String
Optional
Example
proxyLogin
Proxy Login Password (proxyLoginPassword)
Description
Password for the HTTP proxy if proxy authentication is used.
Attributes
String
Optional
Sensitive
User Agent (userAgent)
Description
A HTTP client sends a userAgent header with each request to identify the client software. If no value or an empty value is specified, "Apache-HttpClient/4.1 (java 1.5)" is used as user agent. This value allows to overwrite the default user agent.
Attributes
String
Optional
Suggested values
Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko, Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:36.0) Gecko/20100101 Firefox/36.0, Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2272.76 Safari/537.36
Correlation ID Header Name (correlationIdHeaderName)
Description

When configured, all requests sent contain a header with the correlation ID with the configured name. If no value or an empty value is specified, the correlation ID header is not sent.

If the correlation ID is not defined, the correlation ID header is not included in sent requests.

Attributes
String
Optional
Validation RegEx: [a-zA-Z0-9_-]+
Suggested values
X-Correlation-ID
YAML Template (with default values)

type: HttpClientWithClientAuth
id: HttpClientWithClientAuth-xxxxxx
displayName: 
comment: 
properties:
  basicAuthCredentials:
  bearerToken:
  connectTimeout: 30
  correlationIdHeaderName:
  keyStorePassword:
  keyStorePath:
  keyStoreType: JKS
  preemptiveBasicAuth: false
  privateKeyPassword:
  proxyHost:
  proxyLoginPassword:
  proxyLoginUser:
  proxyPort:
  readTimeout: 60
  trustStorePassword:
  trustStorePath:
  trustStoreType: JKS
  userAgent:
  verifyServerHostname: true