Security Settings
encryptionKey) The encryption key (encoded in base64) is required to encrypt sensitive data in cookies or in REST responses.
The openssl tool can be used to generate a random base64 string with 256 bits (32 bytes): openssl rand -base64 32
hmacKey) The HMAC Key (encoded in base64) is required to sign sensitive data stored in cookies or REST responses.
The openssl tool can be used to generate a random base64 string with 512 bits (64 bytes): openssl rand -base64 64
Security Recommendation: Use an HMAC key length of 512 bit or greater for optimal security with the used HS512 algorithm.
corsSettings) csrfProtection) If enabled, REST endpoints are protected against CSRF attacks.
With this protection, the REST API only accepts requests that contain the custom header X-Same-Domain with an arbitrary non-empty value. In cross-origin resource sharing (CORS), such requests are not considered simple requests and thus must always be preceded by a preflight request, which prevents cross-site request forgery (CSRF) attacks.
Security warning: Disabling this feature may allow CSRF attacks. Only do so if the REST client is unable to comply with the aforementioned restrictions.
To be RFC-compliant, the endpoint /<loginapp-uri>/rest/public/tech-client-registration/oauth2/<as-identifier>/register never requires the X-Same-Domain header.
Requests to this endpoint are guaranteed to be non-simple, because of the enforced non-simple content type application/json
fixedResponseDuration) Defines how long it takes (in milliseconds) until IAM answers an unsuccessful request in the public part of the API. Faster answers are delayed until the configured duration is reached. This helps to prevent user enumeration timing attacks. The configured response delay does not affect successful or slower responses. Protection against timing attacks is only provided if IAM is able to process 'unsuccessful' requests within the configured duration.
The endpoints for the password policy check, application access check, and the user self-registration are excluded from response delaying.
usernameFilterPattern) sameSitePolicy) Specifies the 'SameSite' cookie attribute of the IAM session cookie 'iam-session-id'. The 'Secure' attribute is automatically set based on whether the request was performed using http or https (see exception for 'None' below).
- Strict: The cookie is not sent in cross-origin requests.
- Lax: The cookie is sent in some cross-origin requests, such as GET requests.
- None: The cookie is sent in cross-origin requests. In this case, the 'Secure' Cookie-Attribute is always set, regardless of whether the request was performed using http or https.Use this setting when using SAML2 in combination with cross-domain POST Bindings.
- No SameSite Attribute: No attribute is set. Browsers apply their default behaviour, usually 'Lax'.
type: SecuritySettings
id: SecuritySettings-xxxxxx
displayName:
comment:
properties:
corsSettings:
csrfProtection: true
encryptionKey:
fixedResponseDuration: 2000
hmacKey:
sameSitePolicy: LAX
usernameFilterPattern: [a-zA-Z0-9@._+-]{1,100}