SAML Access Cookie Identity Propagator
This plugin performs a HTTP POST request with a SAML 2.0 assertion to an application and expects this application to set one or more access cookies. Those cookies are then added to the current response.
accessCookieSourceUrl) httpParamSaml) httpParams) In many cases, the submit button value must be sent to an application to make it think that the button has been pressed.
allowOnlyTrustedCerts) Only allow connections to servers whose certificate is trusted. See documentation of property "Trust Store Path" for more information about what certificates are trusted.
Security warning: Trusting all certificates allows connections to adversarial hosts. Only disable this property for testing and integration setups.
verifyServerHostname) Enables hostname verification, i.e. the actual hostname must be the same as in the server certificate.
Security warning: Not verifying the hostname may allow connections to adversarial hosts, e.g. if they employ DNS spoofing. Only disable this property for testing and integration setups.
trustStorePath) If this property is not defined the following certificate issuers are trusted:
- The list of issuers known to the Java VM if the system property "javax.net.ssl.trustStore" is not defined.
- The list of issuers in a keystore referenced by system property "javax.net.ssl.trustStore" if defined in instance.properties using iam.java.opts
If this property is defined then the following certificate issuers are trusted:
- The list of issuers in the referenced truststore file and no others.
This property is only relevant if the property "Allow Only Trusted Certs" is enabled.
trustStoreType) trustStorePassword) Depending on the keystore type, leaving this property empty (or undefined) has a different effect:
- In keystores like JKS, the keystore can be opened and used but the integrity of the keystore is not checked.
- In keystores like PKCS12, the keystore cannot be opened an an error occurs.
connectTimeout) correlationIdHeaderName) When configured, all requests sent contain a header with the correlation ID with the configured name. If no value or an empty value is specified, the correlation ID header is not sent.
If the correlation ID is not defined, the correlation ID header is not included in sent requests.
proxyHost) proxyPort) proxyLoginUser) proxyLoginPassword) cookies) issuer) subjectTemplate) subjectConfirmationMethod) nameIdFormat) spProvidedId) attributes) assertionValidityMillis) assertionNotBeforeSkewMillis) xmlSignatureAlgorithm) The (deprecated) value "SHA1 (automatic RSA/DSA)" automatically chooses "http://www.w3.org/2000/09/xmldsig#rsa-sha1" or "http://www.w3.org/2000/09/xmldsig#dsa-sha1" depending on the type of the key found in the keystore. However please use a more secure hash instead, as SHA-1 is not considered to be secure.
xmlSignatureDigestMethod) keystoreFile) keystorePassword) signingKeyAlias) signingKeyPassword) audienceRestrictions) If set, adds the given audiences to an AudienceRestriction element. This is usually not required. Each element of this list is included in the AudienceRestriction as a separate Audience.
e.g. If this list contains the Strings:{"https://1.airlock.com","https://2.airlock.com"} the resulting condition contains:
<saml:Conditions ...>
<saml:AudienceRestriction>
<saml:Audience>https://1.airlock.com</saml:Audience>
<saml:Audience>https://2.airlock.com</saml:Audience>
</saml:AudienceRestriction>
</saml:Conditions>
enableSubjectConfirmation) enableAuthnStatement)
type: SamlAccessCookieIdentityPropagator
id: SamlAccessCookieIdentityPropagator-xxxxxx
displayName:
comment:
properties:
accessCookieSourceUrl:
allowOnlyTrustedCerts: true
assertionNotBeforeSkewMillis: 5000
assertionValidityMillis: 30000
attributes:
audienceRestrictions:
connectTimeout: 10
cookies:
correlationIdHeaderName:
enableAuthnStatement: true
enableSubjectConfirmation: true
httpParamSaml:
httpParams:
issuer:
keystoreFile:
keystorePassword:
nameIdFormat: urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
proxyHost:
proxyLoginPassword:
proxyLoginUser:
proxyPort:
signingKeyAlias:
signingKeyPassword:
spProvidedId:
subjectConfirmationMethod: urn:oasis:names:tc:SAML:2.0:cm:sender-vouches
subjectTemplate: ${userId}
trustStorePassword:
trustStorePath:
trustStoreType: JKS
verifyServerHostname: true
xmlSignatureAlgorithm: http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
xmlSignatureDigestMethod: http://www.w3.org/2001/04/xmlenc#sha256