SAML Assertion Cookie Identity Propagator
cookieName) Note that only one cookie per cookie path and name can exist. Make sure that this cookie name does not clash with other cookie's names. For example, do not use session cookie names such as "JSESSIONID".
cookiePath) If one single assertion cookie is used for all applications, the value "/" can be used. If different tickets are used for different applications, the application's path should be used.
Note that only one cookie per cookie path and name can exist. Make sure that this cookie name does not clash with other cookie's names. For example, do not use session cookie names such as "JSESSIONID".
Make sure the configuration flag Interpret Cookie Domains is set in the Airlock Gateway (WAF) configuration. If not, the cookie path is ignored and cookies in the cookie store are sent to any back-end HTTP request of the same session. This also means that there may be only one cookie per cookie name!
It is best to consult the corresponding documentation of the web entry server or reverse proxy to get more accurate information on cookie handling.
cookieDomain) Because of security restrictions in browsers (same origin policy) it is usually not possible to set a cookie for a different domain unless the right-most two domain parts (e.g. "ergon.ch") are equal to that of the application setting the cookie.
It is possible that there are further restrictions regarding this in browsers.
If you are using a HTTP reverse proxy that stores the cookie in its session store (and does not send it to the client), make sure to understand the proxies interpretation of the cookie domain and cookie path.
Make sure the configuration flag Interpret Cookie Domains is set in the Airlock Gateway (WAF) configuration. If not the cookie domain is ignored and cookies in the cookie store are sent to any back-end HTTP request of the same session. The cookie path is also ignored meaning that there may be only one cookie per cookie name!
Airlock also supports the following cookie domain values (if the flag Interpret Cookie Domains is set):
- The value
.*results in cookies being sent to all back-end servers. This is especially useful if one authentication ticket is used for multiple back-ends. - The value
@<fully-qualified-host>results in the cookie being treated as if it were set by the host specified by "<fully-qualified-host>". If using this value, make sure the corresponding mapping also uses the fully qualified hostname.
If one single assertion cookie is used for all applications, the value "/" can be used. If different cookies are used for different applications, the applications path should be used.
cookieSecureFlag) If the cookie is marked as secure, the browser (and any HTTP proxy behaving like a browser) should send the cookie only over secure connections.
Caution: If you think that setting this flag makes your application more secure, remember that this flag just "asks" the browser to not transmit the cookie over unencrypted connections.
cookieEncodingScheme) Make sure that the component receiving the ticket uses the same URL encoding scheme.
issuer) subjectTemplate) subjectConfirmationMethod) nameIdFormat) spProvidedId) attributes) assertionValidityMillis) assertionNotBeforeSkewMillis) xmlSignatureAlgorithm) The (deprecated) value "SHA1 (automatic RSA/DSA)" automatically chooses "http://www.w3.org/2000/09/xmldsig#rsa-sha1" or "http://www.w3.org/2000/09/xmldsig#dsa-sha1" depending on the type of the key found in the keystore. However please use a more secure hash instead, as SHA-1 is not considered to be secure.
xmlSignatureDigestMethod) keystoreFile) keystorePassword) signingKeyAlias) signingKeyPassword) audienceRestrictions) If set, adds the given audiences to an AudienceRestriction element. This is usually not required. Each element of this list is included in the AudienceRestriction as a separate Audience.
e.g. If this list contains the Strings:{"https://1.airlock.com","https://2.airlock.com"} the resulting condition contains:
<saml:Conditions ...>
<saml:AudienceRestriction>
<saml:Audience>https://1.airlock.com</saml:Audience>
<saml:Audience>https://2.airlock.com</saml:Audience>
</saml:AudienceRestriction>
</saml:Conditions>
enableSubjectConfirmation) enableAuthnStatement)
type: SamlAssertionCookieIdentityPropagator
id: SamlAssertionCookieIdentityPropagator-xxxxxx
displayName:
comment:
properties:
assertionNotBeforeSkewMillis: 5000
assertionValidityMillis: 30000
attributes:
audienceRestrictions:
cookieDomain:
cookieEncodingScheme: UTF-8
cookieName:
cookiePath: /
cookieSecureFlag: false
enableAuthnStatement: true
enableSubjectConfirmation: true
issuer:
keystoreFile:
keystorePassword:
nameIdFormat: urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
signingKeyAlias:
signingKeyPassword:
spProvidedId:
subjectConfirmationMethod: urn:oasis:names:tc:SAML:2.0:cm:sender-vouches
subjectTemplate: ${userId}
xmlSignatureAlgorithm: http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
xmlSignatureDigestMethod: http://www.w3.org/2001/04/xmlenc#sha256