← Back to plugin index

SAML Federation Config

Description
Federation settings used for all SAML 2.0 use-cases.
Type name
SamlFederation
Class
com.airlock.iam.saml2.application.configuration.SamlFederationConfig
May be used by
License-Tags
SamlIdp,SamlSp
Properties
Error Page URL (errorpageUrl)
Description
URL where the user is redirected to when an internal SAML2 error happens. Use
  • ui/app/error/message for Flow-based SAML2
    Relative URIs not starting with a slash are resolved against the current context path.

When customized and behind an Airlock Gateway (WAF), a "URL Encryption Exception" must be configured.

Attributes
String
Optional
Default value
ui/app/error/message
Suggested values
ui/app/error/message
Max Content Length (maxContentLength)
Description
The maximum content-length in bytes for an HTTP Request that will be allowed.
This avoids unnecessary parsing of very long payloads, avoiding DoS attacks. Set to 0 (zero) to disable this check.
Attributes
Integer
Optional
Default value
16384
XML Signature Keystore Provider (xmlSignatureKeystoreProvider)
Description
The keystore provider to use for XML signatures and encryption.
If this IAM instance is only used as a service provider and does not make use of any signature nor encryption, the special "SAML No Cert Key Provider" can be used which does not require any keystores. Notice though that even a simple service provider should make use of signatures, especially with SP-initiated SSO and with Single-Logout (SLO).
Attributes
Plugin-Link
Mandatory
Assignable plugins
XML Canonicalization Algorithm (xmlCanonicalizationAlgorithm)
Description
XML canonicalization algorithm. Used for SAML XML signature generation and verification.
Attributes
String
Optional
Default value
http://www.w3.org/2001/10/xml-exc-c14n#
Allowed values
http://www.w3.org/2001/10/xml-exc-c14n#, http://www.w3.org/2001/10/xml-exc-c14n#WithComments, http://www.w3.org/TR/2001/REC-xml-c14n-20010315, http://www.w3.org/TR/2001/REC-xml-c14n-20010315#WithComments
XML Signature Algorithm (xmlSignatureAlgorithm)
Description
XML signature algorithm. Used for SAML XML and query signature generation.
The (deprecated) value "SHA1 (automatic RSA/DSA)" automatically chooses "http://www.w3.org/2000/09/xmldsig#rsa-sha1" or "http://www.w3.org/2000/09/xmldsig#dsa-sha1" depending on the type of the key found in the keystore. However please use a more secure hash instead, as SHA-1 is not considered to be secure.
Attributes
String
Optional
Default value
http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
Allowed values
http://www.w3.org/2001/04/xmldsig-more#rsa-sha512, http://www.w3.org/2001/04/xmldsig-more#rsa-sha384, http://www.w3.org/2001/04/xmldsig-more#rsa-sha256, http://www.w3.org/2000/09/xmldsig#rsa-sha1, http://www.w3.org/2000/09/xmldsig#dsa-sha1, SHA1 (automatic RSA/DSA), http://www.w3.org/2001/04/xmldsig-more#rsa-md5
Allowed XML Signature Algorithm(s) (allowedXmlSignatureAlgorithms)
Description
Allowed XML signature algorithm(s) used for XML and query signature verification.
Attributes
String-List
Optional
Default value
[http://www.w3.org/2001/04/xmldsig-more#rsa-sha512, http://www.w3.org/2001/04/xmldsig-more#rsa-sha384, http://www.w3.org/2001/04/xmldsig-more#rsa-sha256]
XML Signature Digest Method (xmlSignatureDigestMethod)
Description
XML signature digest method. Used for SAML XML signature generation and verification.
Attributes
String
Optional
Default value
http://www.w3.org/2001/04/xmlenc#sha256
Allowed values
http://www.w3.org/2001/04/xmlenc#sha512, http://www.w3.org/2001/04/xmlenc#sha256, http://www.w3.org/2000/09/xmldsig#sha1, http://www.w3.org/2001/04/xmlenc#ripemd160
XML Transformation Algorithm (xmlTransformationAlgorithm)
Description
XML transformation algorithm. Used for SAML XML signature generation and verification.
Attributes
String
Optional
Default value
http://www.w3.org/2001/10/xml-exc-c14n#
Allowed values
http://www.w3.org/2001/10/xml-exc-c14n#, http://www.w3.org/2001/10/xml-exc-c14n#WithComments, http://www.w3.org/TR/2001/REC-xml-c14n-20010315, http://www.w3.org/TR/2001/REC-xml-c14n-20010315#WithComments, http://www.w3.org/TR/1999/REC-xslt-19991116, http://www.w3.org/2000/09/xmldsig#base64, http://www.w3.org/TR/1999/REC-xpath-19991116, http://www.w3.org/2000/09/xmldsig#enveloped-signature, http://www.w3.org/TR/2001/WD-xptr-20010108, http://www.w3.org/2002/04/xmldsig-filter2, http://www.w3.org/2002/06/xmldsig-filter2, http://www.nue.et-inf.uni-siegen.de/~geuer-pollmann/#xpathFilter
Key Transport Algorithm (keyTransportAlgorithm)
Description
The Key Transport algorithm used to encrypt and decrypt keys.
Attributes
Plugin-Link
Optional
Assignable plugins
Password Decoder (passwordDecoder)
Description
Used to decode a possibly encrypted password from a file to access a keystore and the keys contained. Will also be used to decode the configured BASIC AUTH password.
The default implementation also supports encrypted passwords using the "[ENC]" prefix.
Attributes
String
Optional
Default value
com.airlock.iam.saml2.infrastructure.plugin.Saml2PasswordDecoder
Debug Provider (debugProvider)
Description
Defines the class name of the DebugProvider to use to create instances used for debug logging.
Attributes
String
Optional
Default value
com.airlock.iam.saml2.infrastructure.plugin.DebugProviderImpl
Log Provider (logProvider)
Description
Specifies the implementation for the Logger interface to log errors and special access logs.
Attributes
String
Optional
Default value
com.airlock.iam.saml2.infrastructure.plugin.LoggerImpl
Configuration Provider (configurationProvider)
Description
Specifies the implementation of the ConfigurationInstance providing all library-wide settings as well as specific SAML properties and entities.
Attributes
String
Optional
Default value
com.airlock.iam.saml2.infrastructure.plugin.configuration.ConfigurationInstanceImpl
Datastore Provider (datastoreProvider)
Description
Specifies the default implementation for the DataStoreProvider interface providing access to an optional data store holding user data to include in an assertion.
Attributes
String
Optional
Default value
com.airlock.iam.saml2.infrastructure.plugin.DataStoreProviderImpl
Session Provider (sessionProvider)
Description
Specifies the implementation for the SessionProvider interface providing access to a federation session storing information about protocols used and service providers accessed for a specific authenticated user.
Attributes
String
Optional
Default value
com.airlock.iam.saml2.infrastructure.plugin.SessionProviderImpl
IdP AuthnContext Mapper (idpAuthnContextMapper)
Description
Specifies the implementation for the IDPAuthnContextMapper interface which defines how the AuthnContext is created in the Assertion.
Attributes
String
Optional
Default value
com.airlock.iam.saml2.infrastructure.plugin.IDPAuthnContextMapperImpl
IdP Account Mapper (idpAccountMapper)
Description
Specifies the implementation for the IDPAccountMapper interface which defines how the NameID is created in the Assertion.
Attributes
String
Optional
Default value
com.airlock.iam.saml2.infrastructure.plugin.IDPAccountMapperImpl
IdP Attribute Mapper (idpAttributeMapper)
Description
Specifies the implementation for the IDPAttributeMapper interface which defines how the Attributes are created in the Assertion.
Attributes
String
Optional
Default value
com.airlock.iam.saml2.infrastructure.plugin.IDPAttributeMapperImpl
SP Adapter (spAdapter)
Description
Specifies the implementation of the SAML2ServiceProviderAdapter. The SP Adapter is called on certain events during SAMLv2 protocol processing on the Service Provider side.
Attributes
String
Optional
Default value
com.airlock.iam.saml2.infrastructure.plugin.Saml2ServiceProviderAdapter
SP AuthnContext Mapper (spAuthnContextMapper)
Description
Specifies the implementation for the SPAuthnContextMapper interface which defines how the AuthnContext is created in the Assertion.
Attributes
String
Optional
Default value
com.airlock.iam.saml2.infrastructure.plugin.SPAuthnContextMapper
YAML Template (with default values)

type: SamlFederation
id: SamlFederation-xxxxxx
displayName: 
comment: 
properties:
  allowedXmlSignatureAlgorithms: [http://www.w3.org/2001/04/xmldsig-more#rsa-sha512, http://www.w3.org/2001/04/xmldsig-more#rsa-sha384, http://www.w3.org/2001/04/xmldsig-more#rsa-sha256]
  configurationProvider: com.airlock.iam.saml2.infrastructure.plugin.configuration.ConfigurationInstanceImpl
  datastoreProvider: com.airlock.iam.saml2.infrastructure.plugin.DataStoreProviderImpl
  debugProvider: com.airlock.iam.saml2.infrastructure.plugin.DebugProviderImpl
  errorpageUrl: ui/app/error/message
  idpAccountMapper: com.airlock.iam.saml2.infrastructure.plugin.IDPAccountMapperImpl
  idpAttributeMapper: com.airlock.iam.saml2.infrastructure.plugin.IDPAttributeMapperImpl
  idpAuthnContextMapper: com.airlock.iam.saml2.infrastructure.plugin.IDPAuthnContextMapperImpl
  keyTransportAlgorithm:
  logProvider: com.airlock.iam.saml2.infrastructure.plugin.LoggerImpl
  maxContentLength: 16384
  passwordDecoder: com.airlock.iam.saml2.infrastructure.plugin.Saml2PasswordDecoder
  sessionProvider: com.airlock.iam.saml2.infrastructure.plugin.SessionProviderImpl
  spAdapter: com.airlock.iam.saml2.infrastructure.plugin.Saml2ServiceProviderAdapter
  spAuthnContextMapper: com.airlock.iam.saml2.infrastructure.plugin.SPAuthnContextMapper
  xmlCanonicalizationAlgorithm: http://www.w3.org/2001/10/xml-exc-c14n#
  xmlSignatureAlgorithm: http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
  xmlSignatureDigestMethod: http://www.w3.org/2001/04/xmlenc#sha256
  xmlSignatureKeystoreProvider:
  xmlTransformationAlgorithm: http://www.w3.org/2001/10/xml-exc-c14n#