...
XML element | Name | Use | Description |
---|---|---|---|
issuer | Issuer URL | Required | This URL defines the location of the IDP to whom unauthenticated requests are redirected |
realm | Realm | Optional | Security realm of the Relying Party / Application. This value is part of the SignIn request as the |
authenticationType | Authentication Type | Optional | The authentication type defines what kind of authentication is required. This information is provided in the SignInRequest to the IDP (parameter |
roleURI | Role Claim URI | Optional | Defines the attribute name of the SAML token which contains the roles. |
roleDelimiter | Role Value Delimiter | Optional | There are different ways to encode multi value attributes in SAML.
|
claimTypesRequested | Requested claims | Optional | The claims required by the Relying Party are listed here. Claims can be optional. If a mandatory claim can't be provided by the IDP the issuance of the token should fail |
homeRealm | Home Realm | Optional | Indicates the Resource IDP the home realm of the requestor. This may be an URL or an identifier like urn: or uuid: and depends on the Resource IDP implementation. This value is part of the SignIn request as the |
tokenValidators | TokenValidators | Custom Token validator classes can be configured here. The SAML Token validator is enabled by default. |
Attributes resolved at runtime
...
Code Block | ||||
---|---|---|---|---|
| ||||
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<FedizConfig>
<contextConfig name="/fedizhelloworld">
<audienceUris>
<audienceItem>https://localhost:8443/fedizhelloworld</audienceItem>
</audienceUris>
<certificateStores>
<keyStore file="conf/stsstore.jks" password="stsspass" type="file" />
</certificateStores>
<maximumClockSkew>10</maximumClockSkew>
<trustedIssuers>
<issuer name="issuer 1" certificateValidation="ChainTrust" subject=".*CN=www.sts.com.*" />
</trustedIssuers>
<protocol xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="federationProtocolType" version="1.2">
<issuer>https://localhost:9443/fedizidp/</issuer>
<roleDelimiter>,</roleDelimiter>
<roleURI>http://schemas.xmlsoap.org/ws/2005/05/identity/claims/role</roleURI>
<claimTypesRequested>
<claimType type="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/role" optional="true" />
</claimTypesRequested>
<authenticationType type="String" value="http://docs.oasis-open.org/wsfed/authorization/200706/authntypes/smartcard" />
<homeRealm type="Class" value="example.HomeRealmCallbackHandler" />
<tokenValidators>
<validator>org.apache.cxf.fediz.core.CustomValidator</validator>
</tokenValidators>
</protocol>
</contextConfig>
</FedizConfig>
|