Skip to content
Browse Gluu Server 4.4

Release

oxAuth JSON Properties

#Overview

This page explains the JSON Configuration which can be accessed by navigating to Configuration > JSON Configuration > oxAuth Configuration.

#oxAuth.properties

image

The following tables include the name and description of each configurable oxAuth property:

#General Configuration

NameDescription
sessionAsJwtExperimental feature. This saves session data as a JWT
IssuerURL using the https scheme that OP asserts as Issuer identifier
baseEndpointThe base URL for endpoints
authorizationEndpointThe authorization endpoint URL
tokenEndpointThe token endpoint URL
tokenRevocationEndpointThe URL for the access_token or refresh_token revocation endpoint
userInfoEndpointThe User Info endpoint URL
clientInfoEndpointThe Client Info endpoint URL
checkSessionIFrameURL for an OP IFrame that supports cross-origin communications for session state information with the RP Client using the HTML5 postMessage API
endSessionEndpointURL at the OP to which an RP can perform a redirect to request that the end user be logged out at the OP
jwksUriURL of the OP's JSON Web Key Set (JWK) document. This contains the signing key(s) the RP uses to validate signatures from the OP
registrationEndpointRegistration endpoint URL
openIdDiscoveryEndpointDiscovery endpoint URL
idGenerationEndpointID Generation endpoint URL
introspectionEndpointIntrospection endpoint URL
introspectionAccessTokenMustHaveUmaProtectionScopeIf True, rejects introspection requests if access_token does not have the uma_protection scope in its authorization header
umaConfigurationEndpointUMA Configuration endpoint URL
sectorIdentifierEndpointSector Identifier endpoint URL
oxElevenGenerateKeyEndpointoxEleven Generate Key endpoint URL
oxElevenSignEndpointoxEleven Sign endpoint URL
oxElevenVerifySignatureEndpointoxEleven Verify Signature endpoint URL
oxElevenDeleteKeyEndpointoxEleven Delete Key endpoint URL
oxElevenJwksEndpointoxEleven JWKS endpoint URL
openidSubAttributeSpecifies which LDAP attribute is used for the subject identifier claim
responseTypesSupportedThis list details which OAuth 2.0 response_type values are supported by this OP. By default, every combination of code, token and id_token is supported.
grantTypesSupportedThis list details which OAuth 2.0 grant types are supported by this OP
dynamicGrantTypeDefaultThis list details which OAuth 2.0 grant types can be set up with the client registration API
subjectTypesSupportedThis list details which Subject Identifier types that the OP supports. Valid types include pairwise and public.
defaultSubjectTypeThe default subject type used for dynamic client registration
userInfoSigningAlgValuesSupportedThis JSON Array lists which JWS signing algorithms (alg values) [JWA] can be used by for the UserInfo endpoint to encode the claims in a JWT
userInfoEncryptionAlgValuesSupportedThis JSON Array lists which JWS encryption algorithms (alg values) [JWA] can be used by for the UserInfo endpoint to encode the claims in a JWT
userInfoEncryptionEncValuesSupportedThis JSON Array lists which JWS encryption algorithms (enc values) [JWA] can be used by for the UserInfo endpoint to encode the claims in a JWT
idTokenSigningAlgValuesSupportedA list of the JWS signing algorithms (alg values) supported by the OP for the ID Token to encode the Claims in a JWT
idTokenEncryptionAlgValuesSupportedA list of the JWE encryption algorithms (alg values) supported by the OP for the ID Token to encode the Claims in a JWT
idTokenEncryptionEncValuesSupportedA list of the JWE encryption algorithms (enc values) supported by the OP for the ID Token to encode the Claims in a JWT
requestObjectSigningAlgValuesSupportedA list of the JWS signing algorithms (alg values) supported by the OP for Request Objects
requestObjectEncryptionAlgValuesSupportedA list of the JWE encryption algorithms (alg values) supported by the OP for Request Objects
requestObjectEncryptionEncValuesSupportedA list of the JWE encryption algorithms (enc values) supported by the OP for Request Objects
tokenEndpointAuthMethodsSupportedA list of Client Authentication methods supported by this Token Endpoint
tokenEndpointAuthSigningAlgValuesSupportedA list of the JWS signing algorithms (alg values) supported by the Token Endpoint for the signature on the JWT used to authenticate the Client at the Token Endpoint for the private_key_jwt and client_secret_jwt authentication methods
dynamicRegistrationCustomAttributesThis list details the custom attributes for dynamic registration
displayValuesSupportedA list of the display parameter values that the OpenID Provider supports
claimTypesSupportedA list of the Claim Types that the OpenID Provider supports
serviceDocumentationURL of a page containing human-readable information that developers might want or need to know when using the OpenID Provider
claimsLocalesSupportedThis list details the languages and scripts supported for values in the claims being returned
idTokenTokenBindingCnfValuesSupportedArray containing a list of the JWT Confirmation Method member names supported by the OP for Token Binding of ID Tokens. The presence of this parameter indicates that the OpenID Provider supports Token Binding of ID Tokens. If omitted, the default is that the OpenID Provider does not support Token Binding of ID Tokens
uiLocalesSupportedThis list details the languages and scripts supported for the user interface
persistIdTokenInLdapSpecifies whether to persist id_token into LDAP (otherwise saves into cache)
persistRefreshTokenInLdapSpecifies whether to persist refresh_token into LDAP (otherwise saves into cache)
claimsParameterSupportedSpecifies whether the OP supports use of the claims parameter
requestParameterSupportedBoolean value specifying whether the OP supports use of the request parameter
requestUriParameterSupportedBoolean value specifying whether the OP supports use of the request_uri parameter
requireRequestUriRegistrationBoolean value specifying whether the OP requires any request_uri values used to be pre-registered using the request_uris registration parameter
opPolicyUriURL that the OpenID Provider provides to the person registering the Client to read about the OP's requirements on how the Relying Party can use the data provided by the OP
opTosUriURL that the OpenID Provider provides to the person registering the Client to read about OpenID Provider's terms of service
authorizationCodeLifetimeThe lifetime of the Authorization Code
refreshTokenLifetimeThe lifetime of the Refresh Token
idTokenLifetimeThe lifetime of the ID Token
accessTokenLifetimeThe lifetime of the short lived Access Token
umaRptLifetimeUMA RPT lifetime
umaTicketLifetimeUMA ticket lifetime
umaPctLifetimeUMA PCT lifetime
umaResourceLifetimeUMA Resource lifetime
umaAddScopesAutomaticallyAdd UMA scopes automatically if it is not registered yet
umaGrantAccessIfNoPoliciesSpecify whether to grant access to resources if there is no any policies associated with scopes
umaRestrictResourceToAssociatedClientRestrict access to resource by associated client
umaKeepClientDuringResourceSetRegistrationSave client information during resource registration
umaRptAsJwtIssue RPT as JWT or as random string
cleanServiceIntervalTime interval for the Clean Service in seconds
cleanServiceBatchChunkSizeClean service chunk size which is used during clean up.
cleanServiceBaseDnsArray of base DNs where clean service will look up for expired entities.
keyRegenerationEnabledBoolean value specifying whether to regenerate keys
keyRegenerationIntervalThe interval for key regeneration in hours
defaultSignatureAlgorithmThe default signature algorithm to sign ID Tokens
oxOpenIdConnectVersionOpenID Connect Version
organizationInumThe Organization Inum
oxIdURL for the Inum generator Service
dynamicRegistrationEnabledBoolean value specifying whether to enable Dynamic Registration
dynamicRegistrationExpirationTimeExpiration time in seconds for clients created with dynamic registration, 0 or -1 means never expire
dynamicRegistrationPersistClientAuthorizationsBoolean value specifying whether to persist client authorizations
trustedClientEnabledBoolean value specifying whether a client is trusted and no authorization is required
dynamicRegistrationScopesParamEnabledBoolean value specifying whether to enable scopes parameter in dynamic registration
dynamicRegistrationCustomObjectClassLDAP custom object class for dynamic registration
personCustomObjectClassListThis list details LDAP custom object classes for dynamic person enrollment
authenticationFiltersEnabledBoolean value specifying whether to enable user authentication filters
clientAuthenticationFiltersEnabledBoolean value specifying whether to enable client authentication filters
clientRegDefaultToCodeFlowWithRefreshBoolean value specifying whether to add Authorization Code Flow with Refresh grant during client registration.
authenticationFiltersThis list details filters for user authentication
clientAuthenticationFiltersThis list details filters for client authentication
sessionIdUnusedLifetimeThe lifetime for unused session states
sessionIdUnauthenticatedUnusedLifetimeThe lifetime for unused unauthenticated session states
sessionIdLifetimeThe lifetime of session id in seconds. If 0 or -1 then expiration is not set. session_id cookie expires when browser session ends.
serverSessionIdLifetimeDedicated property to control lifetime of the server side OP session object in seconds. Overrides sessionIdLifetime. By default value is 0, so object lifetime equals sessionIdLifetime (which sets both cookie and object expiration). It can be useful if goal is to keep different values for client cookie and server object.
sessionIdRequestParameterEnabledBoolean value specifying whether to enable session_id HTTP request parameter
sessionIdPersistOnPromptNoneBoolean value specifying whether to persist session ID on prompt none
fapiCompatibilityBoolean value specifying whether to turn on FAPI compatibility mode. If true AS behaves in more strict mode.
consentGatheringScriptBackwardCompatibilityBoolean value specifying whether to turn on Consent Gathering Script backward compatibility mode. If true AS will pick up script with higher level globally. If false (default) AS will pick up script based on client configuration.
introspectionScriptBackwardCompatibilityBoolean value specifying whether switch off client's introspection scripts (true value) and run all scripts that exists on server. Default value is false.
clientAuthorizationBackwardCompatibilityBoolean value specifying whether switch to old way of fetching client authorizations (querying by userInum=<v>&clientId=<c> filter instead of getting by key v_c introduced in 4.2.1 which impacts performance).
rejectJwtWithNoneAlgBoolean value specifying whether reject JWT requested or validated with algorithm None. Default value is true.
spontaneousScopeLifetimeThe lifetime of spontaneous scope in seconds.
configurationUpdateIntervalThe interval for configuration update in seconds
cssLocationThe location for CSS files
jsLocationThe location for JavaScript files
imgLocationThe location for image files
metricReporterIntervalThe interval for metric reporter in seconds
metricReporterKeepDataDaysThe days to keep metric reported data
metricReporterEnabledBoolean value specifying whether to enable Metric Reporter
pairwiseIdTypethe pairwise ID type
pairwiseCalculationKeyKey to calculate algorithmic pairwise IDs
pairwiseCalculationSaltSalt to calculate algorithmic pairwise IDs
shareSubjectIdBetweenClientWithSameSectorIdWhen true, clients with the same Sector ID also share the same Subject ID.
webKeysStorageWeb Key Storage Type
dnNameDN of certificate issuer
keyStoreFileThe Key Store File (JKS)
keyStoreSecretThe Key Store password
keySelectionStrategyKey Selection Strategy : OLDER (default), NEWER, FIRST
endSessionWithAccessTokenChoose whether to accept access tokens to call end_session endpoint
сookieDomainSets cookie domain for all cookies created by OP
clientWhiteListThis list specifies which client redirection URIs are white-listed
clientBlackListThis list specified which client redirection URIs are black-listed
legacyIdTokenClaimsChoose whether to include claims in ID tokens
customHeadersWithAuthorizationResponseChoose whether to enable the custom response header parameter to return custom headers with the authorization response
frontChannelLogoutSessionSupportedChoose whether to support front channel session logout
useCacheForAllImplicitFlowObjectsChoose whether to persist all objects into the cache during implicit flow
invalidateSessionCookiesAfterAuthorizationFlowBoolean value to specify whether to invalidate session_id and consent_session_id cookies right after successful or unsuccessful authorization
updateUserLastLogonTimeChoose if application should update oxLastLogonTime attribute upon user authentication
updateClientAccessTimeChoose if application should update oxLastAccessTime/oxLastLogonTime attributes upon client authentication
enableClientGrantTypeUpdateChoose if client can update Grant Type values
loggingLevelSpecify the logging level for oxAuth loggers
corsConfigurationFiltersThis list specifies the CORS configuration filters
logClientIdOnClientAuthenticationChoose if application should log the Client ID on client authentication
logClientNameOnClientAuthenticationChoose if application should log the Client Name on client authentication
authorizationRequestCustomAllowedParametersThis list details the allowed custom parameters for authorization requests
legacyDynamicRegistrationScopeParamChoose whether to allow legacy dynamic registration JSON array parameters
openidScopeBackwardCompatabilitySet to false to only allow token endpoint request for openid scope with grant type equals to authorization_code, restrict access to userinfo to scope openid and only return id_token if scope contains openid
skipAuthorizationForOpenIdScopeAndPairwiseIdChoose whether to skip authorization if a client has an OpenId scope and a pairwise ID
allowPostLogoutRedirectWithoutValidationAllows post-logout redirect without validation for the End Session endpoint (still AS validates it against clientWhiteList url pattern property)
httpLoggingEnabledEnable/disable request/response logging filter
httpLoggingExcludePathsThis list details the base URIs for which the request/response logging filter will not record activity
externalLoggerConfigurationThe path to the external log4j2 logging configuration
disableU2fEndpointChoose whether to disable U2F endpoints
disableJdkLoggerChoose whether to disable JDK loggers
errorHandlingMethodA list of possible error handling methods
useLocalCacheCache in local memory cache attributes, scopes, clients and organization entry with expiration 60 seconds
jwksAlgorithmsSupportedA list of algorithms that will be used in JWKS endpoint.
returnClientSecretOnReadBoolean value specifying whether a client_secret is returned on client GET or PUT. Set to true by default which means to return secret.
changeSessionIdOnAuthenticationBoolean value specifying whether change session_id on authentication. Default value is true.
forceOfflineAccessScopeToEnableRefreshTokenBoolean value specifying whether force offline_access scope to enable refresh_token grant type. Default value is true.
errorReasonEnabledBoolean value specifying whether to return detailed reason of the error from AS. Default value is false.
removeRefreshTokensForClientOnLogoutBoolean value specifying whether to remove Refresh Tokens on logout. Default value is false.

#Brute Force Protection

The Gluu Server comes with a feature to help protect against brute force attacks by periodically delaying login requests that occur too frequently in too short a period of time. The following parameters are listed under the authenticationProtectionConfiguration header:

NameDescription
attemptExpirationHow long, in minutes, to store a login attempt.
maximumAllowedAttemptsWithoutDelayHow many attempts the application allows before delaying
delayTimeHow long, in seconds, to delay a login attempt that exceeds the maximum allowed
bruteForceProtectionEnabledChoose whether to enable this feature

All parameters except bruteForceProtectionEnabled require a server restart for changes to take effect.

For example, the following parameters:

attemptExpiration: 15
maximumAllowedAttemptsWithoutDelay: 4
delayTime: 2
bruteForceProtectionEnabled: true

... will insert a 2 second delay after every fourth login attempt within 15 minutes of each other.

#fido2Configuration

NameDescription
authenticatorCertsFolderLocation of authenticator certificate folder
mdsAccessTokenMDS Access Token
mdsCertsFolderLocation of MDS TOC root certificate folder
mdsTocsFolderLocation of MDS TOC files folder
userAutoEnrollmentSelect whether to enroll users on enrollment/authentication requests
unfinishedRequestExpirationExpiration time in seconds for pending enrollment/authentication requests
authenticationHistoryExpirationExpiration time in seconds for approved authentication requests
serverMetadataFolderLocation of authenticator metadata in JSON format, such as virtual devices
disableFido2Enable/disable Fido2 endpoints