Skip to content
Browse Gluu Server 4.5

Release

oxTrust JSON Properties

#Overview

This page explains the oxTrust JSON Configuration which can by found by navigating to Configuration > JSON Configuration.

#oxtrust.properties

image

The following fields are available for edit in the menu.

Fields/AttributesDescription
baseDNThe base distinguished name of oxTrust. The default is o=gluu
orgSupportEmailThe support email address of the Gluu Server installation
applianceUrlThe URI of the appliance
baseEndpoint

#personObjectClassTypes

This class holds the relationship between the person entry and its relative object class.

Fields/AttributesDescription
item 1inetOrgPerson
item 2gluuPerson
item 3eduPerson
personCustomObjectClassgluuCustomPerson

#personObjectClassDisplayNames

This class holds the relationship between the display name of the person and the relative object class.

Fields/AttributesDescription
item 1gluuCustomPerson
item 2gluuPerson
item 3eduPerson

#contactObjectClassTypes

Items can be added under this class by clicking on the + item button.

#contactObjectClassDisplayNames

Items can be added under this class by clicking on the + item button.

Fields/AttributesDescription
photoRepositoryRootDirPath to the root directory of photographs
photoRepositoryThumbWidththumb width of a photo
photoRepositoryThumbHeightsets the thumb height of a photo
photoRepositoryCountLevelscount level per photo repository
photoRepositoryCountFoldersPerLevelnumber of folders per level
authModeset this tag to basic to use basic authentication or leave it blank to use oxAuth
ldifStorePath to the LDIF store
shibboleth2IdpRootDirroot directory for the shibboleth plugin
shibboleth2SpConfDirConfiguration directory for the shibboleth plugin
pokenApplicationSecret
updateStatusupdate appliance state for the site. Use true to allow, and false to forbid
svnConfigurationStoreRootRoot of the SVN configuration store
svnConfigurationStorePasswordPassword of the SVN configuration store
keystorePathPath to the keystore
keystorePasswordPassword to the keystore
allowPersonModificationEnables or disables the allowance to modify a person entry. Use true to allow (default value), and false otherwise
idpUrluri of the OpenID provider that is in use
velocityLogVelocity log filename with path
spMetadataPathPath to the Gluu Server metadata
logoLocationDirectory name for the images and logos that are used
idpSecurityKeySecurity key of the OpenID provider
idpSecurityKeyPassowrdSecurity password of the OpenID provider
idpSecurityCertSecurity certificate of the machine

#gluuSpAttributes

Items can be added here by clicking on the + item button.

Fields/AttributesDescription
configGenerationThis entry controls the automatic generation of the configuration files. Use enable to allow and disable otherwise
idpLdapProtocolProtocol used by the [LDAP][ldap] server
idpLdapServerHostname of the [LDAP][ldap] server with port
idpBindDnDomain name of the OpenID provider
idpBindPassowrdPassword for the OpenID provider
idpUserFields
gluuSpCertCertificate name and location of the Gluu Server
shibboleth3FederationRootDirRoot directory for the Shobboleth federation plugin
cacheRefreshEnabledValue of the cache refresh mechanism. Use true to enable and false otherwise
cacheRefreshIntervalMinutesTime in minutes counting down to next cache-refresh event
caCertsLocationKeystore to use for downloaded SSL certificates
caCertsPassphrasePassword for the caCerts keystore
tempCertDirTemporary location for certificates while certificate update procedure
certDirLocaiton of certificates used in configuration files
servicesRestartTriggerLocation of the file which will restart the applicance server if deleted
persistSVNState of persistence in SVN. Use true to enable or false otherwise
oxAuthSectorIdentifierUrlURI for oxAuth sector identifier
oxAuthClientIdIdentification number for oxAuth client
oxAuthClientPasswordPassword for oxAuth client
oxAuthClientScopeScope of the oxAuth client
loginRedirectUrlRedirect URI for oxAuth
logoutRedirectUrlLogout redirect URI for oxAuth

#clusteredInums

Items can be added here by clicking on the + item button.

Fields/AttributesDescription
clientAssociationAttributeAttribute which identifies the OpenID client
oxAuthIssuersURI of the issuer authorization server
ignoreValidationControl to check/ignore token validation. Use true to validate or false otherwise
umaIssuerURI of the issuer authorization server
scimUmaClientIdIdentification of the UMA client
scimUmaClientKeyId
scimUmaResourceId
scimUmaScopeScopes available for this resource
scimUmaClientKeyStoreFile
scimUmaClientKeyStorePassword
apiUmaClientID
apiUmaClientKeyId
apiUmaResourceId

#apiUmaScopes

Items can be added here by clicking on the + item button

Fields/AttributesDescription
apiUmaClientKeyStoreFile
apiUmaClientKeyStorePassword
passportUmaClientId
passportUmaClientKeyId
passportUmaResourceId
passportUmaScope
passportUmaClientKeyStoreFile
passportUmaClientKeyStorePassword
recaptchaSiteKey
recaptchaSecretKey
cssLocationPath to the CSS files
jsLocationPath to the JS files
metricReporterIntervalThe interval for metric reporter in seconds
metricReporterKeepDataDaysThe number of days to keep metric reported data
metricReporterEnabledBoolean value specifying whether to enable Metric Reporter
rptConnectionPoolUseConnectionPooling
rptConnectionPoolMaxTotal
rptConnectionPoolDefaultMaxPerRoute
rptConnectionPoolValidateAfterInactivity
rptConnectionPoolCustomKeepAliveTimeout
scimTestMode
shibbolethVersion
shibboleth3ldpRootDir
shibboleth3SpConfDir
organizationName
idp3SigningCert
idp3EncryptionCert
oxIncommonFlag
loggingLevelLogging level for oxTrust loggers

#clientWhiteList

This list details the whitelisted client redirection URIs

#clientBlackList

This list details the blacklisted client redirection URIs

#Scim Properties

Fields/AttributesDescription
MAX COUNTMaximum value "count" query parameter can take (also used as default value when not specified)
disableJdkLoggerBoolean value specifying whether to enable JDK Loggers
passwordResetRequestExpirationTimeExpiration time in seconds for password reset requests
cleanServiceIntervalTime interval for the Clean Service in seconds
authenticationRecaptchaEnabledBoolean value specifying whether to enable Recaptcha on authentication
enforceEmailUniquenessBoolean value specifying whether to enforce email uniqueness on oxTrust side

#Description of oxTrust properties

Descriptions for oxTrust properties can be viewed here and the oxTrust import JSON description is here