cxf-commits mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From build...@apache.org
Subject svn commit: r859614 - in /websites/production/cxf/content: cache/main.pageCache fediz-configuration.html
Date Tue, 23 Apr 2013 14:47:56 GMT
Author: buildbot
Date: Tue Apr 23 14:47:56 2013
New Revision: 859614

Log:
Production update by buildbot for cxf

Modified:
    websites/production/cxf/content/cache/main.pageCache
    websites/production/cxf/content/fediz-configuration.html

Modified: websites/production/cxf/content/cache/main.pageCache
==============================================================================
Binary files - no diff available.

Modified: websites/production/cxf/content/fediz-configuration.html
==============================================================================
--- websites/production/cxf/content/fediz-configuration.html (original)
+++ websites/production/cxf/content/fediz-configuration.html Tue Apr 23 14:47:56 2013
@@ -178,7 +178,7 @@ Finally, the audience URI is validated a
 <div class="table-wrap">
 <table class="confluenceTable"><tbody><tr><th colspan="1" rowspan="1"
class="confluenceTh">XML element </th><th colspan="1" rowspan="1" class="confluenceTh">Name
</th><th colspan="1" rowspan="1" class="confluenceTh">Use </th><th colspan="1"
rowspan="1" class="confluenceTh">Description</th></tr><tr><td colspan="1"
rowspan="1" class="confluenceTd"> audienceUris </td><td colspan="1" rowspan="1"
class="confluenceTd"> Audience URI </td><td colspan="1" rowspan="1" class="confluenceTd">
Required </td><td colspan="1" rowspan="1" class="confluenceTd"> The values of
the list of audience URIs are verified against the element <tt>AudienceRestriction</tt>
in the SAML token </td></tr><tr><td colspan="1" rowspan="1" class="confluenceTd">
certificateStores </td><td colspan="1" rowspan="1" class="confluenceTd"> Trusted
certificate store </td><td colspan="1" rowspan="1" class="confluenceTd"> Required
</td><td colspan="1" rowspan="1" class="confluenceTd"> The list of keystores (JKS,
PEM) inclu
 des at least the certificate of the Certificate Authorities (CA) which signed the certificate
which is used to sign the SAML token.<br clear="none">
 If the file location is not fully qualified it needs to be relative to the Container home
directory </td></tr><tr><td colspan="1" rowspan="1" class="confluenceTd">
trustedIssuers </td><td colspan="1" rowspan="1" class="confluenceTd"> Trusted
Issuers </td><td colspan="1" rowspan="1" class="confluenceTd"> Required </td><td
colspan="1" rowspan="1" class="confluenceTd"> There are two ways to configure a trusted
issuer (IDP). Either you configure the subject name and the CA(s) who signed the certificate
of the IDP (<tt>certificateValidation=ChainTrust</tt>) or you configure the certificate
of the IDP and the CA(s) who signed it (<tt>certificateValidation=PeerTrust</tt>)</td></tr><tr><td
colspan="1" rowspan="1" class="confluenceTd"> maximumClockSkew </td><td colspan="1"
rowspan="1" class="confluenceTd"> Maximum Clock Skew </td><td colspan="1" rowspan="1"
class="confluenceTd"> Optional </td><td colspan="1" rowspan="1" class="confluenceTd">
Maximum allowable time difference between 
 the system clocks of the IDP and RP.<br clear="none">
-Default 5 seconds. </td></tr><tr><td colspan="1" rowspan="1" class="confluenceTd">
tokenReplayCache </td><td colspan="1" rowspan="1" class="confluenceTd"> Token
Replay Cache </td><td colspan="1" rowspan="1" class="confluenceTd"> Optional </td><td
colspan="1" rowspan="1" class="confluenceTd"> The <a shape="rect" class="external-link"
href="http://svn.apache.org/viewvc/cxf/fediz/trunk/plugins/core/src/main/java/org/apache/cxf/fediz/core/TokenReplayCache.java?view=markup">TokenReplayCache</a>
implementation to use to cache tokens. The default is an implementation based on EHCache.
</td></tr><tr><td colspan="1" rowspan="1" class="confluenceTd"> signingKey
</td><td colspan="1" rowspan="1" class="confluenceTd"> Key for Signature </td><td
colspan="1" rowspan="1" class="confluenceTd"> Optional </td><td colspan="1" rowspan="1"
class="confluenceTd"> If configured, the published (WS-Federation) <a shape="rect" href="fediz-metadata.html"
title="Fediz Metadata">Metadata document</a> is s
 igned by this key. Otherwise, not signed.</td></tr></tbody></table>
+Default 5 seconds. </td></tr><tr><td colspan="1" rowspan="1" class="confluenceTd">
tokenReplayCache </td><td colspan="1" rowspan="1" class="confluenceTd"> Token
Replay Cache </td><td colspan="1" rowspan="1" class="confluenceTd"> Optional </td><td
colspan="1" rowspan="1" class="confluenceTd"> The <a shape="rect" class="external-link"
href="http://svn.apache.org/viewvc/cxf/fediz/trunk/plugins/core/src/main/java/org/apache/cxf/fediz/core/TokenReplayCache.java?view=markup">TokenReplayCache</a>
implementation to use to cache tokens. The default is an implementation based on EHCache.
</td></tr><tr><td colspan="1" rowspan="1" class="confluenceTd"> signingKey
</td><td colspan="1" rowspan="1" class="confluenceTd"> Key for Signature </td><td
colspan="1" rowspan="1" class="confluenceTd"> Optional </td><td colspan="1" rowspan="1"
class="confluenceTd"> If configured, the published (WS-Federation) <a shape="rect" href="fediz-metadata.html"
title="Fediz Metadata">Metadata document</a> is s
 igned by this key. Otherwise, not signed.</td></tr><tr><td colspan="1"
rowspan="1" class="confluenceTd"> tokenDecryptionKey </td><td colspan="1" rowspan="1"
class="confluenceTd"> Decryption Key </td><td colspan="1" rowspan="1" class="confluenceTd">
Optional </td><td colspan="1" rowspan="1" class="confluenceTd"> A Keystore used
to decrypt an encrypted token. </td></tr></tbody></table>
 </div>
 
 



Mime
View raw message