Package org.forgerock.openig.ping
Class PingFederateService
java.lang.Object
org.forgerock.openig.ping.PingFederateService
The
PingFederateService supports integration with a PingFederate server, providing the service URL and the
URI of its JWK Set endpoint (used to validate PingFederate-issued access tokens). A JwkSetSecretStore backed
by the PingFederate JWK Set is created at startup and exposed through getJwkSetSecretStore(). The
endpointHandler should be configured to correctly access the PingFederate endpoints (e.g. providing
client authentication where required).
{
"type": "PingFederateService",
"config": {
"serviceUrl" : Config Expression<URI> [REQUIRED - The PingFederate service URL.]
"endpointHandler" : Handler [OPTIONAL - The Handler to use to make requests on the
service endpoints - defaults to the
heap-defined ForgeRockClientHandler.]
"jwkset" : object [OPTIONAL - JWK Set retrieval configuration.]
"cacheTimeout" : expression<duration> [OPTIONAL - cache timeout to avoid reloading the
cache all the time - default is
"2 minutes".]
"cacheMissTimeout" : expression<duration> [OPTIONAL - the cache time before reloading the
cache in case of a cache miss (i.e.
an unknown key id) - default is
"2 minutes".]
}
}
The example configuration below illustrates a PingFederate service config:
{
"name" : "pingFederateService",
"type" : "PingFederateService",
"config" : {
"serviceUrl" : "https://pingfed.example.com:9031",
"endpointHandler" : "pingFedEndpointHandler",
"jwkset" : {
"cacheTimeout" : "5 minutes",
"cacheMissTimeout" : "30 seconds"
}
}
}
Notes:
-
The
serviceUrlis the root service URL for the PingFederate server, from which the JWK Set endpoint URI is derived by appending the/pf/JWKSpath. -
The
JwkSetSecretStoreis resolved at startup from the PingFederate JWK Set endpoint (/pf/JWKS), failing the heap initialization if the endpoint cannot be reached. -
JWK Set data is cached and reloaded by the underlying
JwksStore:jwkset.cacheTimeoutdrives the periodic reload, whilejwkset.cacheMissTimeoutgates the single reload triggered by an unknown key id (rate-limiting to avoid endpoint hammering). -
Verification keys fetched using purpose
Purpose.VERIFYare constrained on JWK use 'sig', to prevent cross-JWK usage (where a valid but unintended JWK may be selected for a given use/purpose). Note that JWKs without auseattribute are also excluded - the PingFederate server is expected to emituse: sigon its JWK Set signing keys.
-
Nested Class Summary
Nested ClassesModifier and TypeClassDescriptionstatic classCreates and initialises aPingFederateServicein a heap environment. -
Method Summary
Modifier and TypeMethodDescriptionGet theJwkSetSecretStoreresolved at startup from the PingFederate JWK Set endpoint.
-
Method Details
-
getJwkSetSecretStore
Get theJwkSetSecretStoreresolved at startup from the PingFederate JWK Set endpoint. The underlying JWK Set data is cached and reloaded by the secret store'sJwksStore, handling key rotation.- Returns:
- the
JwkSetSecretStoresourced from the PingFederate JWK Set endpoint.
-