Class PingFederateService

java.lang.Object
org.forgerock.openig.ping.PingFederateService

public class PingFederateService extends Object
The PingFederateService supports integration with a PingFederate server, providing the service URL and the URI of its JWK Set endpoint (used to validate PingFederate-issued access tokens). A JwkSetSecretStore backed by the PingFederate JWK Set is created at startup and exposed through getJwkSetSecretStore(). The endpointHandler should be configured to correctly access the PingFederate endpoints (e.g. providing client authentication where required).
 {
      "type": "PingFederateService",
      "config": {
         "serviceUrl"       : Config Expression<URI>  [REQUIRED - The PingFederate service URL.]
         "endpointHandler"  : Handler                 [OPTIONAL - The Handler to use to make requests on the
                                                                      service endpoints - defaults to the
                                                                      heap-defined ForgeRockClientHandler.]
         "jwkset"           : object                  [OPTIONAL - JWK Set retrieval configuration.]
             "cacheTimeout"     : expression<duration>    [OPTIONAL - cache timeout to avoid reloading the
                                                                      cache all the time - default is
                                                                      "2 minutes".]
             "cacheMissTimeout" : expression<duration>    [OPTIONAL - the cache time before reloading the
                                                                      cache in case of a cache miss (i.e.
                                                                      an unknown key id) - default is
                                                                      "2 minutes".]
      }
 }
 
 

The example configuration below illustrates a PingFederate service config:

 {
     "name" : "pingFederateService",
     "type" : "PingFederateService",
     "config" : {
       "serviceUrl" : "https://pingfed.example.com:9031",
       "endpointHandler" : "pingFedEndpointHandler",
       "jwkset" : {
         "cacheTimeout" : "5 minutes",
         "cacheMissTimeout" : "30 seconds"
       }
     }
 }
 
 
Notes:
  • The serviceUrl is the root service URL for the PingFederate server, from which the JWK Set endpoint URI is derived by appending the /pf/JWKS path.
  • The JwkSetSecretStore is resolved at startup from the PingFederate JWK Set endpoint (/pf/JWKS), failing the heap initialization if the endpoint cannot be reached.
  • JWK Set data is cached and reloaded by the underlying JwksStore: jwkset.cacheTimeout drives the periodic reload, while jwkset.cacheMissTimeout gates the single reload triggered by an unknown key id (rate-limiting to avoid endpoint hammering).
  • Verification keys fetched using purpose Purpose.VERIFY are constrained on JWK use 'sig', to prevent cross-JWK usage (where a valid but unintended JWK may be selected for a given use/purpose). Note that JWKs without a use attribute are also excluded - the PingFederate server is expected to emit use: sig on its JWK Set signing keys.
  • Method Details

    • getJwkSetSecretStore

      public JwkSetSecretStore getJwkSetSecretStore()
      Get the JwkSetSecretStore resolved at startup from the PingFederate JWK Set endpoint. The underlying JWK Set data is cached and reloaded by the secret store's JwksStore, handling key rotation.
      Returns:
      the JwkSetSecretStore sourced from the PingFederate JWK Set endpoint.