PingGateway

PingFederateService

Holds information about a PingFederate server. Filters using the server reference a PingFederateService.

Usage

{
  "name": string,
  "type": "PingFederateService",
  "config": {
    "serviceUrl": configuration expression<url>,
    "endpointHandler": Handler reference,
    "jwkset": {
      "cacheTimeout": configuration expression<duration>,
      "cacheMissTimeout": configuration expression<duration>
    }
  }
}

Properties

"serviceUrl": configuration expression<url>, required

The PingFederate root service URL.

Example: https://pingfed.example.com:9031.

"endpointHandler": Handler reference, optional

The handler that makes requests to the service URL.

Make sure this handler can access PingFederate endpoints for the services it makes requests to.

Default: ForgeRockClientHandler as defined in the heap

"jwkset": object, optional

The configuration for retrieving the PingFederate JSON Web Key (JWK) set. PingGateway derives the JWK set endpoint by appending the path /pf/JWKS to the "serviceUrl".

The PingFederateService fetches only JWKs with a sig purpose to prevent selecting the wrong key when verifying a key signature. The PingFederate server must set sig on its JWK set signing keys.

"cacheTimeout": configuration expression<duration>, optional

Delay before reloading the JWK set cache to avoid doing so too often.

Default: 2 minutes

"cacheMissTimeout": configuration expression<duration>, optional

The delay before reloading the cache after a cache miss. A cache miss arises, for example, when the JWK key ID is unknown. This avoids hammering the endpoint when a specific key isn’t yet cached.

Default: 2 minutes

Example

The following example shows a PingFederateService using the default endpoint handler and cache settings:

{
    "name": "PingFederateService-1",
    "type": "PingFederateService",
    "config": {
        "serviceEndpoint": "https://pingfed.example.com:9031"
    }
}