Embedded Jetty configuration
|
In IDM 8.0, When serving SSL requests, Jetty 12 checks that the incoming host header matches the server certificate’s subject and returns a Learn more in Jetty 12 support. |
PingIDM includes an embedded Jetty web server. The Jetty web server configuration is included in IDM’s configuration service, allowing for Jetty properties to be modified at runtime. The configuration includes:
-
A
webserver.jsonthat contains the global Jetty settings -
A
webserver.listener-*.jsonthat configures a Jetty connector to listen on a specific portAt least one webserver.listener-*.jsonmust be defined and enabled for Jetty to start.Learn more about the configuration properties for
webserver.jsonandwebserver.listener-*.jsonin Jetty configuration properties.
Jetty key store and trust store
Jetty depends on IDM to supply the mainKeyStore and mainTrustStore configured in secrets.json. If the mainTrustStore is not defined, the mainKeyStore is used as Jetty’s trust store.
Understanding Jetty configuration and Apache Felix
IDM runs in the Apache Felix framework, which allows the Jetty configuration to be specified and managed through OSGI components. If there is a change to the Jetty configuration in webserver.json, Apache Felix rebuilds the Jetty instance.
Learn more about OSGI and Apache Felix in the Architectural overview.
Changes to webserver.listener-*.json files don’t cause Jetty to restart. Only the Jetty connector configured by the changed file is restarted or removed if the file is deleted or disabled.
|