...
Property | Type | Default | Function |
---|---|---|---|
idp.transientId.generator | Bean ID of a TransientIdGenerationStrategy | shibboleth.CryptoTransientIdGenerator | Identifies the strategy plugin for generating transient IDs |
idp.persistentId.generator | Bean ID of a PersistentIdGenerationStrategy | shibboleth.ComputedPersistentIdGenerator | Identifies the strategy plugin for generating persistent IDs |
idp.persistentId.dataSource 3.2 | Bean ID of a JDBC DataSource | Identifies a data source for storage-based strategy for persistent IDs | |
idp.persistentId.store | Bean ID of a PersistentIdStore | Identifies the data store plugin for storage-based strategy for persistent IDs | |
idp.persistentId.computed | Bean ID of a ComputedPersistentIdGenerationStrategy | shibboleth.ComputedPersistentIdGenerator | May be null, Identifies a strategy plugin to use to generate the first persistent identifier for each subject, used to migrate from the computed to stored strategies |
idp.persistentId.sourceAttribute | Comma-delim'd List | List of attributes to search for a value to uniquely identify the subject of a persistent identifier, it MUST be stable, long-lived, and non-reassignable | |
idp.persistentId.useUnfilteredAttributes 3.2 | Boolean | true | Whether or not the previous property has access to unreleased attributes |
idp.persistentId.salt | String | A secret salt for the hash when using computed persistent IDs | |
idp.persistentId.encodedSalt 3.3 | Base64-encoded String | An encoded form of the previous property | |
idp.persistentId.algorithm | String | SHA | The hash algorithm used when using computed persistent IDs |
idp.persistentId.encoding 3.3.2 | "BASE64" or "BASE32" | BASE64 | The final encoding applied to the hash generated when using computed persistent IDs (BASE32 is strongly recommended for new installs) |
idp.persistentId.exceptionMap 3.4 | Bean ID | shibboleth.ComputedIdExceptionMap | Advanced feature allowing revocation or regeneration of computed persistent IDs for specific subjects or services |
idp.nameid.saml2.legacyGenerator | Bean ID | DEPRECATED Identifies a default generator plugin to use as a last resort if no others succeed | |
idp.nameid.saml1.legacyGenerator | Bean ID | DEPRECATED Identifies a default generator plugin to use as a last resort if no others succeed | |
idp.nameid.saml2.default | URI | urn:oasis:names:tc:SAML:2.0:nameid-format:transient | The default Format to generate if nothing else is indicated |
idp.nameid.saml1.default | URI | urn:mace:shibboleth:1.0:nameIdentifier | The default Format to generate if nothing else is indicated |
...