Fido2 Configuration Properties#
| Property Name | Description | |
|---|---|---|
| abandonedRequestExpiration | Expiration time in seconds for abandoned assertion ceremonies. Kept much shorter than authenticationHistoryExpiration because conditional-UI ceremonies start on nearly every login page load, making abandonment the highest-volume outcome | Details |
| abandonedRequestSweepInterval | Interval in seconds between sweeps for lapsed assertion ceremonies. Must stay below unfinishedRequestExpiration so a ceremony cannot lapse and be deleted between two sweeps | Details |
| allowedTopOrigins | Full origins (scheme, host and optional port) permitted to frame a cross-origin ceremony; empty denies every framed ceremony | Details |
| attestationMode | String value indicating whether MDS validation should be omitted during attestation | Details |
| attestationMode | Attestation mode for this relying party - disabled, monitor or enforced. Unset falls back to the global attestationMode. | Details |
| authenticationHistoryExpiration | Expiration time in seconds for approved authentication requests | Details |
| authenticatorCertsFolder | Authenticators certificates folder | Details |
| baseEndpoint | The base URL for Fido2 endpoints | Details |
| cleanServiceBatchChunkSize | Each clean up iteration fetches chunk of expired data per base dn and removes it from storage | Details |
| cleanServiceInterval | Time interval for the Clean Service in seconds | Details |
| disableExternalLoggerConfiguration | Choose whether to disable external log4j configuration override | Details |
| disableJdkLogger | Boolean value specifying whether to enable JDK Loggers | Details |
| disableMetadataService | Boolean value indicating whether the MDS download should be omitted | Details |
| enabledFidoAlgorithms | List of Requested Credential Types | Details |
| enterpriseAttestation | If authenticators have been enabled for use in a specific protected envt (enterprise authenticators) | Details |
| externalLoggerConfiguration | Path to external Fido2 logging configuration | Details |
| fido2DeviceInfoCollection | Boolean value specifying whether to collect device information in FIDO2 metrics | Details |
| fido2ErrorCategorization | Boolean value specifying whether to categorize errors in FIDO2 metrics | Details |
| fido2MetricsAggregationEnabled | Boolean value specifying whether FIDO2 metrics aggregation is enabled | Details |
| fido2MetricsEnabled | Boolean value specifying whether FIDO2 passkey metrics collection is enabled | Details |
| fido2MetricsRetentionDays | Number of days to keep FIDO2 passkey metrics data | Details |
| fido2PerformanceMetrics | Boolean value specifying whether to collect detailed performance metrics for FIDO2 operations | Details |
| hints | Hints to the RP - security-key, client-device, hybrid | Details |
| issuer | URL using the https scheme for Issuer identifier | Details |
| lockAuditClientId | OAuth2 client ID used to obtain a token (scope https://jans.io/oauth/lock/log.write) for posting Lock Server audit events | Details |
| lockAuditClientPassword | OAuth2 client secret (encrypted), paired with lockAuditClientId | Details |
| lockAuditEnabled | Boolean value indicating whether passkey registration and authentication events are delivered to the Lock Server as audit evidence | Details |
| lockAuditEndpoint | Base URL of the Lock Server audit endpoint (e.g. https://lock.example.com/audit); /log and /log/bulk are derived from it | Details |
| lockAuditFlushInterval | Interval in seconds between batched deliveries of buffered Lock Server audit events. Read once at server startup; changing it requires a restart to take effect | Details |
| loggingLayout | Logging layout used for Fido2 | Details |
| loggingLevel | Logging level for Fido2 logger | Details |
| mdsCertsFolder | MDS TOC root certificates folder | Details |
| mdsDownloadStartupRetries | Number of times the MDS TOC download is retried at server startup when the TOC blob is missing (a missing TOC prevents attestation validation) | Details |
| mdsDownloadStartupRetryInterval | Delay in seconds between MDS TOC download retries at server startup when the TOC blob is missing | Details |
| mdsTocsFolder | MDS TOC files folder | Details |
| metadataServers | String value to provide source of URLs with external metadata | Details |
| metricReporterEnabled | Boolean value specifying whether metric reporter is enabled | Details |
| metricReporterInterval | The interval for metric reporter in seconds | Details |
| metricReporterKeepDataDays | The days to keep report data | Details |
| personCustomObjectClassList | Custom object class list for dynamic person enrolment | Details |
| recordAbandonedAssertions | Boolean value indicating whether assertion ceremonies that lapse without being completed are relabelled as abandoned instead of being deleted unlabelled | Details |
| requestedParties | Authenticators metadata in json format | Details |
| serverMetadataFolder | Authenticators metadata in json format | Details |
| trustedProxyEnabled | Whether proxy headers may be trusted when recording the client IP in metrics. Unset preserves the legacy behaviour of trusting them unconditionally. False never reads them. True trusts them only from the source addresses listed in trustedProxyIpRanges. | Details |
| trustedProxyIpRanges | Reverse-proxy source addresses whose forwarded headers are trusted, in CIDR notation (for example ["10.0.0.0/8", "192.168.1.0/24"]). Only consulted when trustedProxyEnabled is true; an empty list trusts nothing. | Details |
| unfinishedRequestExpiration | Expiration time in seconds for pending enrollment/authentication requests | Details |
| useLocalCache | Boolean value to indicate if Local Cache is to be used | Details |
| userAutoEnrollment | Allow to enroll users on enrollment/authentication requests | Details |
abandonedRequestExpiration#
-
Description: Expiration time in seconds for abandoned assertion ceremonies. Kept much shorter than authenticationHistoryExpiration because conditional-UI ceremonies start on nearly every login page load, making abandonment the highest-volume outcome
-
Required: No
-
Default value: 86400
abandonedRequestSweepInterval#
-
Description: Interval in seconds between sweeps for lapsed assertion ceremonies. Must stay below unfinishedRequestExpiration so a ceremony cannot lapse and be deleted between two sweeps
-
Required: No
-
Default value: 30
allowedTopOrigins#
-
Description: Full origins (scheme, host and optional port) permitted to frame a cross-origin ceremony; empty denies every framed ceremony
-
Required: No
-
Default value: None
attestationMode#
-
Description: String value indicating whether MDS validation should be omitted during attestation
-
Required: No
-
Default value: monitor
attestationMode#
-
Description: Attestation mode for this relying party - disabled, monitor or enforced. Unset falls back to the global attestationMode.
-
Required: No
-
Default value: None
authenticationHistoryExpiration#
-
Description: Expiration time in seconds for approved authentication requests
-
Required: No
-
Default value: None
authenticatorCertsFolder#
-
Description: Authenticators certificates folder
-
Required: No
-
Default value: None
baseEndpoint#
-
Description: The base URL for Fido2 endpoints
-
Required: No
-
Default value: None
cleanServiceBatchChunkSize#
-
Description: Each clean up iteration fetches chunk of expired data per base dn and removes it from storage
-
Required: No
-
Default value: None
cleanServiceInterval#
-
Description: Time interval for the Clean Service in seconds
-
Required: No
-
Default value: None
disableExternalLoggerConfiguration#
-
Description: Choose whether to disable external log4j configuration override
-
Required: No
-
Default value: true
disableJdkLogger#
-
Description: Boolean value specifying whether to enable JDK Loggers
-
Required: No
-
Default value: None
disableMetadataService#
-
Description: Boolean value indicating whether the MDS download should be omitted
-
Required: No
-
Default value: false
enabledFidoAlgorithms#
-
Description: List of Requested Credential Types
-
Required: No
-
Default value: None
enterpriseAttestation#
-
Description: If authenticators have been enabled for use in a specific protected envt (enterprise authenticators)
-
Required: No
-
Default value: false
externalLoggerConfiguration#
-
Description: Path to external Fido2 logging configuration
-
Required: No
-
Default value: None
fido2DeviceInfoCollection#
-
Description: Boolean value specifying whether to collect device information in FIDO2 metrics
-
Required: No
-
Default value: true
fido2ErrorCategorization#
-
Description: Boolean value specifying whether to categorize errors in FIDO2 metrics
-
Required: No
-
Default value: true
fido2MetricsAggregationEnabled#
-
Description: Boolean value specifying whether FIDO2 metrics aggregation is enabled
-
Required: No
-
Default value: true
fido2MetricsEnabled#
-
Description: Boolean value specifying whether FIDO2 passkey metrics collection is enabled
-
Required: No
-
Default value: true
fido2MetricsRetentionDays#
-
Description: Number of days to keep FIDO2 passkey metrics data
-
Required: No
-
Default value: 90
fido2PerformanceMetrics#
-
Description: Boolean value specifying whether to collect detailed performance metrics for FIDO2 operations
-
Required: No
-
Default value: true
hints#
-
Description: Hints to the RP - security-key, client-device, hybrid
-
Required: No
-
Default value: None
issuer#
-
Description: URL using the https scheme for Issuer identifier
-
Required: No
-
Default value: None
lockAuditClientId#
-
Description: OAuth2 client ID used to obtain a token (scope https://jans.io/oauth/lock/log.write) for posting Lock Server audit events
-
Required: No
-
Default value: None
lockAuditClientPassword#
-
Description: OAuth2 client secret (encrypted), paired with lockAuditClientId
-
Required: No
-
Default value: None
lockAuditEnabled#
-
Description: Boolean value indicating whether passkey registration and authentication events are delivered to the Lock Server as audit evidence
-
Required: No
-
Default value: false
lockAuditEndpoint#
-
Description: Base URL of the Lock Server audit endpoint (e.g. https://lock.example.com/audit); /log and /log/bulk are derived from it
-
Required: No
-
Default value: None
lockAuditFlushInterval#
-
Description: Interval in seconds between batched deliveries of buffered Lock Server audit events. Read once at server startup; changing it requires a restart to take effect
-
Required: No
-
Default value: 20
loggingLayout#
-
Description: Logging layout used for Fido2
-
Required: No
-
Default value: None
loggingLevel#
-
Description: Logging level for Fido2 logger
-
Required: No
-
Default value: None
mdsCertsFolder#
-
Description: MDS TOC root certificates folder
-
Required: No
-
Default value: None
mdsDownloadStartupRetries#
-
Description: Number of times the MDS TOC download is retried at server startup when the TOC blob is missing (a missing TOC prevents attestation validation)
-
Required: No
-
Default value: 3
mdsDownloadStartupRetryInterval#
-
Description: Delay in seconds between MDS TOC download retries at server startup when the TOC blob is missing
-
Required: No
-
Default value: 30
mdsTocsFolder#
-
Description: MDS TOC files folder
-
Required: No
-
Default value: None
metadataServers#
-
Description: String value to provide source of URLs with external metadata
-
Required: No
-
Default value: None
metricReporterEnabled#
-
Description: Boolean value specifying whether metric reporter is enabled
-
Required: No
-
Default value: None
metricReporterInterval#
-
Description: The interval for metric reporter in seconds
-
Required: No
-
Default value: None
metricReporterKeepDataDays#
-
Description: The days to keep report data
-
Required: No
-
Default value: None
personCustomObjectClassList#
-
Description: Custom object class list for dynamic person enrolment
-
Required: No
-
Default value: None
recordAbandonedAssertions#
-
Description: Boolean value indicating whether assertion ceremonies that lapse without being completed are relabelled as abandoned instead of being deleted unlabelled
-
Required: No
-
Default value: true
requestedParties#
-
Description: Authenticators metadata in json format
-
Required: No
-
Default value: None
serverMetadataFolder#
-
Description: Authenticators metadata in json format
-
Required: No
-
Default value: None
trustedProxyEnabled#
-
Description: Whether proxy headers may be trusted when recording the client IP in metrics. Unset preserves the legacy behaviour of trusting them unconditionally. False never reads them. True trusts them only from the source addresses listed in trustedProxyIpRanges.
-
Required: No
-
Default value: None
trustedProxyIpRanges#
-
Description: Reverse-proxy source addresses whose forwarded headers are trusted, in CIDR notation (for example ["10.0.0.0/8", "192.168.1.0/24"]). Only consulted when trustedProxyEnabled is true; an empty list trusts nothing.
-
Required: No
-
Default value: None
unfinishedRequestExpiration#
-
Description: Expiration time in seconds for pending enrollment/authentication requests
-
Required: No
-
Default value: None
useLocalCache#
-
Description: Boolean value to indicate if Local Cache is to be used
-
Required: No
-
Default value: None
userAutoEnrollment#
-
Description: Allow to enroll users on enrollment/authentication requests
-
Required: No
-
Default value: None