Lock Configuration Properties#
| Property Name | Description | |
|---|---|---|
| allowedProducerIds | Producer ids the client is allowed to submit records for; "*" allows any producer | Details |
| auditPersistenceMode | Audit persistence mode | Details |
| baseDN | Entry Base distinguished name (DN) that identifies the starting point of a search | Details |
| baseEndpoint | Lock base endpoint URL | Details |
| cedarlingConfiguration | Cedarling configuration | Details |
| cleanServiceBatchChunkSize | Each clean up iteration fetches chunk of expired data per base dn and removes it from storage | Details |
| cleanServiceInterval | Time interval for the Clean Service in seconds | Details |
| clientDomainBindings | OAuth client to evidence-domain bindings | Details |
| clientId | Lock Client ID | Details |
| clientId | OAuth client id bound to the evidence domain | Details |
| clientPassword | Lock client password | Details |
| defaultEvidenceDomainId | Evidence domain id used when a submitting client has no explicit binding | Details |
| disableExternalLoggerConfiguration | Choose whether to disable external log4j configuration override | Details |
| disableJdkLogger | Choose whether to disable JDK loggers | Details |
| enabled | Enable TRACE evidence ingestion endpoints | Details |
| errorReasonEnabled | Boolean value specifying whether to return detailed reason of the error from AS. Default value is false | Details |
| evidenceDomainId | Evidence domain id the client is bound to | Details |
| externalLoggerConfiguration | The path to the external log4j2 logging configuration | Details |
| grpcConfiguration | gRPC server configuration | Details |
| grpcPort | Specify grpc port | Details |
| latenessThresholdSeconds | Seconds after signed_at a record is accepted before being flagged late | Details |
| loggingLayout | Logging layout used for Jans Authorization Server loggers | Details |
| loggingLevel | Specify the logging level of loggers | Details |
| maxArrayLength | Maximum accepted JSON array length in a TRACE assertion | Details |
| maxBulkRecords | Maximum number of assertions accepted in one POST /audit/trace/bulk request | Details |
| maxBulkRequestBytes | Maximum total body size, in bytes, buffered for one POST /audit/trace/bulk request; clamped to 16777216 regardless of this value | Details |
| maxJsonDepth | Maximum accepted JSON nesting depth of a TRACE assertion | Details |
| maxObjectMembers | Maximum accepted JSON object member count in a TRACE assertion | Details |
| maxRequestBytes | Maximum accepted TRACE request body size in bytes | Details |
| maxStringLength | Maximum accepted JSON string length (UTF-16 units) in a TRACE assertion | Details |
| messageConsumerType | PubSub consumer service | Details |
| metricReporterEnabled | Enable metric reporter | Details |
| metricReporterInterval | The interval for metric reporter in seconds | Details |
| metricReporterKeepDataDays | The days to keep metric reported data | Details |
| openIdIssuer | OpenID issuer URL | Details |
| pendingReceiptTimeoutSeconds | Seconds a PENDING receipt may stay unresolved before the repair timer settles it | Details |
| protectionMode | Protection mode for the Lock server (OAuth or Cedarling) | Details |
| receiptAllocationRetryLimit | Maximum retries when allocating a receipt-chain sequence number | Details |
| receiptRepairIntervalSeconds | Interval in seconds between receipt repair timer runs | Details |
| serverMode | gRPC server mode | Details |
| statEnabled | Active stat enabled | Details |
| statTimerIntervalInSeconds | Statistical data capture time interval | Details |
| tlsCertChainFilePath | TLS Cert Chain File Path | Details |
| tlsPrivateKeyFilePath | TLS Private Key File Path | Details |
| tokenChannels | List of token channel names | Details |
| traceConfiguration | TRACE evidence ingestion configuration | Details |
| useTls | Use TLS for gRPC communication | Details |
allowedProducerIds#
-
Description: Producer ids the client is allowed to submit records for; "*" allows any producer
-
Required: No
-
Default value: None
auditPersistenceMode#
-
Description: Audit persistence mode
-
Required: No
-
Default value: None
baseDN#
-
Description: Entry Base distinguished name (DN) that identifies the starting point of a search
-
Required: No
-
Default value: None
baseEndpoint#
-
Description: Lock base endpoint URL
-
Required: No
-
Default value: None
cedarlingConfiguration#
-
Description: Cedarling configuration
-
Required: No
-
Default value: None
cleanServiceBatchChunkSize#
-
Description: Each clean up iteration fetches chunk of expired data per base dn and removes it from storage
-
Required: No
-
Default value: None
cleanServiceInterval#
-
Description: Time interval for the Clean Service in seconds
-
Required: No
-
Default value: None
clientDomainBindings#
-
Description: OAuth client to evidence-domain bindings
-
Required: No
-
Default value: None
clientId#
-
Description: Lock Client ID
-
Required: No
-
Default value: None
clientId#
-
Description: OAuth client id bound to the evidence domain
-
Required: No
-
Default value: None
clientPassword#
-
Description: Lock client password
-
Required: No
-
Default value: None
defaultEvidenceDomainId#
-
Description: Evidence domain id used when a submitting client has no explicit binding
-
Required: No
-
Default value: None
disableExternalLoggerConfiguration#
-
Description: Choose whether to disable external log4j configuration override
-
Required: No
-
Default value: true
disableJdkLogger#
-
Description: Choose whether to disable JDK loggers
-
Required: No
-
Default value: true
enabled#
-
Description: Enable TRACE evidence ingestion endpoints
-
Required: No
-
Default value: true
errorReasonEnabled#
-
Description: Boolean value specifying whether to return detailed reason of the error from AS. Default value is false
-
Required: No
-
Default value: false
evidenceDomainId#
-
Description: Evidence domain id the client is bound to
-
Required: No
-
Default value: None
externalLoggerConfiguration#
-
Description: The path to the external log4j2 logging configuration
-
Required: No
-
Default value: None
grpcConfiguration#
-
Description: gRPC server configuration
-
Required: No
-
Default value: None
grpcPort#
-
Description: Specify grpc port
-
Required: No
-
Default value: 50051
latenessThresholdSeconds#
-
Description: Seconds after signed_at a record is accepted before being flagged late
-
Required: No
-
Default value: 300
loggingLayout#
-
Description: Logging layout used for Jans Authorization Server loggers
-
Required: No
-
Default value: None
loggingLevel#
-
Description: Specify the logging level of loggers
-
Required: No
-
Default value: None
maxArrayLength#
-
Description: Maximum accepted JSON array length in a TRACE assertion
-
Required: No
-
Default value: 256
maxBulkRecords#
-
Description: Maximum number of assertions accepted in one POST /audit/trace/bulk request
-
Required: No
-
Default value: 100
maxBulkRequestBytes#
-
Description: Maximum total body size, in bytes, buffered for one POST /audit/trace/bulk request; clamped to 16777216 regardless of this value
-
Required: No
-
Default value: 4194304
maxJsonDepth#
-
Description: Maximum accepted JSON nesting depth of a TRACE assertion
-
Required: No
-
Default value: 32
maxObjectMembers#
-
Description: Maximum accepted JSON object member count in a TRACE assertion
-
Required: No
-
Default value: 256
maxRequestBytes#
-
Description: Maximum accepted TRACE request body size in bytes
-
Required: No
-
Default value: 262144
maxStringLength#
-
Description: Maximum accepted JSON string length (UTF-16 units) in a TRACE assertion
-
Required: No
-
Default value: 8192
messageConsumerType#
-
Description: PubSub consumer service
-
Required: No
-
Default value: None
metricReporterEnabled#
-
Description: Enable metric reporter
-
Required: No
-
Default value: None
metricReporterInterval#
-
Description: The interval for metric reporter in seconds
-
Required: No
-
Default value: None
metricReporterKeepDataDays#
-
Description: The days to keep metric reported data
-
Required: No
-
Default value: None
openIdIssuer#
-
Description: OpenID issuer URL
-
Required: No
-
Default value: None
pendingReceiptTimeoutSeconds#
-
Description: Seconds a PENDING receipt may stay unresolved before the repair timer settles it
-
Required: No
-
Default value: 120
protectionMode#
-
Description: Protection mode for the Lock server (OAuth or Cedarling)
-
Required: No
-
Default value: None
receiptAllocationRetryLimit#
-
Description: Maximum retries when allocating a receipt-chain sequence number
-
Required: No
-
Default value: 8
receiptRepairIntervalSeconds#
-
Description: Interval in seconds between receipt repair timer runs
-
Required: No
-
Default value: 300
serverMode#
-
Description: gRPC server mode
-
Required: No
-
Default value: None
statEnabled#
-
Description: Active stat enabled
-
Required: No
-
Default value: None
statTimerIntervalInSeconds#
-
Description: Statistical data capture time interval
-
Required: No
-
Default value: None
tlsCertChainFilePath#
-
Description: TLS Cert Chain File Path
-
Required: No
-
Default value:
tlsPrivateKeyFilePath#
-
Description: TLS Private Key File Path
-
Required: No
-
Default value:
tokenChannels#
-
Description: List of token channel names
-
Required: No
-
Default value: jans_token
traceConfiguration#
-
Description: TRACE evidence ingestion configuration
-
Required: No
-
Default value: None
useTls#
-
Description: Use TLS for gRPC communication
-
Required: No
-
Default value: false