OAuth2Provider.xml revision 7ce0a42f86f49ae2e046a38efd4a0bfc6054c490
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ServicesConfiguration
PUBLIC "=//iPlanet//Service Management Services (SMS) 1.0 DTD//EN"
"jar://com/sun/identity/sm/sms.dtd">
<!--
/*
* The contents of this file are subject to the terms of the Common Development and
* Distribution License (the License). You may not use this file except in compliance with the
* License.
*
* You can obtain a copy of the License at legal/CDDLv1.0.txt. See the License for the
* specific language governing permission and limitations under the License.
*
* When distributing Covered Software, include this CDDL Header Notice in each file and include
* the License file at legal/CDDLv1.0.txt. If applicable, add the following below the CDDL
* Header, with the fields enclosed by brackets [] replaced by your own identifying
* information: "Portions Copyrighted [year] [name of copyright owner]".
*
* Copyright 2012-2014 ForgeRock AS.
*/
-->
<ServicesConfiguration>
<Service name="OAuth2Provider" version="1.0">
<Schema
serviceHierarchy="/DSAMEConfig/ForgerockOAuth2ProviderService"
i18nFileName="OAuth2Provider"
revisionNumber="1"
i18nKey="forgerock-oauth2-provider-description">
<Organization>
<AttributeSchema name="forgerock-oauth2-provider-authorization-code-lifetime"
type="single"
syntax="number_range" rangeStart="0" rangeEnd="2147483647"
validator="RequiredValueValidator"
i18nKey="a100">
<DefaultValues>
<Value>10</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-refresh-token-lifetime"
type="single"
syntax="number_range" rangeStart="0" rangeEnd="2147483647"
validator="RequiredValueValidator"
i18nKey="a101">
<DefaultValues>
<Value>600</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-access-token-lifetime"
type="single"
syntax="number_range" rangeStart="0" rangeEnd="2147483647"
validator="RequiredValueValidator"
i18nKey="a102">
<DefaultValues>
<Value>60</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-issue-refresh-token"
type="single"
syntax="boolean"
i18nKey="a103">
<BooleanValues>
<BooleanTrueValue i18nKey="i18nTrue">true</BooleanTrueValue>
<BooleanFalseValue i18nKey="i18nFalse">false</BooleanFalseValue>
</BooleanValues>
<DefaultValues>
<Value>true</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-issue-refresh-token-on-refreshing-token"
type="single"
syntax="boolean"
i18nKey="a103a">
<BooleanValues>
<BooleanTrueValue i18nKey="i18nTrue">true</BooleanTrueValue>
<BooleanFalseValue i18nKey="i18nFalse">false</BooleanFalseValue>
</BooleanValues>
<DefaultValues>
<Value>true</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-scope-implementation-class"
type="single"
syntax="string"
validator="RequiredValueValidator"
i18nKey="a104">
<DefaultValues>
<Value>org.forgerock.openam.oauth2.OpenAMScopeValidator</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="org-forgerock-oidc-profile-attribute-mappings"
type="list"
syntax="string"
i18nKey="a104a">
<DefaultValues>
<Value>name=cn</Value>
<Value>given_name=givenname</Value>
<Value>family_name=sn</Value>
<Value>locale=preferredlocale</Value>
<Value>zoneinfo=preferredtimezone</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="org-forgerock-oidc-email-attribute-mapping"
type="single"
syntax="string"
i18nKey="a104b">
<DefaultValues>
<Value>mail</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="org-forgerock-oidc-address-attribute-mapping"
type="single"
syntax="string"
i18nKey="a104c">
<DefaultValues>
<Value>postaladdress</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="org-forgerock-oidc-phone-attribute-mapping"
type="single"
syntax="string"
i18nKey="a104d">
<DefaultValues>
<Value>telephonenumber</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-response-type-map-class"
type="list"
syntax="string"
i18nKey="a105">
<DefaultValues>
<Value>token|org.forgerock.restlet.ext.oauth2.flow.responseTypes.TokenResponseType</Value>
<Value>code|org.forgerock.restlet.ext.oauth2.flow.responseTypes.CodeResponseType</Value>
<Value>id_token|org.forgerock.restlet.ext.oauth2.flow.responseTypes.IDTokenResponseType</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema
name="forgerock-oauth2-provider-authentication-attributes"
type="list"
syntax="string"
i18nKey="a106">
<DefaultValues>
<Value>uid</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-saved-consent-attribute"
type="single"
syntax="string"
i18nKey="a107">
<DefaultValues>
<Value></Value>
</DefaultValues>
</AttributeSchema>
<!--
<AttributeSchema
name="forgerock-oauth2-provider-supported-scopes"
type="list"
syntax="string"
i18nKey="a108">
<DefaultValues>
<Value>openid</Value>
</DefaultValues>
</AttributeSchema>
-->
<AttributeSchema
name="forgerock-oauth2-provider-jkws-uri"
type="single"
syntax="string"
i18nKey="a109">
<DefaultValues>
<Value></Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema
name="forgerock-oauth2-provider-subject-types-supported"
type="list"
syntax="string"
i18nKey="a110">
<DefaultValues>
<Value>public</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema
name="forgerock-oauth2-provider-id-token-signing-algorithms-supported"
type="list"
syntax="string"
i18nKey="a111">
<DefaultValues>
<Value>HS256</Value>
<Value>HS384</Value>
<Value>HS512</Value>
<Value>RS256</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema
name="forgerock-oauth2-provider-supported-claims"
type="list"
syntax="string"
i18nKey="a112">
<DefaultValues>
<Value>openid</Value>
<Value>profile</Value>
<Value>email</Value>
<Value>address</Value>
<Value>phone</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-jwt-token-lifetime"
type="single"
syntax="number_range" rangeStart="0" rangeEnd="2147483647"
validator="RequiredValueValidator"
i18nKey="a113">
<DefaultValues>
<Value>600</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-keypair-name"
type="single"
syntax="string"
validator="RequiredValueValidator"
i18nKey="a114">
<DefaultValues>
<Value>test</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-allow-open-dynamic-registration"
type="single"
syntax="boolean"
i18nKey="a115">
<BooleanValues>
<BooleanTrueValue i18nKey="i18nTrue">true</BooleanTrueValue>
<BooleanFalseValue i18nKey="i18nFalse">false</BooleanFalseValue>
</BooleanValues>
<DefaultValues>
<Value>false</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-generate-registration-access-tokens"
type="single"
syntax="boolean"
i18nKey="a116">
<BooleanValues>
<BooleanTrueValue i18nKey="i18nTrue">true</BooleanTrueValue>
<BooleanFalseValue i18nKey="i18nFalse">false</BooleanFalseValue>
</BooleanValues>
<DefaultValues>
<Value>true</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="MapValueValidator"
type="validator"
syntax="string">
<DefaultValues>
<Value>com.sun.identity.common.configuration.MapValueValidator</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-loa-mapping"
type="list"
syntax="string"
uitype="maplist"
validator="MapValueValidator"
i18nKey="a117">
<ChoiceValues>
<ChoiceValuesClassName
className="com.sun.identity.authentication.service.ConfiguredAuthServices"/>
</ChoiceValues>
</AttributeSchema>
<AttributeSchema
name="forgerock-oauth2-provider-default-acr"
type="single"
syntax="string"
i18nKey="a118">
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-amr-mappings"
type="list"
syntax="string"
uitype="maplist"
validator="MapValueValidator"
i18nKey="a119">
<ChoiceValues>
<ChoiceValuesClassName
className="com.sun.identity.authentication.service.AllConfiguredModuleInstances"/>
</ChoiceValues>
</AttributeSchema>
<AttributeSchema
name="forgerock-oauth2-provider-modified-attribute-name"
type="single"
syntax="string"
i18nKey="a120">
<DefaultValues>
<Value>modifyTimestamp</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema
name="forgerock-oauth2-provider-created-attribute-name"
type="single"
syntax="string"
i18nKey="a121">
<DefaultValues>
<Value>createTimestamp</Value>
</DefaultValues>
</AttributeSchema>
<SubSchema name="serverconfig" inheritance="multiple">
<AttributeSchema name="forgerock-oauth2-provider-authorization-code-lifetime"
type="single"
syntax="number_range" rangeStart="0" rangeEnd="2147483647"
validator="RequiredValueValidator"
i18nKey="a100">
<DefaultValues>
<Value>10</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-refresh-token-lifetime"
type="single"
syntax="number_range" rangeStart="0" rangeEnd="2147483647"
validator="RequiredValueValidator"
i18nKey="a101">
<DefaultValues>
<Value>600</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-access-token-lifetime"
type="single"
syntax="number_range" rangeStart="0" rangeEnd="2147483647"
validator="RequiredValueValidator"
i18nKey="a102">
<DefaultValues>
<Value>60</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-issue-refresh-token"
type="single"
syntax="boolean"
i18nKey="a103">
<BooleanValues>
<BooleanTrueValue i18nKey="i18nTrue">true</BooleanTrueValue>
<BooleanFalseValue i18nKey="i18nFalse">false</BooleanFalseValue>
</BooleanValues>
<DefaultValues>
<Value>true</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-issue-refresh-token-on-refreshing-token"
type="single"
syntax="boolean"
i18nKey="a103a">
<BooleanValues>
<BooleanTrueValue i18nKey="i18nTrue">true</BooleanTrueValue>
<BooleanFalseValue i18nKey="i18nFalse">false</BooleanFalseValue>
</BooleanValues>
<DefaultValues>
<Value>true</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-scope-implementation-class"
type="single"
syntax="string"
validator="RequiredValueValidator"
i18nKey="a104">
<DefaultValues>
<Value>org.forgerock.openam.oauth2.OpenAMScopeValidator</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="org-forgerock-oidc-profile-attribute-mappings"
type="list"
syntax="string"
i18nKey="a104a">
<DefaultValues>
<Value>name=cn</Value>
<Value>given_name=givenname</Value>
<Value>family_name=sn</Value>
<Value>locale=preferredlocale</Value>
<Value>zoneinfo=preferredtimezone</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="org-forgerock-oidc-email-attribute-mapping"
type="single"
syntax="string"
i18nKey="a104b">
<DefaultValues>
<Value>mail</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="org-forgerock-oidc-address-attribute-mapping"
type="single"
syntax="string"
i18nKey="a104c">
<DefaultValues>
<Value>postaladdress</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="org-forgerock-oidc-phone-attribute-mapping"
type="single"
syntax="string"
i18nKey="a104d">
<DefaultValues>
<Value>telephonenumber</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-response-type-map-class"
type="list"
syntax="string"
i18nKey="a105">
<DefaultValues>
<Value>token|org.forgerock.restlet.ext.oauth2.flow.responseTypes.TokenResponseType</Value>
<Value>code|org.forgerock.restlet.ext.oauth2.flow.responseTypes.CodeResponseType</Value>
<Value>id_token|org.forgerock.restlet.ext.oauth2.flow.responseTypes.IDTokenResponseType</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema
name="forgerock-oauth2-provider-authentication-attributes"
type="list"
syntax="string"
i18nKey="a106">
<DefaultValues>
<Value>uid</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-saved-consent-attribute"
type="single"
syntax="string"
i18nKey="a107">
<DefaultValues>
<Value></Value>
</DefaultValues>
</AttributeSchema>
<!--
<AttributeSchema
name="forgerock-oauth2-provider-supported-scopes"
type="list"
syntax="string"
i18nKey="a108">
<DefaultValues>
<Value>openid</Value>
</DefaultValues>
</AttributeSchema>
-->
<AttributeSchema
name="forgerock-oauth2-provider-jkws-uri"
type="single"
syntax="string"
i18nKey="a109">
<DefaultValues>
<Value></Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema
name="forgerock-oauth2-provider-subject-types-supported"
type="list"
syntax="string"
i18nKey="a110">
<DefaultValues>
<Value>public</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema
name="forgerock-oauth2-provider-id-token-signing-algorithms-supported"
type="list"
syntax="string"
i18nKey="a111">
<DefaultValues>
<Value>HS256</Value>
<Value>HS384</Value>
<Value>HS512</Value>
<Value>RS256</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema
name="forgerock-oauth2-provider-supported-claims"
type="list"
syntax="string"
i18nKey="a112">
<DefaultValues>
<Value>openid</Value>
<Value>profile</Value>
<Value>email</Value>
<Value>address</Value>
<Value>phone</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-jwt-token-lifetime"
type="single"
syntax="number_range" rangeStart="0" rangeEnd="2147483647"
validator="RequiredValueValidator"
i18nKey="a113">
<DefaultValues>
<Value>600</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-keypair-name"
type="single"
syntax="string"
validator="RequiredValueValidator"
i18nKey="a114">
<DefaultValues>
<Value>test</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-allow-open-dynamic-registration"
type="single"
syntax="boolean"
i18nKey="a115">
<BooleanValues>
<BooleanTrueValue i18nKey="i18nTrue">true</BooleanTrueValue>
<BooleanFalseValue i18nKey="i18nFalse">false</BooleanFalseValue>
</BooleanValues>
<DefaultValues>
<Value>false</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-generate-registration-access-tokens"
type="single"
syntax="boolean"
i18nKey="a116">
<BooleanValues>
<BooleanTrueValue i18nKey="i18nTrue">true</BooleanTrueValue>
<BooleanFalseValue i18nKey="i18nFalse">false</BooleanFalseValue>
</BooleanValues>
<DefaultValues>
<Value>true</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="MapValueValidator"
type="validator"
syntax="string">
<DefaultValues>
<Value>com.sun.identity.common.configuration.MapValueValidator</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-loa-mapping"
type="list"
syntax="string"
uitype="maplist"
validator="MapValueValidator"
i18nKey="a117">
<ChoiceValues>
<ChoiceValuesClassName
className="com.sun.identity.authentication.service.ConfiguredAuthServices"/>
</ChoiceValues>
</AttributeSchema>
<AttributeSchema
name="forgerock-oauth2-provider-default-acr"
type="single"
syntax="string"
i18nKey="a118">
<DefaultValues>
<Value></Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema name="forgerock-oauth2-provider-amr-mappings"
type="list"
syntax="string"
uitype="maplist"
validator="MapValueValidator"
i18nKey="a119">
<ChoiceValues>
<ChoiceValuesClassName
className="com.sun.identity.authentication.service.AllConfiguredModuleInstances"/>
</ChoiceValues>
</AttributeSchema>
<AttributeSchema
name="forgerock-oauth2-provider-modified-attribute-name"
type="single"
syntax="string"
i18nKey="a120">
<DefaultValues>
<Value>modifyTimestamp</Value>
</DefaultValues>
</AttributeSchema>
<AttributeSchema
name="forgerock-oauth2-provider-created-attribute-name"
type="single"
syntax="string"
i18nKey="a121">
<DefaultValues>
<Value>createTimestamp</Value>
</DefaultValues>
</AttributeSchema>
</SubSchema>
</Organization>
</Schema>
</Service>
</ServicesConfiguration>