Class: Saml::Kit::Configuration

Inherits:
Object
  • Object
show all
Defined in:
lib/saml/kit/configuration.rb

Overview

This class represents the main configuration that is use for generating SAML documents.

Saml::Kit::Configuration.new do |config|
config.issuer = "com:saml:kit"
config.signature_method = :SHA256
config.digest_method = :SHA256
config.registry = Saml::Kit::DefaultRegistry.new
config.session_timeout = 30.minutes
config.logger = Rails.logger
end

To specify global configuration it is best to do this in an initialize 
that runs at the start of the program.

Saml::Kit.configure do |configuration|
configuration.issuer = "https://www.example.com/saml/metadata"
configuration.generate_key_pair_for(use: :signing)
configuration.add_key_pair(ENV["X509_CERTIFICATE"], ENV["PRIVATE_KEY"], password: ENV['PRIVATE_KEY_PASSWORD'], use: :encryption)
end

Instance Attribute Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize {|_self| ... } ⇒ Configuration

:yields configuration

Yields:

  • (_self)

Yield Parameters:



36
37
38
39
40
41
42
43
44
# File 'lib/saml/kit/configuration.rb', line 36

def initialize # :yields configuration
  @signature_method = :SHA256
  @digest_method = :SHA256
  @registry = DefaultRegistry.new
  @session_timeout = 3.hours
  @logger = Logger.new(STDOUT)
  @key_pairs = []
  yield self if block_given?
end

Instance Attribute Details

#digest_method ⇒ Object

The digest method to use when generating signatures (See SAML::Kit::Builders::XmlSignature::DIGEST_METHODS)



28
29
30
# File 'lib/saml/kit/configuration.rb', line 28

def digest_method
  @digest_method
end

#issuer ⇒ Object

The issuer or entity_id to use.



24
25
26
# File 'lib/saml/kit/configuration.rb', line 24

def issuer
  @issuer
end

#logger ⇒ Object

The logger to write log messages to.



34
35
36
# File 'lib/saml/kit/configuration.rb', line 34

def logger
  @logger
end

#registry ⇒ Object

The metadata registry to use for searching for metadata associated with an issuer.



30
31
32
# File 'lib/saml/kit/configuration.rb', line 30

def registry
  @registry
end

#session_timeout ⇒ Object

The session timeout to use when generating an Assertion.



32
33
34
# File 'lib/saml/kit/configuration.rb', line 32

def session_timeout
  @session_timeout
end

#signature_method ⇒ Object

The signature method to use when generating signatures (See SAML::Kit::Builders::XmlSignature::SIGNATURE_METHODS)



26
27
28
# File 'lib/saml/kit/configuration.rb', line 26

def signature_method
  @signature_method
end

Instance Method Details

#add_key_pair(certificate, private_key, password: '', use: :signing) ⇒ Object

Add a key pair that can be used for either signing or encryption.

Parameters:

  • certificate (String) —

    the x509 certificate with public key.

  • private_key (String) —

    the plain text private key.

  • password (String) (defaults to: '') —

    the password to decrypt the private key.

  • use (Symbol) (defaults to: :signing) —

    the type of key pair, :signing or :encryption



52
53
54
# File 'lib/saml/kit/configuration.rb', line 52

def add_key_pair(certificate, private_key, password: '', use: :signing)
  @key_pairs.push(KeyPair.new(certificate, private_key, password, use.to_sym))
end

#certificates(use: nil) ⇒ Object

Return each certificate for a specific use.

Parameters:

  • use (Symbol) (defaults to: nil) —

    the type of key pair to return nil, :signing or :encryption



75
76
77
# File 'lib/saml/kit/configuration.rb', line 75

def certificates(use: nil)
  key_pairs(use: use).flat_map(&:certificate)
end

#encryption_certificate ⇒ Object

Deprecated.

Use #certificates instead of this method.



87
88
89
90
# File 'lib/saml/kit/configuration.rb', line 87

def encryption_certificate
  Saml::Kit.deprecate("encryption_certificate is deprecated. Use certificates(use: :encryption) instead")
  certificates(use: :encryption).last
end

#encryption_private_key ⇒ Object

Deprecated.

Use #private_keys instead of this method.



99
100
101
102
# File 'lib/saml/kit/configuration.rb', line 99

def encryption_private_key
  Saml::Kit.deprecate("encryption_private_key is deprecated. Use private_keys(use: :encryption) instead")
  private_keys(use: :encryption).last
end

#generate_key_pair_for(use:, password: SecureRandom.uuid) ⇒ Object

Generates a unique key pair that can be used for signing or encryption.

Parameters:

  • use (Symbol) —

    the type of key pair, :signing or :encryption

  • password (String) (defaults to: SecureRandom.uuid) —

    the private key password to use.



60
61
62
63
# File 'lib/saml/kit/configuration.rb', line 60

def generate_key_pair_for(use:, password: SecureRandom.uuid)
  certificate, private_key = SelfSignedCertificate.new(password).create
  add_key_pair(certificate, private_key, password: password, use: use)
end

#key_pairs(use: nil) ⇒ Object

Return each key pair for a specific use.

Parameters:

  • use (Symbol) (defaults to: nil) —

    the type of key pair to return nil, :signing or :encryption



68
69
70
# File 'lib/saml/kit/configuration.rb', line 68

def key_pairs(use: nil)
  use.present? ? @key_pairs.find_all { |x| x.for?(use) } : @key_pairs
end

#private_keys(use: :signing) ⇒ Object

Return each private for a specific use.

Parameters:

  • use (Symbol) (defaults to: :signing) —

    the type of key pair to return nil, :signing or :encryption



82
83
84
# File 'lib/saml/kit/configuration.rb', line 82

def private_keys(use: :signing)
  key_pairs(use: use).flat_map(&:private_key)
end

#sign? ⇒ Boolean

Returns true if there is at least one signing certificate registered.

Returns:

  • (Boolean)


105
106
107
# File 'lib/saml/kit/configuration.rb', line 105

def sign?
  certificates(use: :signing).any?
end

#signing_private_key ⇒ Object

Deprecated.

Use #private_keys instead of this method.



93
94
95
96
# File 'lib/saml/kit/configuration.rb', line 93

def signing_private_key
  Saml::Kit.deprecate("signing_private_key is deprecated. Use private_keys(use: :signing) instead")
  private_keys(use: :signing).last
end