Available technical configuration parameters
To add configuration to your kubernetes deployment, click here. |
To add configuration to your RPM installation, click here. |
Parameter stream.security.http.headers.xapi.idprov was deleted.
|
Parameter stream.security.http.headers.xapi.key was deleted.
|
Parameter stream.security.http.headers.xapi.id was deleted.
|
Parameter stream.security.http.headers.xid was deleted.
|
Parameter stream.trustchain.ca.online.root.operational was deleted.
|
Parameter stream.trustchain.ca.online.root.non_operational was deleted.
|
Parameter stream.trustchain.ca.online.subordinate.operational was deleted.
|
Parameter stream.trustchain.ca.offline.root.non_operational was deleted.
|
Parameter stream.crl.manager.timeout was deleted.
|
Parameter stream.ocsp.manager.timeout was deleted.
|
Parameter stream.timestamping.manager.timeout was deleted.
|
Parameter stream.crl.queue.size was deleted.
|
Bootstrap Configuration
stream.bootstrap.administrator.name
stream.bootstrap.administrator.name = "administrator"
Default administrator account name
stream.bootstrap.administrator.display-name
stream.bootstrap.administrator.display-name = "Stream Administrator"
Default administrator account display name
This parameter replaces stream.bootstrap.administrator.display.name . Please modify your configuration accordingly
|
stream.bootstrap.administrator.password.path
stream.bootstrap.administrator.password.path = "var/run/adminPassword"
Relative path of the file where the initial admin password should be stored into
CRL Configuration
stream.crl.sync.interval
stream.crl.sync.interval = "15m"
Interval at which CRL synchronization occurs
stream.crl.cache.max-age.mode
stream.crl.cache.max-age.mode = "1s"
How to set max-age cache directive on crl fetch: one of 'disabled', 'nextrefresh' or a duration
Event Configuration
stream.event.ttl
stream.event.ttl = null
Time to live of the events. If not set, events never expire
stream.event.chainsign
stream.event.chainsign = true
Specify whether to chain and sign the Stream events to ensure they haven’t been tampered with
stream.event.seal.algorithm
stream.event.seal.algorithm = "HS512"
Algorithm to use to hash the signature of the events in Stream (other possible values are "HS384" and "HS256")
stream.event.ignore-unsealed-pending
stream.event.ignore-unsealed-pending = false
Do not throw an error if pending events are unsealed
stream.event.disable-stacktrace
stream.event.disable-stacktrace = false
Enable to remove stacktraces from Stream events
General
stream.security.trustmanager.enforce-serverauth
stream.security.trustmanager.enforce-serverauth = false
If set to true, enforces the use of the serverAuth EKU in the server authentication certificates (when Stream accesses a service through TLS)
This parameter replaces stream.security.trustmanager.enforce_serverauth . Please modify your configuration accordingly
|
stream.security.trustmanager.timeout
stream.security.trustmanager.timeout = "10s"
Timeout to check trust status of certificates
This parameter replaces stream.trust.manager.timeout . Please modify your configuration accordingly
|
stream.security.trustmanager.cache.expire-after-access.external
stream.security.trustmanager.cache.expire-after-access.external = "30d"
Time after which an entry in the CRL cache expires for external CAs
This parameter replaces stream.trust.manager.cache.external.expireafteraccess . Please modify your configuration accordingly
|
stream.security.trustmanager.cache.expire-after-access.managed
stream.security.trustmanager.cache.expire-after-access.managed = "5m"
Time after which an entry in the CRL cache expires for managed CAs
This parameter replaces stream.trust.manager.cache.managed.expireafteraccess . Please modify your configuration accordingly
|
stream.security.trustmanager.crl-info.interval
stream.security.trustmanager.crl-info.interval = "5m"
Interval at which CRL Info are synchronized in trust manager
stream.security.manager.timeout
stream.security.manager.timeout = "10s"
Duration after which the security manager times out when trying to authenticate a principal with its session
stream.security.principal.password.length
stream.security.principal.password.length = 42
Local accounts password length
This parameter replaces stream.account.secret.length . Please modify your configuration accordingly
|
stream.keystore.timeout
stream.keystore.timeout = "1m"
How long the authentication cache lasts
Timeout for operations using keystores (generating CSR, listing keys, etc ..)
stream.keystore.pkcs11.reload.delay
stream.keystore.pkcs11.reload.delay = "5s"
Delay when reloading pkcs11 keystores after an error
stream.keystore.healthcheck.interval
stream.keystore.healthcheck.interval = "5m"
Interval at which keystore status is checked
stream.keystore.required-for-readiness
stream.keystore.required-for-readiness = []
List of names of keystores that are required to consider the instance ready
stream.queue.parallelism
stream.queue.parallelism = 5
Number of parallel requests (enrollment, revocation, ocsp, timestamping…) on the default queue
This parameter replaces stream.queue.default.parallelism . Please modify your configuration accordingly
|
stream.queue.size
stream.queue.size = 100
Number of requests (enrollment, revocation, ocsp, timestamping, crl, krl) that can be queued on the default queue
This parameter replaces stream.queue.default.size,stream.crl.queue.size . Please modify your configuration accordingly
|
stream.metrics.intervals.short
stream.metrics.intervals.short = "30s"
Interval at which short lived metrics are computed
stream.metrics.intervals.long
stream.metrics.intervals.long = "5m"
Interval at which background metrics are computed
stream.ntp.client.timeout
stream.ntp.client.timeout = "1m"
Timeout for registering the NTP Clients in actors
HTTP Headers Configuration
KRL Configuration
OCSP Configuration
stream.ocsp.timeout
stream.ocsp.timeout = "1m"
Timeout for processing OCSP requests and starting OCSP actors
OpenID Configuration
stream.openid.state-separator
stream.openid.state-separator = "#"
Separator character of the OpenID state
This parameter replaces stream.security.identity.provider.openid.state.separator . Please modify your configuration accordingly
|
Search Configuration
stream.security.principal.search.page.default-size
stream.security.principal.search.page.default-size = 50
How many elements to retrieve in a security principals search query if no pageSize has been specified
This parameter replaces stream.security.principal.search.page.default_size . Please modify your configuration accordingly
|
stream.security.principal.search.page.max-size
stream.security.principal.search.page.max-size = null
How big can the pageSize parameter be in a security principals search query (Must be a positive integer)
This parameter replaces stream.security.principal.search.page.max_size . Please modify your configuration accordingly
|
stream.event.search.page.default-size
stream.event.search.page.default-size = 50
How many elements to retrieve in an event search query if no pageSize has been specified
This parameter replaces stream.event.search.page.default_size . Please modify your configuration accordingly
|
stream.event.search.page.max-size
stream.event.search.page.max-size = null
How big can the pageSize parameter be in an event search query (Must be a positive integer)
This parameter replaces stream.event.search.page.max_size . Please modify your configuration accordingly
|
stream.x509.certificate.search.page.default-size
stream.x509.certificate.search.page.default-size = 50
How many elements to retrieve in a X509 certificate search query if no pageSize has been specified
This parameter replaces stream.certificate.search.page.default_size . Please modify your configuration accordingly
|
stream.x509.certificate.search.page.max-size
stream.x509.certificate.search.page.max-size = null
How big can the pageSize parameter be in a X509 certificate search query (Must be a positive integer)
This parameter replaces stream.certificate.search.page.max_size . Please modify your configuration accordingly
|