An SSLContext for use on the server side of a connection.
| Name | Dynamic | Other provider points |
|---|---|---|
| org.wildfly.security.ssl-context | true | /subsystem=elytron/server-ssl-sni-context=* /subsystem=elytron/client-ssl-context=* |
| Attribute | Value |
|---|---|
| Type | INT |
| Nillable | false |
| Expressions Allowed | false |
| Storage | runtime |
| Access Type | read-only |
| Attribute | Value |
|---|---|
| Default Value | false |
| Type | BOOLEAN |
| Nillable | true |
| Expressions Allowed | true |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Attribute | Value |
|---|---|
| Default Value | DEFAULT |
| Type | STRING |
| Nillable | true |
| Expressions Allowed | true |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Attribute | Value |
|---|---|
| Type | STRING |
| Nillable | true |
| Expressions Allowed | true |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Attribute | Value |
|---|---|
| Capability reference | |
| Type | STRING |
| Nillable | true |
| Expressions Allowed | false |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | resource-services |
| Attribute | Value |
|---|---|
| Capability reference | |
| Type | STRING |
| Nillable | false |
| Expressions Allowed | false |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Attribute | Value |
|---|---|
| Default Value | -1 |
| Type | INT |
| Nillable | true |
| Expressions Allowed | true |
| Min | -1 |
| Max | 2,147,483,647 |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Attribute | Value |
|---|---|
| Default Value | false |
| Type | BOOLEAN |
| Nillable | true |
| Expressions Allowed | true |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Attribute | Value |
|---|---|
| Capability reference | |
| Type | STRING |
| Nillable | true |
| Expressions Allowed | false |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | resource-services |
| Attribute | Value |
|---|---|
| Capability reference | |
| Type | STRING |
| Nillable | true |
| Expressions Allowed | false |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | resource-services |
| Attribute | Value |
|---|---|
| Type | LIST |
| Nillable | true |
| Expressions Allowed | true |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Allowed Values | SSLv2 SSLv2Hello SSLv3 TLSv1 TLSv1.1 TLSv1.2 TLSv1.3 |
| Attribute | Value |
|---|---|
| Type | STRING |
| Nillable | true |
| Expressions Allowed | true |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Attribute | Value |
|---|---|
| Capability reference | |
| Type | STRING |
| Nillable | true |
| Expressions Allowed | false |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Attribute | Value |
|---|---|
| Capability reference | |
| Type | STRING |
| Nillable | true |
| Expressions Allowed | false |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | resource-services |
| Attribute | Value |
|---|---|
| Capability reference | |
| Type | STRING |
| Nillable | true |
| Expressions Allowed | false |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Attribute | Value |
|---|---|
| Default Value | -1 |
| Type | INT |
| Nillable | true |
| Expressions Allowed | true |
| Min | -1 |
| Max | 2,147,483,647 |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Attribute | Value |
|---|---|
| Capability reference | |
| Type | STRING |
| Nillable | true |
| Expressions Allowed | false |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Attribute | Value |
|---|---|
| Default Value | true |
| Type | BOOLEAN |
| Nillable | true |
| Expressions Allowed | true |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Attribute | Value |
|---|---|
| Default Value | false |
| Type | BOOLEAN |
| Nillable | true |
| Expressions Allowed | true |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Attribute | Value |
|---|---|
| Default Value | false |
| Type | BOOLEAN |
| Nillable | true |
| Expressions Allowed | true |
| Storage | configuration |
| Access Type | read-write |
| Restart Required | all-services |
| Request Parameter | Type | Required | Expressions Allowed | Default value | Description |
|---|---|---|---|---|---|
| authentication-optional | BOOLEAN | false | true | false | Rejecting of the client certificate by the security domain will not prevent the connection. Allows a fall through to use other authentication mechanisms (like form login) when the client certificate is rejected by security domain. Has an effect only when the security domain is set. |
| cipher-suite-filter | STRING | false | true | DEFAULT | The filter to apply to specify the enabled cipher suites for TLSv1.2 and below. |
| cipher-suite-names | STRING | false | true | The filter to apply to specify the enabled cipher suites for TLSv1.3. | |
| final-principal-transformer | STRING | false | false | A final principal transformer to apply for this mechanism realm. | |
| key-manager | STRING | true | false | Reference to the key manager to use within the SSLContext. | |
| maximum-session-cache-size | INT | false | true | -1 | The maximum number of SSL sessions in the cache. The default value -1 means use the JVM default value. Value zero means there is no limit. |
| need-client-auth | BOOLEAN | false | true | false | To require a client certificate on SSL handshake. Connection without trusted client certificate (see trust-manager) will be rejected. |
| post-realm-principal-transformer | STRING | false | false | A principal transformer to apply after the realm is selected. | |
| pre-realm-principal-transformer | STRING | false | false | A principal transformer to apply before the realm is selected. | |
| protocols | LIST | false | true | The enabled protocols. | |
| provider-name | STRING | false | true | The name of the provider to use. If not specified, all providers from providers will be passed to the SSLContext. | |
| providers | STRING | false | false | The name of the providers to obtain the Provider[] to use to load the SSLContext. | |
| realm-mapper | STRING | false | false | The realm mapper to be used for SSL authentication. | |
| security-domain | STRING | false | false | The security domain to use for authentication during SSL session establishment. | |
| session-timeout | INT | false | true | -1 | The timeout for SSL sessions, in seconds. The default value -1 means use the JVM default value. Value zero means there is no limit. |
| trust-manager | STRING | false | false | Reference to the trust manager to use within the SSLContext. | |
| use-cipher-suites-order | BOOLEAN | false | true | true | To honor local cipher suites preference. |
| want-client-auth | BOOLEAN | false | true | false | To request (but not to require) a client certificate on SSL handshake. If a security domain is referenced and supports X509 evidence, this will be set to true automatically. Ignored when need-client-auth is set. |
| wrap | BOOLEAN | false | true | false | Should the SSLEngine, SSLSocket, and SSLServerSocket instances returned be wrapped to protect against further modification. |