API Server configuration properties that are common across all tenants are stored in nnlgateway.json located in the $TOMCAT_HOME/webapps/nnlgateway/WEB-INF/classes/ directory. The table below describes the properties in the nnlgateway.json configuration file.
All client_auth.* properties are related to mutual TLS authentication if it is enabled on the Authentication Server's host. If this is the case, assign true to client_auth.enabled and then configure the other client_auth.* properties. Usually client_auth.enabled is false because mutual TLS authentication is rarely used.
If you are using a development installation, you may want to update the include_in_log.* properties to true so you get more information in the API Server's diagnostic log, nnlgateway.log, to help you debug.
Property | Description |
|---|---|
client_auth.enabled | Optional. Whether mutual TLS authentication is enabled on the Authentication Server's host. One of:
|
client_auth.keystore_file | Optional. The keystore file path to use if mutual TLS authentication is enabled. |
client_auth.keystore_passphrase | Optional. The keystore’s passphrase. |
client_auth.keystore_type | Optional. The keystore type. One of:
|
configuration_type | Mandatory. By default, API Server and plugin configuration is stored in the database. The installer assigns db to this property. If you need backward compatibility with releases prior to 7.0.0, assign file to this variable after installation. Specifies that API Server and plugin configuration is stored in files. |
configuration_update_check_interval | Mandatory. Polling interval, in seconds, to check for configuration updates. The default is 10. |
default_tenant_id | Optional. The default tenant ID name. Used when the tenant_id parameter is not specified in the HTTP request. In other words, tenant id cannot be identified from the URL path. The default value is default. |
include_in_log.userName | Optional. Whether to include log messages in nnlgateway.log containing information related to userName. One of:
|
include_in_log.sessionData | Optional. Whether to include log messages containing information related to sessionData. One of:
|
include_in_log.message | Optional. Whether to include log messages containing information related to message. One of:
|
include_in_log.request_all | Optional. Whether to log all requests. One of:
|
include_in_log.response_all | Optional. Whether to log all responses. One of:
|
mfas_location | Mandatory. The URL where the Authentication Server is hosted. If the URL uses the HTTP protocol instead of the HTTPS protocol, the API Server ignores all client_auth.* and server_auth.* properties in nnlgateway.json. |
server_auth.enabled | Optional. To enable/disable TLS server authentication (TLS certificate validation) at the client side. One of:
|
server_auth.truststore_file | Optional. The truststore file path (used only when server.auth.enabled is true). If this property has no value, the API Server uses the default Java runtime environment truststore. |
server_auth.truststore_passphrase | Optional. The truststore password (used only when server_auth:enabled is true). The default value is empty. |
server_auth.truststore_type | Optional. The truststore type. One of:
|