Before specifying additional properties, specify a value in the Token generator name and the Token generator class name fields.
This class must implement the com.ibm.wsspi.wssecurity.token.TokenGeneratorComponent interface.
When the token generator is not for a PKCS#7 token type, you must select None. When the token generator is for the PKCS#7 token type and you want to package CRL in the security token, select Dedicated signing information and specify the CRL for the collection certificate store.
| Binding name | Cell level, server level, or application level | Path |
|---|---|---|
| Default generator bindings | Cell level |
|
| Default generator bindings | Server level |
|
Using the collection certificate store, you can configure a related certificate revocation list by clicking Certificate revocation list under Additional properties.
| Property name | Default value | Explanation |
|---|---|---|
com.ibm.ws.wssecurity.config.token. BasicAuth.Nonce.cacheTimeout |
600 seconds | Specifies the timeout value, in seconds, for the nonce value that is cached on the server. |
com.ibm.ws.wssecurity.config.token. BasicAuth.Nonce.clockSkew |
0 seconds | Specifies the time, in seconds, before the nonce time stamp expires. |
com.ibm.ws.wssecurity.config.token. BasicAuth.Nonce.maxAge |
300 seconds | Specifies the clock skew value, in seconds, to consider when WebSphere Application Server checks the timeliness of the message. |
This option is displayed on the cell, server, and application levels. This option is valid only when the generated token type is a user name token.
This option is displayed on the cell, server, and application levels. This option is valid only when the generated token type is a user name token.
When you specify a custom value type for custom tokens, you can specify the local name and the URI of the quality name (QName) of the value type. For example, you might specify Custom for the local name and http://www.ibm.com/custom for the URI.
When you specify the token generator for the user name token or the X.509 certificate security token, you do not need to specify this option. If you want to specify another token, specify the URI of the QName of the value type.
WebSphere Application Server provides the following predefined value type URI for the LTPA token: http://www.ibm.com/websphere/appserver/tokentype/5.0.2