Configuration Security - Vault

You can also store sensitive settings inside Vault. Vault can store your existing secrets, or it can dynamically generate new secrets to control access to third-party resources or provide time-limited credentials for your infrastructure. To learn more about Vault and its installation process, please visit the project website.

Once vault is accessible and configured inside CAS, support is provided via the following dependency:

1
2
3
4
5
<dependency>
    <groupId>org.apereo.cas</groupId>
    <artifactId>cas-server-support-configuration-cloud-vault</artifactId>
    <version>${cas.version}</version>
</dependency>
1
implementation "org.apereo.cas:cas-server-support-configuration-cloud-vault:${project.'cas.version'}"
1
2
3
4
5
6
7
8
9
dependencyManagement {
    imports {
        mavenBom "org.apereo.cas:cas-server-support-bom:${project.'cas.version'}"
    }
}

dependencies {
    implementation "org.apereo.cas:cas-server-support-configuration-cloud-vault"
}
1
2
3
4
5
6
7
8
9
10
dependencies {
    /*
        The following platform references are included automatically and are listed for reference only.

        implementation enforcedPlatform("org.apereo.cas:cas-server-support-bom:${project.'cas.version'}")
        implementation platform(org.springframework.boot.gradle.plugin.SpringBootPlugin.BOM_COORDINATES)
        
    */
    implementation "org.apereo.cas:cas-server-support-configuration-cloud-vault"
}

The following settings and properties are available from the CAS configuration catalog:

spring.cloud.vault.app-id.app-id-pathMount path of the AppId authentication backend.
app-id
Third party

Mount path of the AppId authentication backend.

Type
String
Default
app-id
Defined by
VaultProperties$AppIdProperties
spring.cloud.vault.app-id.network-interfaceNetwork interface hint for the "MAC_ADDRESS" UserId mechanism.
no default
Third party

Network interface hint for the "MAC_ADDRESS" UserId mechanism.

Type
String
Default
none
Defined by
VaultProperties$AppIdProperties
spring.cloud.vault.app-id.user-idUserId mechanism.
MAC_ADDRESS
Third party

UserId mechanism. Can be either "MAC_ADDRESS", "IP_ADDRESS", a string or a class name.

Type
String
Default
MAC_ADDRESS
Defined by
VaultProperties$AppIdProperties
spring.cloud.vault.app-role.app-role-pathMount path of the AppRole authentication backend.
approle
Third party

Mount path of the AppRole authentication backend.

Type
String
Default
approle
Defined by
VaultProperties$AppRoleProperties
spring.cloud.vault.app-role.roleName of the role, optional, used for pull-mode.
no default
Third party

Name of the role, optional, used for pull-mode.

Type
String
Default
none
Defined by
VaultProperties$AppRoleProperties
spring.cloud.vault.app-role.role-idThe RoleId.
no default
Third party

The RoleId.

Type
String
Default
none
Defined by
VaultProperties$AppRoleProperties
spring.cloud.vault.app-role.secret-idThe SecretId.
no default
Third party

The SecretId.

Type
String
Default
none
Defined by
VaultProperties$AppRoleProperties
spring.cloud.vault.application-nameApplication name for AppId authentication.
application
Third party

Application name for AppId authentication.

Type
String
Default
application
Defined by
VaultProperties
spring.cloud.vault.authentication
token
Third party
Type
VaultProperties.AuthenticationMethod
Default
token
Defined by
VaultProperties
spring.cloud.vault.aws-ec2.aws-ec2-pathMount path of the AWS-EC2 authentication backend.
aws-ec2
Third party

Mount path of the AWS-EC2 authentication backend.

Type
String
Default
aws-ec2
Defined by
VaultProperties$AwsEc2Properties
spring.cloud.vault.aws-ec2.identity-documentURL of the AWS-EC2 PKCS7 identity document.
http://169.254.169.254/latest/dynamic/instance-identity/pkcs7
Third party

URL of the AWS-EC2 PKCS7 identity document.

Type
URI
Default
http://169.254.169.254/latest/dynamic/instance-identity/pkcs7
Defined by
VaultProperties$AwsEc2Properties
spring.cloud.vault.aws-ec2.nonceNonce used for AWS-EC2 authentication.
no default
Third party

Nonce used for AWS-EC2 authentication. An empty nonce defaults to nonce generation.

Type
String
Default
none
Defined by
VaultProperties$AwsEc2Properties
spring.cloud.vault.aws-ec2.roleName of the role, optional.
no default
Third party

Name of the role, optional.

Type
String
Default
none
Defined by
VaultProperties$AwsEc2Properties
spring.cloud.vault.aws-iam.aws-pathMount path of the AWS authentication backend.
aws
Third party

Mount path of the AWS authentication backend.

Type
String
Default
aws
Defined by
VaultProperties$AwsIamProperties
spring.cloud.vault.aws-iam.endpoint-uriSTS server URI.
no default
Third party

STS server URI. @since 2.2

Type
URI
Default
none
Defined by
VaultProperties$AwsIamProperties
spring.cloud.vault.aws-iam.regionName of the region, optional.
no default
Third party

Name of the region, optional. Inferred by AWS defaults if not set. @since 4.0.1

Type
String
Default
none
Defined by
VaultProperties$AwsIamProperties
spring.cloud.vault.aws-iam.roleName of the role, optional.
no default
Third party

Name of the role, optional. Defaults to the friendly IAM name if not set.

Type
String
Default
none
Defined by
VaultProperties$AwsIamProperties
spring.cloud.vault.aws-iam.server-nameName of the server used to set X-Vault-AWS-IAM-Server-ID header in the headers of login requests.
no default
Third party

Name of the server used to set X-Vault-AWS-IAM-Server-ID header in the headers of login requests.

Type
String
Default
none
Defined by
VaultProperties$AwsIamProperties
spring.cloud.vault.azure-msi.azure-pathMount path of the Azure MSI authentication backend.
azure
Third party

Mount path of the Azure MSI authentication backend.

Type
String
Default
azure
Defined by
VaultProperties$AzureMsiProperties
spring.cloud.vault.azure-msi.identity-token-serviceIdentity token service URI.
no default
Third party

Identity token service URI. @since 3.0

Type
URI
Default
none
Defined by
VaultProperties$AzureMsiProperties
spring.cloud.vault.azure-msi.metadata-serviceInstance metadata service URI.
no default
Third party

Instance metadata service URI. @since 3.0

Type
URI
Default
none
Defined by
VaultProperties$AzureMsiProperties
spring.cloud.vault.azure-msi.roleName of the role.
no default
Third party

Name of the role.

Type
String
Default
none
Defined by
VaultProperties$AzureMsiProperties
spring.cloud.vault.config.lifecycle.enabledEnable lifecycle management.
true
Third party

Enable lifecycle management.

Type
Boolean
Default
true
Defined by
VaultProperties$ConfigLifecycle
spring.cloud.vault.config.lifecycle.expiry-thresholdThe expiry threshold.
no default
Third party

The expiry threshold. Lease is renewed the given Duration before it expires. @since 2.2

Type
Duration
Default
none
Defined by
VaultProperties$ConfigLifecycle
spring.cloud.vault.config.lifecycle.lease-endpointsSet the LeaseEndpoints to delegate renewal/revocation calls to.
no default
Third party

Set the LeaseEndpoints to delegate renewal/revocation calls to. LeaseEndpoints encapsulates differences between Vault versions that affect the location of renewal/revocation endpoints. Can be LeaseEndpoints#SysLeases for version 0.8 or above of Vault or LeaseEndpoints#Legacy for older versions (the default). @since 2.2

Type
LeaseEndpoints
Default
none
Defined by
VaultProperties$ConfigLifecycle
spring.cloud.vault.config.lifecycle.lease-strategySets the LeaseStrategy to be used with org.springframework.vault.core.lease.SecretLeaseContainer#setLeaseStrategy(LeaseStrategy) to retain or drop tokens on renewal errors.
no default
Third party

Sets the LeaseStrategy to be used with org.springframework.vault.core.lease.SecretLeaseContainer#setLeaseStrategy(LeaseStrategy) to retain or drop tokens on renewal errors. @since 4.1

Type
VaultProperties.PredefinedLeaseStrategy
Default
none
Defined by
VaultProperties$ConfigLifecycle
spring.cloud.vault.config.lifecycle.min-renewalThe time period that is at least required before renewing a lease.
no default
Third party

The time period that is at least required before renewing a lease. @since 2.2

Type
Duration
Default
none
Defined by
VaultProperties$ConfigLifecycle
spring.cloud.vault.config.orderUsed to set a org.springframework.core.env.PropertySource priority.
0
Third partyDeprecated

Used to set a org.springframework.core.env.PropertySource priority. This is useful to use Vault as an override on other property sources. @see org.springframework.core.PriorityOrdered

Type
Integer
Default
0
Defined by
VaultProperties$Config
Deprecation
WARNING, no replacement
spring.cloud.vault.connection-timeoutConnection timeout.
5000
Third party

Connection timeout.

Type
Integer
Default
5000
Defined by
VaultProperties
spring.cloud.vault.discovery.enabledFlag to indicate that Vault server discovery is enabled (vault server URL will be looked up via discovery).
false
Third party

Flag to indicate that Vault server discovery is enabled (vault server URL will be looked up via discovery).

Type
Boolean
Default
false
Defined by
VaultProperties$Discovery
spring.cloud.vault.discovery.service-idService id to locate Vault.
vault
Third party

Service id to locate Vault.

Type
String
Default
vault
Defined by
VaultProperties$Discovery
spring.cloud.vault.enabledEnable Vault config server.
true
Third party

Enable Vault config server.

Type
Boolean
Default
true
Defined by
VaultProperties
spring.cloud.vault.fail-fastFail fast if data cannot be obtained from Vault.
false
Third party

Fail fast if data cannot be obtained from Vault.

Type
Boolean
Default
false
Defined by
VaultProperties
spring.cloud.vault.gcp-gce.gcp-pathMount path of the Kubernetes authentication backend.
gcp
Third party

Mount path of the Kubernetes authentication backend.

Type
String
Default
gcp
Defined by
VaultProperties$GcpGceProperties
spring.cloud.vault.gcp-gce.roleName of the role against which the login is being attempted.
no default
Third party

Name of the role against which the login is being attempted.

Type
String
Default
none
Defined by
VaultProperties$GcpGceProperties
spring.cloud.vault.gcp-gce.service-accountOptional service account id.
no default
Third party

Optional service account id. Using the default id if left unconfigured.

Type
String
Default
none
Defined by
VaultProperties$GcpGceProperties
spring.cloud.vault.gcp-iam.credentials.encoded-keyThe base64 encoded contents of an OAuth2 account private key in JSON format.
no default
Third party

The base64 encoded contents of an OAuth2 account private key in JSON format.

Type
String
Default
none
Defined by
VaultProperties$GcpCredentials
spring.cloud.vault.gcp-iam.credentials.locationLocation of the OAuth2 credentials private key.
no default
Third party

Location of the OAuth2 credentials private key.

Since this is a Resource, the private key can be in a multitude of locations, such as a local file system, classpath, URL, etc.

Type
Resource
Default
none
Defined by
VaultProperties$GcpCredentials
spring.cloud.vault.gcp-iam.gcp-pathMount path of the Kubernetes authentication backend.
gcp
Third party

Mount path of the Kubernetes authentication backend.

Type
String
Default
gcp
Defined by
VaultProperties$GcpIamProperties
spring.cloud.vault.gcp-iam.jwt-validityValidity of the JWT token.
15m
Third party

Validity of the JWT token.

Type
Duration
Default
15m
Defined by
VaultProperties$GcpIamProperties
spring.cloud.vault.gcp-iam.project-idOverrides the GCP project Id.
no default
Third party

Overrides the GCP project Id.

Type
String
Default
none
Defined by
VaultProperties$GcpIamProperties
spring.cloud.vault.gcp-iam.roleName of the role against which the login is being attempted.
no default
Third party

Name of the role against which the login is being attempted.

Type
String
Default
none
Defined by
VaultProperties$GcpIamProperties
spring.cloud.vault.gcp-iam.service-account-idOverrides the GCP service account Id.
no default
Third party

Overrides the GCP service account Id.

Type
String
Default
none
Defined by
VaultProperties$GcpIamProperties
spring.cloud.vault.github.github-pathMount path of the GitHub authentication backend.
github
Third party

Mount path of the GitHub authentication backend.

Type
String
Default
github
Defined by
VaultProperties$GithubProperties
spring.cloud.vault.github.tokenGitHub personal token.
no default
Third party

GitHub personal token.

Type
String
Default
none
Defined by
VaultProperties$GithubProperties
spring.cloud.vault.hostVault server host.
localhost
Third party

Vault server host.

Type
String
Default
localhost
Defined by
VaultProperties
spring.cloud.vault.kubernetes.kubernetes-pathMount path of the Kubernetes authentication backend.
kubernetes
Third party

Mount path of the Kubernetes authentication backend.

Type
String
Default
kubernetes
Defined by
VaultProperties$KubernetesProperties
spring.cloud.vault.kubernetes.roleName of the role against which the login is being attempted.
no default
Third party

Name of the role against which the login is being attempted.

Type
String
Default
none
Defined by
VaultProperties$KubernetesProperties
spring.cloud.vault.kubernetes.service-account-token-filePath to the service account token file.
/var/run/secrets/kubernetes.io/serviceaccount/token
Third party

Path to the service account token file.

Type
String
Default
/var/run/secrets/kubernetes.io/serviceaccount/token
Defined by
VaultProperties$KubernetesProperties
spring.cloud.vault.kv.application-nameApplication name to be used for the context.
application
Third party

Application name to be used for the context.

Type
String
Default
application
Defined by
VaultKeyValueBackendProperties
spring.cloud.vault.kv.backendName of the default backend.
secret
Third party

Name of the default backend.

Type
String
Default
secret
Defined by
VaultKeyValueBackendProperties
spring.cloud.vault.kv.backend-versionKey-Value backend version.
2
Third partyDeprecated
Key-Value backend version. Currently supported versions are:
  • Version 1 (unversioned key-value backend).
  • Version 2 (versioned key-value backend).
Type
Integer
Default
2
Defined by
VaultKeyValueBackendProperties
Deprecation
WARNING, no replacement
spring.cloud.vault.kv.default-contextName of the default context.
application
Third party

Name of the default context.

Type
String
Default
application
Defined by
VaultKeyValueBackendProperties
spring.cloud.vault.kv.enabledEnable the key-value backend.
true
Third party

Enable the key-value backend.

Type
Boolean
Default
true
Defined by
VaultKeyValueBackendProperties
spring.cloud.vault.kv.profile-separatorProfile-separator to combine application name and profile.
/
Third party

Profile-separator to combine application name and profile.

Type
String
Default
/
Defined by
VaultKeyValueBackendProperties
spring.cloud.vault.kv.profilesList of active profiles.
no default
Third party

List of active profiles. @since 3.0

Type
List<String>
Default
none
Defined by
VaultKeyValueBackendProperties
spring.cloud.vault.namespaceVault namespace (requires Vault Enterprise).
no default
Third party

Vault namespace (requires Vault Enterprise).

Type
String
Default
none
Defined by
VaultProperties
spring.cloud.vault.pcf.instance-certificatePath to the instance certificate (PEM).
no default
Third party

Path to the instance certificate (PEM). Defaults to CF_INSTANCE_CERT env variable.

Type
Resource
Default
none
Defined by
VaultProperties$PcfProperties
spring.cloud.vault.pcf.instance-keyPath to the instance key (PEM).
no default
Third party

Path to the instance key (PEM). Defaults to CF_INSTANCE_KEY env variable.

Type
Resource
Default
none
Defined by
VaultProperties$PcfProperties
spring.cloud.vault.pcf.pcf-pathMount path of the Kubernetes authentication backend.
pcf
Third party

Mount path of the Kubernetes authentication backend.

Type
String
Default
pcf
Defined by
VaultProperties$PcfProperties
spring.cloud.vault.pcf.roleName of the role against which the login is being attempted.
no default
Third party

Name of the role against which the login is being attempted.

Type
String
Default
none
Defined by
VaultProperties$PcfProperties
spring.cloud.vault.portVault server port.
8200
Third party

Vault server port.

Type
Integer
Default
8200
Defined by
VaultProperties
spring.cloud.vault.reactive.enabledFlag to indicate that reactive discovery is enabled.
true
Third party

Flag to indicate that reactive discovery is enabled.

Type
Boolean
Default
true
Defined by
VaultProperties$Reactive
spring.cloud.vault.read-timeoutRead timeout.
15000
Third party

Read timeout.

Type
Integer
Default
15000
Defined by
VaultProperties
spring.cloud.vault.schemeProtocol scheme.
https
Third party

Protocol scheme. Can be either "http" or "https".

Type
String
Default
https
Defined by
VaultProperties
spring.cloud.vault.session.lifecycle.enabledEnable session lifecycle management.
true
Third party

Enable session lifecycle management.

Type
Boolean
Default
true
Defined by
VaultProperties$SessionLifecycle
spring.cloud.vault.session.lifecycle.expiry-thresholdThe expiry threshold for a LoginToken .
7s
Third party

The expiry threshold for a LoginToken. The threshold represents a minimum TTL duration to consider a login token as valid. Tokens with a shorter TTL are considered expired and are not used anymore. Should be greater than refreshBeforeExpiry to prevent token expiry.

Type
Duration
Default
7s
Defined by
VaultProperties$SessionLifecycle
spring.cloud.vault.session.lifecycle.refresh-before-expiryThe time period that is at least required before renewing the LoginToken .
5s
Third party

The time period that is at least required before renewing the LoginToken.

Type
Duration
Default
5s
Defined by
VaultProperties$SessionLifecycle
spring.cloud.vault.ssl.cert-auth-pathMount path of the TLS cert authentication backend.
cert
Third party

Mount path of the TLS cert authentication backend.

Type
String
Default
cert
Defined by
VaultProperties$Ssl
spring.cloud.vault.ssl.enabled-cipher-suitesList of enabled SSL/TLS cipher suites.
no default
Third party

List of enabled SSL/TLS cipher suites. @since 3.0.2

Type
List<String>
Default
none
Defined by
VaultProperties$Ssl
spring.cloud.vault.ssl.enabled-protocolsList of enabled SSL/TLS protocol.
no default
Third party

List of enabled SSL/TLS protocol. @since 3.0.2

Type
List<String>
Default
none
Defined by
VaultProperties$Ssl
spring.cloud.vault.ssl.key-storeTrust store that holds certificates and private keys.
no default
Third party

Trust store that holds certificates and private keys.

Type
Resource
Default
none
Defined by
VaultProperties$Ssl
spring.cloud.vault.ssl.key-store-passwordPassword used to access the key store.
no default
Third party

Password used to access the key store.

Type
String
Default
none
Defined by
VaultProperties$Ssl
spring.cloud.vault.ssl.key-store-typeType of the key store.
no default
Third party

Type of the key store. @since 3.0

Type
String
Default
none
Defined by
VaultProperties$Ssl
spring.cloud.vault.ssl.roleName of the role against which the login is being attempted.
no default
Third party

Name of the role against which the login is being attempted. @since 5.0

Type
String
Default
none
Defined by
VaultProperties$Ssl
spring.cloud.vault.ssl.trust-storeTrust store that holds SSL certificates.
no default
Third party

Trust store that holds SSL certificates.

Type
Resource
Default
none
Defined by
VaultProperties$Ssl
spring.cloud.vault.ssl.trust-store-passwordPassword used to access the trust store.
no default
Third party

Password used to access the trust store.

Type
String
Default
none
Defined by
VaultProperties$Ssl
spring.cloud.vault.ssl.trust-store-typeType of the trust store.
no default
Third party

Type of the trust store. @since 3.0

Type
String
Default
none
Defined by
VaultProperties$Ssl
spring.cloud.vault.tokenStatic vault token.
no default
Third party

Static vault token. Required if #authentication is TOKEN.

Type
String
Default
none
Defined by
VaultProperties
spring.cloud.vault.uriVault URI.
no default
Third party

Vault URI. Can be set with scheme, host and port.

Type
String
Default
none
Defined by
VaultProperties

Required settings may be needed to activate or affect the feature; review them even when they have a default. Optional settings only need to be set to change a default or to turn on the behavior they control. Third party settings belong to libraries such as Spring Boot that CAS builds on; their own documentation may have more detail.

Notes on configuration

Configuration Metadata

The collection of configuration properties listed in this section are automatically generated from the CAS source and components that contain the actual field definitions, types, descriptions, modules, etc. This metadata may not always be 100% accurate, or could be lacking details and sufficient explanations.

Be Selective

This section is meant as a guide only. Do NOT copy/paste the entire collection of settings into your CAS configuration; rather pick only the properties that you need. Do NOT enable settings unless you are certain of their purpose and do NOT copy settings into your configuration only to keep them as reference. All these ideas lead to upgrade headaches, maintenance nightmares and premature aging.

YAGNI

Note that for nearly ALL use cases, declaring and configuring properties listed here is sufficient. You should NOT have to explicitly massage a CAS XML/Java/etc configuration file to design an authentication handler, create attribute release policies, etc. CAS at runtime will auto-configure all required changes for you. If you are unsure about the meaning of a given CAS setting, do NOT turn it on without hesitation. Review the codebase or better yet, ask questions to clarify the intended behavior.

Naming Convention

Property names can be specified in very relaxed terms. For instance cas.someProperty, cas.some-property, cas.some_property are all valid names. While all forms are accepted by CAS, there are certain components (in CAS and other frameworks used) whose activation at runtime is conditional on a property value, where this property is required to have been specified in CAS configuration using kebab case. This is both true for properties that are owned by CAS as well as those that might be presented to the system via an external library or framework such as Spring Boot, etc.

:information_source: Note

When possible, properties should be stored in lower-case kebab format, such as cas.property-name=value. The only possible exception to this rule is when naming actuator endpoints; The name of the actuator endpoints (i.e. ssoSessions) MUST remain in camelCase mode.

Settings and properties that are controlled by the CAS platform directly always begin with the prefix cas. All other settings are controlled and provided to CAS via other underlying frameworks and may have their own schemas and syntax. BE CAREFUL with the distinction. Unrecognized properties are rejected by CAS and/or frameworks upon which CAS depends. This means if you somehow misspell a property definition or fail to adhere to the dot-notation syntax and such, your setting is entirely refused by CAS and likely the feature it controls will never be activated in the way you intend.

Validation

Configuration properties are automatically validated on CAS startup to report issues with configuration binding, especially if defined CAS settings cannot be recognized or validated by the configuration schema. Additional validation processes are also handled via Configuration Metadata and property migrations applied automatically on startup by Spring Boot and family.

Indexed Settings

CAS settings able to accept multiple values are typically documented with an index, such as cas.some.setting[0]=value. The index [0] is meant to be incremented by the adopter to allow for distinct multiple configuration blocks.

With CAS, secrets are picked up at startup of the application server. CAS uses the data and settings from the application name (i.e. cas) and active profiles to determine contexts paths in which secrets should be stored and later fetched.

These context paths typically are:

1
2
/secret/{application}/{profile}
/secret/{application}

As an example, you may write the following CAS setting to Vault:

1
vault write secret/cas/native <setting-name>=<value>

CAS will execute the equivalent of the following command to read settings later when needed:

1
vault read secret/cas/native

All settings and secrets that are stored inside Vault may be reloaded at any given time. To learn more about how CAS allows you to reload configuration changes, please review this guide. To learn more about how configuration is managed and profiled by CAS, please review this guide.

Troubleshooting

To enable additional logging, modify the logging configuration file to add the following:

1
2
3
4
<Logger name="org.springframework.cloud.vault" level="debug" additivity="false">
    <AppenderRef ref="casConsole"/>
    <AppenderRef ref="casFile"/>
</Logger>