Class pki:WebTokenData (CONCRETE)

Class ID:1480
Class Label: Web Token Data
Encrypted: true - Exportable: true - Persistent: true - Configurable: true - Subject to Quota: Disabled - Abstraction Layer: Ambiguous Placement in the Model - APIC NX Processing: Disabled
Write Access: [aaa, admin]
Read Access: [aaa, admin]
Creatable/Deletable: no (see Container Mos for details)
Semantic Scope: Fabric
Semantic Scope Evaluation Rule: Parent
Monitoring Policy Source: Parent
Monitoring Flags : [ IsObservable: false, HasStats: false, HasFaults: false, HasHealth: false, HasEventRules: false ]

The cryptographic data used for generating and verifying web tokens.

Naming Rules
RN FORMAT: webtokendata

    [1] PREFIX=webtokendata


DN FORMAT: 

[1] uni/userext/pkiext/webtokendata

                


Diagram

Super Mo: pki:Definition,
Container Mos: pki:Ep (deletable:no),
Contained Mos: aaa:RbacAnnotation, tag:Annotation, tag:Tag,
Relations From: aaa:UserSessionEp, pol:DefRelnHolder,
Relations: pki:RtWebTokenData, pki:RtWebtokenRel,


Containers Hierarchies
[V] top:Root  This class represents the root element in the object hierarchy. All managed objects in the system are descendants of the Root element.
 ├
[V] fabric:Topology The root for IFC topology.
 
 ├
[V] fabric:Pod A pod.
 
 
 ├
[V] fabric:Node The root node for the APIC.
 
 
 
 ├
[V] ctx:Local The local Context.
 
 
 
 
 ├
[V] ctx:Application The context application.
 
 
 
 
 
 ├
[V] pol:Uni Represents policy definition/resolution universe.
 
 
 
 
 
 
 ├
[V] aaa:UserEp A user endpoint is a local user. A user is assigned a role determines the user's privileges, and belongs to a security domain, which determines the user's scope of control
 
 
 
 
 
 
 
 ├
[V] pki:Ep The PKI configuration, which includes key rings and certificate authority (CA) credentials. Components of the PKI are used to establish secure communications between two devices.
 
 
 
 
 
 
 
 
 ├
[V] pki:WebTokenData The cryptographic data used for generating and verifying web tokens.
[V] top:Root  This class represents the root element in the object hierarchy. All managed objects in the system are descendants of the Root element.
 ├
[V] pol:Uni Represents policy definition/resolution universe.
 
 ├
[V] aaa:UserEp A user endpoint is a local user. A user is assigned a role determines the user's privileges, and belongs to a security domain, which determines the user's scope of control
 
 
 ├
[V] pki:Ep The PKI configuration, which includes key rings and certificate authority (CA) credentials. Components of the PKI are used to establish secure communications between two devices.
 
 
 
 ├
[V] pki:WebTokenData The cryptographic data used for generating and verifying web tokens.


Contained Hierarchy
[V] pki:WebTokenData The cryptographic data used for generating and verifying web tokens.
 ├
[V] aaa:RbacAnnotation  RbacAnnotation is used for capturing rbac properties of any apic object Objects can append rbacannotations as Object->RbacAnnotation which is then checked for domain eligibility
 ├
[V] fault:Delegate Exposes internal faults to the user. A fault delegate object can be defined on IFC (for example, for an endpoint group) and when the fault is raised (for example, under an endpoint policy on a switch), a fault delegate object is created on IFC under the specified object. A fault delegate object follows the lifecycle of the original fault instance object, being created, modified, or deleted based on the changes of the original fault.
 ├
[V] pki:RtWebTokenData 
 ├
[V] pki:RtWebtokenRel A target relation to cryptographic data used for generating and verifying web tokens.
 ├
[V] tag:Annotation 
 ├
[V] tag:Tag 


Inheritance
[V] naming:NamedObject An abstract base class for an object that contains a name.
 ├
[V] pol:Obj Represents a generic policy object.
 
 ├
[V] pol:Def Represents self-contained policy document.
 
 
 ├
[V] pki:Definition This is an abstract class and cannot be instantiated.
 
 
 
 ├
[V] pki:WebTokenData The cryptographic data used for generating and verifying web tokens.


Events
                pki:WebTokenData:creation__pki_WebTokenData
pki:WebTokenData:modification__pki_WebTokenData
pki:WebTokenData:deletion__pki_WebTokenData


Faults
                


Fsms
                


Properties Summary
Defined in: pki:WebTokenData
mo:Annotation
          string:Basic
annotation  (pki:WebTokenData:annotation)
           NO COMMENTS
mo:ExtMngdByType
          scalar:Bitmask32
extMngdBy  (pki:WebTokenData:extMngdBy)
           NO COMMENTS
pki:SHA256_SharedSecret16
          string:Password
hashSecret  (pki:WebTokenData:hashSecret)
           A shared secret key for calculating the hash.
pki:AES128IV
          string:Password
initializationVector  (pki:WebTokenData:initializationVector)
           A random starting variable.
string:Basic jwtApiKey  (pki:WebTokenData:jwtApiKey)
           NO COMMENTS
aaa:SshData
          string:CharBuffer
jwtPrivateKey  (pki:WebTokenData:jwtPrivateKey)
           NO COMMENTS
aaa:SshData
          string:CharBuffer
jwtPublicKey  (pki:WebTokenData:jwtPublicKey)
           NO COMMENTS
pki:AES128Key
          string:Password
key  (pki:WebTokenData:key)
           The web token AES encryption key.
pki:WebTokenValidityPeriodType
          scalar:Uint16
maximumValidityPeriod  (pki:WebTokenData:maximumValidityPeriod)
           The maximum validity period for a webt oken.
pki:SessionRecordFlags
          scalar:Bitmask16
sessionRecordFlags  (pki:WebTokenData:sessionRecordFlags)
           Enables or disables a refresh in the session records.
string:Basic siteFingerprint  (pki:WebTokenData:siteFingerprint)
          
pki:GuiIdleTimeoutType
          scalar:Uint16
uiIdleTimeoutSeconds  (pki:WebTokenData:uiIdleTimeoutSeconds)
           The maximum interval time the GUI remains idle before login needs to be refreshed.
pki:WebTokenTimeoutType
          scalar:Uint16
webtokenTimeoutSeconds  (pki:WebTokenData:webtokenTimeoutSeconds)
           The web token timeout interval.
Defined in: pki:Definition
naming:Name
          string:Basic
name  (pki:Definition:name)
           Overrides:pol:Obj:name | naming:NamedObject:name
          
Defined in: pol:Def
naming:Descr
          string:Basic
descr  (pol:Def:descr)
           Specifies a description of the policy definition.
naming:Descr
          string:Basic
ownerKey  (pol:Def:ownerKey)
           The key for enabling clients to own their data for entity correlation.
naming:Descr
          string:Basic
ownerTag  (pol:Def:ownerTag)
           A tag for enabling clients to add their own data. For example, to indicate who created this object.
Defined in: naming:NamedObject
naming:NameAlias
          string:Basic
nameAlias  (naming:NamedObject:nameAlias)
           NO COMMENTS
Defined in: mo:Resolvable
mo:Owner
          scalar:Enum8
lcOwn  (mo:Resolvable:lcOwn)
           A value that indicates how this object was created. For internal use only.
Defined in: mo:Ownable
scalar:Uint16 uid  (mo:Ownable:uid)
           A unique identifier for this object.
mo:UserDomType
          string:Basic
userdom  (mo:Ownable:userdom)
           NO COMMENTS
Defined in: mo:Modifiable
mo:TStamp
          scalar:Date
modTs  (mo:Modifiable:modTs)
           The time when this object was last modified.
Defined in: mo:TopProps
mo:ModificationChildAction
          scalar:Bitmask32
childAction  (mo:TopProps:childAction)
           Delete or ignore. For internal use only.
reference:BinRef dn  (mo:TopProps:dn)
           A tag or metadata is a non-hierarchical keyword or term assigned to the fabric module.
reference:BinRN rn  (mo:TopProps:rn)
           Identifies an object from its siblings within the context of its parent object. The distinguished name contains a sequence of relative names.
mo:ModificationStatus
          scalar:Bitmask32
status  (mo:TopProps:status)
           The upgrade status. This property is for internal use only.
Properties Detail

annotation

Type: mo:Annotation
Primitive Type: string:Basic

Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "128"
        Allowed Chars:
            Regex: [a-zA-Z0-9_.:-]+
    Comments:
NO COMMENTS



childAction

Type: mo:ModificationChildAction
Primitive Type: scalar:Bitmask32

Units: null
Encrypted: false
Access: implicit
Category: TopLevelChildAction
    Comments:
Delete or ignore. For internal use only.
Constants
deleteAll 16384u deleteAll NO COMMENTS
ignore 4096u ignore NO COMMENTS
deleteNonPresent 8192u deleteNonPresent NO COMMENTS
DEFAULT 0 --- This type is used to





descr

Type: naming:Descr
Primitive Type: string:Basic

Like: naming:Described:descr
Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "128"
        Allowed Chars:
            Regex: [a-zA-Z0-9\\!#$%()*,-./:;@ _{|}~?&+]+
    Comments:
Specifies a description of the policy definition.



dn

Type: reference:BinRef

Units: null
Encrypted: false
Access: implicit
Category: TopLevelDn
    Comments:
A tag or metadata is a non-hierarchical keyword or term assigned to the fabric module.



extMngdBy

Type: mo:ExtMngdByType
Primitive Type: scalar:Bitmask32

Units: null
Encrypted: false
Access: implicit
Category: TopLevelRegular
    Comments:
NO COMMENTS
Constants
undefined 0u undefined NO COMMENTS
msc 1u msc NO COMMENTS
DEFAULT undefined(0u) undefined NO COMMENTS





hashSecret

Type: pki:SHA256_SharedSecret16
Primitive Type: string:Password

Units: null
Encrypted: true
Access: implicit
Category: TopLevelRegular
    Comments:
A shared secret key for calculating the hash.



initializationVector

Type: pki:AES128IV
Primitive Type: string:Password

Units: null
Encrypted: true
Access: implicit
Category: TopLevelRegular
    Comments:
A random starting variable.



jwtApiKey

Type: string:Basic

Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "512"
    Comments:
NO COMMENTS



jwtPrivateKey

Type: aaa:SshData
Primitive Type: string:CharBuffer

Units: null
Encrypted: true
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "16384"
        Allowed Chars:
            Regex: [a-zA-Z0-9=\n\r/+ _.@-]+
    Comments:
NO COMMENTS



jwtPublicKey

Type: aaa:SshData
Primitive Type: string:CharBuffer

Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "16384"
        Allowed Chars:
            Regex: [a-zA-Z0-9=\n\r/+ _.@-]+
    Comments:
NO COMMENTS



key

Type: pki:AES128Key
Primitive Type: string:Password

Units: null
Encrypted: true
Access: implicit
Category: TopLevelRegular
    Comments:
The web token AES encryption key.



lcOwn

Type: mo:Owner
Primitive Type: scalar:Enum8

Units: null
Encrypted: false
Access: implicit
Category: TopLevelRegular
    Comments:
A value that indicates how this object was created. For internal use only.
Constants
local 0 Local NO COMMENTS
policy 1 Policy NO COMMENTS
replica 2 Replica NO COMMENTS
resolveOnBehalf 3 ResolvedOnBehalf NO COMMENTS
implicit 4 Implicit NO COMMENTS
DEFAULT local(0) Local NO COMMENTS





maximumValidityPeriod

Type: pki:WebTokenValidityPeriodType
Primitive Type: scalar:Uint16

Units: hours
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: 4  max: 24
    Comments:
The maximum validity period for a webt oken.
Constants
defaultValue 24 --- NO COMMENTS





modTs

Type: mo:TStamp
Primitive Type: scalar:Date

Units: null
Encrypted: false
Access: implicit
Category: TopLevelRegular
    Comments:
The time when this object was last modified.
Constants
never 0ull never NO COMMENTS
DEFAULT never(0ull) never NO COMMENTS





name

Type: naming:Name
Primitive Type: string:Basic

Overrides:pol:Obj:name  |  naming:NamedObject:name
Units: null Encrypted: false Access: create Category: TopLevelRegular Property Validators: Range: min: "0" max: "64" Allowed Chars: Regex: [a-zA-Z0-9_.:-]+
    Comments:



nameAlias

Type: naming:NameAlias
Primitive Type: string:Basic

Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "63"
        Allowed Chars:
            Regex: [a-zA-Z0-9_.-]+
    Comments:
NO COMMENTS



ownerKey

Type: naming:Descr
Primitive Type: string:Basic

Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "128"
        Allowed Chars:
            Regex: [a-zA-Z0-9\\!#$%()*,-./:;@ _{|}~?&+]+
    Comments:
The key for enabling clients to own their data for entity correlation.



ownerTag

Type: naming:Descr
Primitive Type: string:Basic

Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "64"
        Allowed Chars:
            Regex: [a-zA-Z0-9\\!#$%()*,-./:;@ _{|}~?&+]+
    Comments:
A tag for enabling clients to add their own data. For example, to indicate who created this object.



rn

Type: reference:BinRN

Units: null
Encrypted: false
Access: implicit
Category: TopLevelRn
    Comments:
Identifies an object from its siblings within the context of its parent object. The distinguished name contains a sequence of relative names.



sessionRecordFlags

Type: pki:SessionRecordFlags
Primitive Type: scalar:Bitmask16

Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Comments:
Enables or disables a refresh in the session records.
Constants
login 1 Login NO COMMENTS
logout 2 Logout NO COMMENTS
refresh 4 Refresh NO COMMENTS
defaultValue 7 --- NO COMMENTS





siteFingerprint

Type: string:Basic

Units: null
Encrypted: false
Access: implicit
Category: TopLevelRegular
    Comments:



status

Type: mo:ModificationStatus
Primitive Type: scalar:Bitmask32

Units: null
Encrypted: false
Access: implicit
Category: TopLevelStatus
    Comments:
The upgrade status. This property is for internal use only.
Constants
created 2u created In a setter method: specifies that an object should be created. An error is returned if the object already exists.
In the return value of a setter method: indicates that an object has been created.
modified 4u modified In a setter method: specifies that an object should be modified
In the return value of a setter method: indicates that an object has been modified.
deleted 8u deleted In a setter method: specifies that an object should be deleted.
In the return value of a setter method: indicates that an object has been deleted.
DEFAULT 0 --- This type controls the life cycle of objects passed in the XML API.

When used in a setter method (such as configConfMo), the ModificationStatus specifies whether an object should be created, modified, deleted or removed.
In the return value of a setter method, the ModificationStatus indicates the actual operation that was performed. For example, the ModificationStatus is set to "created" if the object was created. The ModificationStatus is not set if the object was neither created, modified, deleted or removed.

When invoking a setter method, the ModificationStatus is optional:
If a setter method such as configConfMo is invoked and the ModificationStatus is not set, the system automatically determines if the object should be created or modified.






uiIdleTimeoutSeconds

Type: pki:GuiIdleTimeoutType
Primitive Type: scalar:Uint16

Units: seconds
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: 60  max: 65525
    Comments:
The maximum interval time the GUI remains idle before login needs to be refreshed.
Constants
defaultValue 1200 --- NO COMMENTS





uid

Type: scalar:Uint16

Units: null
Encrypted: false
Access: implicit
Category: TopLevelRegular
    Comments:
A unique identifier for this object.



userdom

Type: mo:UserDomType
Primitive Type: string:Basic

Units: null
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: "0"  max: "256"
        Allowed Chars:
            Regex: [a-zA-Z0-9_.:-]+
    Comments:
NO COMMENTS
Constants
defaultValue "all" --- NO COMMENTS





webtokenTimeoutSeconds

Type: pki:WebTokenTimeoutType
Primitive Type: scalar:Uint16

Units: seconds
Encrypted: false
Access: admin
Category: TopLevelRegular
Property Validators:
    Range:  min: 300  max: 9600
    Comments:
The web token timeout interval.
Constants
defaultValue 600 --- NO COMMENTS