Web Agent Services appsetting.json File
The WebAgentServices appsettings.json configuration file allows you to change default orchestrator
Keyfactor orchestrators perform a variety of functions, including managing certificate stores and SSH key stores. API
An API is a set of functions to allow creation of applications. Keyfactor offers the Keyfactor API, which allows third-party software to integrate with the advanced certificate enrollment and management features of Keyfactor Command. installation configuration settings.
Windows Installations Under IIS
To update the appsettings.json file:
-
Navigate to the WebAgentServices\Configuration folder on your server, located by default at:
C:\Program Files\Keyfactor\Keyfactor Platform\WebAgentServices\Configuration - Browse to open the appsettings.json file in a text editor (for example, Notepad) and adjust the values as needed.
- Save the files.
{
"ActiveDirectoryEnforced": false,
"ClientCertificateAuthentication": {
"Enabled": false,
"CheckAuthCertificateRevocationStatus": true,
"DaysBeforeExpirationError": 30,
"DaysBeforeExpirationWarning": 180,
"AlwaysUseHeaderCertificate": false,
"AuthenticationHeaderName": "X-ARR-ClientCert"
},
"ExtensionsDirectory": "Extensions",
"MaxRequestSizeKb": "5000",
"NLogConfigFile": "Configuration/NLog_Orchestrators.config",
"NLogPoller": {
"Enabled": false,
"PollingInterval": 10
},
"SqlRetryConfiguration": {
"NumberOfTries": "5",
"DeltaTime": "00:00:00.5",
"MaxTimeInterval": "00:02:00"
}
}
Container Installations Under Kubernetes
The configurations from the appsettings.json file can be updated in one of two ways for container installations:
-
To update one or two settings, set an environment variable in your custom values file.
-
To update a large number of settings or the entire contents of the appsettings.json file, create a ConfigMap containing the appsettings.json file contents and mount it as a volume to replace the existing appsettings.json file.
To set an environment variable for one or two configuration values:
-
On your Kubernetes server, edit your values file to add an additionalEnvironmentVariables section (if one does not already exist) and environment variable names and values for the settings to change. For example, the following shows a portion of the example values file (see Install Keyfactor Command in Containers Under Kubernetes) with the MaxRequestSizeKb value set to 3000.
additionalEnvironmentVariables: - name: MaxRequestSizeKb value: '3000' workloadDefaults: volumes: - name: root-cas configMap: name: ca-roots items: - key: ca-certificates.crt path: ca-certificates.crt volumeMounts: - name: root-cas mountPath: /etc/pki/tls/certs/ca-bundle.crt # Common CA bundle path for Command containers subPath: ca-certificates.crt # Source path for your CA bundle may varyNote: Parameters are referenced by full name, including parent parameter
A parameter or argument is a value that is passed into a function in an application. name, if applicable. A SQL retry configuration setting would be, for example, SqlRetryConfiguration_NumberOfTries. -
Load the new values, referencing the deployment name, Namespace, your customized values file, the Helm chart, and version. For example:
sudo helm upgrade Helm_Deployment_Name --namespace keyfactor-command --values values-local.yaml oci://repo.keyfactor.com/charts/command --version 26.2.1
To provide the appsettings.json file as a ConfigMap:
-
On your Kubernetes server, create an appsettings.json file with the full contents of the file, including the updates you want to make. For example:
Copy{
"ActiveDirectoryEnforced": false,
"ClientCertificateAuthentication": {
"Enabled": false,
"CheckAuthCertificateRevocationStatus": true,
"DaysBeforeExpirationError": 30,
"DaysBeforeExpirationWarning": 180,
"AlwaysUseHeaderCertificate": false,
"AuthenticationHeaderName": "X-ARR-ClientCert"
},
"ExtensionsDirectory": "Extensions",
"MaxRequestSizeKb": "5000",
"NLogConfigFile": "Configuration/NLog_Orchestrators.config",
"NLogPoller": {
"Enabled": false,
"PollingInterval": 10
},
"SqlRetryConfiguration": {
"NumberOfTries": "5",
"DeltaTime": "00:00:00.5",
"MaxTimeInterval": "00:02:00"
}
}Important: This file needs to be called appsettings.json when you create the ConfigMap for it, not something like appsettings-agentapi.json. -
On your Kubernetes server, create a ConfigMap containing the appsettings.json file. For example:
sudo kubectl create configmap appsettings-orchestratorapi --namespace keyfactor-command --from-file=/opt/kyf_command/appsettings.json -
Edit your values file to add a orchestratorapi section under appConfig (if one does not already exist) and a volume and volumeMount for the ConfigMap of the appsettings.json file within that. For example:
appConfig: orchestratorapi: volumes: - name: appsettings-orchestratorapi-volume configMap: name: appsettings-orchestratorapi volumeMounts: - name: appsettings-orchestratorapi-volume mountPath: /app/Configuration/appsettings.json subPath: appsettings.json -
Load the new values, referencing the deployment name, Namespace, your customized values file, the Helm chart, and version. For example:
sudo helm upgrade Helm_Deployment_Name --namespace keyfactor-command --values values-local.yaml oci://repo.keyfactor.com/charts/command --version 26.2.1
Configuration Settings
The following table shows the configuration settings for the Keyfactor Command OrchestratorAPI application available in the appsettings.json file.
Table 73: WebAgentServices Appsetting.json File Parameters
| Setting | Description | ||||||
|---|---|---|---|---|---|---|---|
|
ActiveDirectoryEnforced
|
A Boolean that indicates whether Active Directory authentication is in use for the Keyfactor Command server. This should be set to False if you are not using Active Directory. An IIS reset is required to apply changes to this setting. | ||||||
|
ClientCertificateAuthentication
|
Configuration settings for client certificate authentication. These values are not used for container installations under Kubernetes. |
||||||
|
ExtensionsDirectory
|
Enter the file path to the extensions to be loaded by the extension loader (for support of custom extensions such as registration handlers and workflow steps). The default is Extensions. For Windows installations under IIS, this is a subdirectory of the WebAgentServices directory. This translates to, for example, for Windows installations under IIS: C:\Program Files\Keyfactor\Keyfactor Platform\WebAgentServices\Extensions
Container installations under Kubernetes: /app/Configuration/Extensions
|
||||||
|
MaxRequestSizeKb
|
This application setting is only used for the CA synchronizations managed with a Keyfactor Universal Orchestrator. It is used to configure the CA synchronization batch size. The default is 5000. | ||||||
|
NLogConfigFile
|
Enter the file path to the NLog_Orchestrators.config file as a subdirectory of the WebAgentServices directory. The default is: Configuration\\NLog_Orchestrators.config
This translates to, for example: C:\Program Files\Keyfactor\Keyfactor Platform\WebAgentServices\Configuration\NLog_Orchestrators.config
This value is not used for container installations under Kubernetes. |
||||||
|
NLogPoller
|
If turned on, the NLog poller service periodically queries for updates to the custom NLog file.
|
||||||
|
SqlRetryConfiguration
|
SQL retry settings (seeChanging SQL Retry Settings for more information). |
Was this page helpful? Provide Feedback