<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<FedizConfig>
	<contextConfig name="/${context.name}">
		<audienceUris>
			<audienceItem>urn:com:10point1:instream:instreamportal</audienceItem>
		</audienceUris>
		<certificateStores>
            <trustManager>
				<keyStore file="bam_keystore.jks" password="secret" type="JKS" />
			</trustManager>
		</certificateStores>
        <signingKey keyPassword="secret">
            <keyStore file="bam_keystore.jks" password="secret" type="JKS" />
        </signingKey>
        <tokenDecryptionKey keyPassword="secret">
            <keyStore file="bam_keystore.jks" password="secret" type="JKS" />
        </tokenDecryptionKey>
        <trustedIssuers>
                <issuer certificateValidation="ChainTrust" />
		</trustedIssuers>
        <maximumClockSkew>1000</maximumClockSkew>
		<protocol xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="federationProtocolType" version="1.2">
            <realm type="Class">com.w1.auth.sso.InstreamCallbackHandler</realm>
			<!-- realm type="Class" value="com.w1.auth.sso.InstreamCallbackHandler" / -->
			<issuer>https://stsinstreamlab.thebamalliance.com/</issuer>
			<reply>/instream/j_spring_fediz_security_check</reply>
			<claimTypesRequested>
				<claimType type="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name" optional="false" />
			</claimTypesRequested>
            <!--authenticationType type="String" value="http://docs.oasis-open.org/wsfed/authorization/200706/authntypes/smartcard" /-->
            <tokenValidators>
                <validator>org.apache.cxf.fediz.core.CustomValidator</validator>
            </tokenValidators>
		</protocol>
	</contextConfig>
</FedizConfig>
