Use ESVs to override global configuration
Global configuration contains settings that apply to all realms in your Advanced Identity Cloud environment. Ping Identity manages this configuration on your behalf. However, several global configuration settings contain ESV placeholders set with default values. You can create the following ESV variables to override these default values in your environments to customize specific behaviors.
| ESV name | Possible values | Default value | Description |
|---|---|---|---|
|
Boolean |
|
Lets you collect and validate all certificates in a certificate chain using the Certificate Collector and Certificate Validation nodes.
To enable this behavior, set this ESV to |
|
Boolean |
|
Lets you override the default By default, the Find more information in Override default |
|
Boolean |
|
Lets you use ETag assertions to verify that a CTS token hasn’t changed since the thread last read it. By default, parallel updates can no longer be made for CTS sessions. To re-enable previous behavior, set this ESV to |
|
Boolean |
|
Lets you ignore critical headers in JWTs used in OAuth 2.0 flows.
To enable this behavior, set this ESV to |
|
Boolean |
|
Lets you overwrite the |
|
String ( |
|
Lets you specify the HTTP binding used to redirect users to the SAML error page when an error occurs during a SAML 2.0 flow.
To specify the HTTP binding, set this ESV to |
|
String (URL) |
|
Lets you specify the URL of the page that’s displayed to end users when an error occurs during a SAML 2.0 flow, for example, You can change the HTTP binding by creating an ESV variable named |
|
Integer |
|
Lets you specify the maximum size, in bytes, for SAML requests. If a SAML request exceeds this size, it will be rejected. Learn more in this support KB article. |
|
Boolean |
|
Lets you disable scope validation script behavior that ensures refresh tokens only obtain access tokens with identical or narrower scopes. Setting this ESV to Learn more in Scope validation. |
|
Boolean |
|
Lets you enforce certain validation rules when processing OAuth 2.0 request objects.
To enable this behavior, set this ESV to |
|
Boolean |
|
Lets you enforce stricter adherence to the PAR and JAR specifications.
Setting the value to |
|
Boolean |
|
Lets you disable legacy JWT validation behavior for OAuth 2.0 and OpenID Connect (OIDC) flows.
If you require the non-legacy behavior, set this ESV to |
|
Boolean |
|
If the OIDC Claims Plugin Type in the OAuth 2.0 provider is set to |