The F-TICKS format implemented by this log appender is a generalization of the eduroam F-TICKS format:
federationIdentifier is 'SWAMID' and
version is '1.0'.
The attributes exposed are:
the login time stamp
the relying party entityID
the asserting party entityID (typcially the IdP)
a sha256-hash of the local principal name and a unique key
the authentication method URN
The instruction is know to work forIdentity Provider version 3.1 or later.
Configuration is done in idp.properties:
Use the following command to generate a salt
Do not lose this salt once you've started to generate logs. If this salt is lost or reset then all local principal names will appear to have changed to analysis tools so avoid this!
Enable the logging
Add the following options to idp.properties