← Back to plugin index

Administrators Management

Description
Configuration of administrators in the Adminapp.
Type name
AdministratorsManagement
Class
com.airlock.iam.admin.application.configuration.administrators.AdministratorsManagement
May be used by
Properties
Enforce Role Combinations (enforceRoleCombinations)
Description
If enabled, role combinations can be defined. The system then enforces that only one role combination can be chosen. If disabled, roles can arbitrarily be assigned. However, the configuration of role combinations is not allowed.
Attributes
Boolean
Optional
Default value
true
Assignable Role Combinations (assignableRoleCombinations)
Description

Defines a list of roles (or combination of roles). Only the specified roles (or combination of roles) can be assigned to the administrators.

Role combinations are specified using comma-separate entries (e.g. "useradmin,tokenadmin"). These combinations can only be assigned to or removed from an admin together. At least one role (or combination of roles) must contain the "superadmin" role.

Translations for the roles displayed in the administrators management UI can be defined using the Adminapp translation keys roles.admin.labels.[rolename], where [rolename] is one of the entries. E.g.:

  • roles.admin.labels.useradmin = User Admin
  • roles.admin.labels.useradmin,tokenadmin = Special Admin

Attributes
String-List
Mandatory
Privilege Escalation Protected Admin Roles (PEPAR) (privilegeEscalationProtectedAdminRoles)
Description

Defines a list of protected roles. Operations on an administrator with one of these roles can only be performed by another administrator that also at least has one of these roles assigned.

Each entry contains a single role.

Attributes
String-List
Optional
Super Admin Role (superAdminRole)
Description
Defines the name of the "superadmin" role. Access control must be configured accordingly to define the allowed actions of this role.
Attributes
String
Mandatory
Suggested values
superadmin
Password Generator (passwordGenerator)
Description
Plugin used to generate passwords for administrators. It defines the length and the characters in the generator passwords.
Attributes
Plugin-Link
Optional
Assignable plugins
Password Hash Function (passwordHashFunction)
Description
The hash function used to store the password. Make sure it is the same as used when verifying the password.

NOTE: Some password hashes, such as SHA 256 Password Hash or Scrypt Password Hash, produce binary output. If one of these is used, make sure the persistence layer supports binary data in the hash field and the corresponding persistence plugins (e.g. Database User Store or Ldap Connector) are configured to treat hash values as binary values.
In case the persistence layer expects a string, encode the password hash by wrapping it with an encoder. To achieve this, use the Password Hash Configuration plugin and specify the hash function (such as Scrypt Password Hash) together with the desired encoder. We recommend using the Base64 Password Hash Encoder.

Attributes
Plugin-Link
Optional
Assignable plugins
Columns In Admin List (columnsInAdminList)
Description
The property names and labels of context data to be displayed on the admin list page. Usually, this is the first- and last name of the administrator.

The data for the columns is taken from the context data container of the available administrators. The configuration of the used admin persister must include the context data properties referenced here.

The columns are displayed in addition to the following columns:

  • username
  • assigned roles
  • locked flag

Attributes
Plugin-List
Optional
Assignable plugins
Rows On Admin Detail Page (rowsOnAdminDetailPage)
Description
The property names and labels of context data to be displayed on the admin detail page.

The data for is taken from the context data container of the selected administrator. The configuration of the used admin persister must include the context data properties referenced here.

Attributes
Plugin-List
Optional
Assignable plugins
Admin User Store (adminUserStore)
Description
User store to manage administrator data.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Lock Reasons (lockReasons)
Description
Lock reasons listed in this property define the options selectable by an administrator when locking an administrator manually. Any string can be used to identify a lock reason. The following is a set of predefined lockout reasons: LockReason.TooManyLoginFailed= Too many login failedLockReason.InitialPasswordExpired= Initial password expiredLockReason.MaxWrongOldPassword= Wrong old passwordLockReason.InitiatedByUser= Initiated by userLockReason.InitiatedByAdmin= Initiated by administrator
Attributes
String-List
Optional
Default value
[LockReason.InitiatedByAdmin]
YAML Template (with default values)

type: AdministratorsManagement
id: AdministratorsManagement-xxxxxx
displayName: 
comment: 
properties:
  adminUserStore:
  assignableRoleCombinations:
  columnsInAdminList:
  enforceRoleCombinations: true
  lockReasons: [LockReason.InitiatedByAdmin]
  passwordGenerator:
  passwordHashFunction:
  privilegeEscalationProtectedAdminRoles:
  rowsOnAdminDetailPage:
  superAdminRole: