Matrix Card Generator
Description
Configuration settings for the generation of matrix cards.
May be used by
Properties
Token Alphabet (
tokenAlphabet) Description
Defines the alphabet (or set of characters) of which a token is composed.
Attributes
Enum
Mandatory
Token Length (
tokenLength) Description
Specifies the length of each token on the token list.
Attributes
Integer
Mandatory
Tokens Per List (
tokensPerList) Description
Specifies the total number of tokens per token list.
Attributes
Integer
Mandatory
Hash Function (
hashFunction) Description
Specifies the hash function plugin used by this plugin in order to produce hash value of the tokens. Using an insecure hash function (such as the
IdentityPasswordHash plugin) results potential security vulnerability in that the token lists may easily be reconstructed from the stored hash values. Attributes
Plugin-Link
Mandatory
Assignable plugins
AWS KMS Password Hash Argon2id Password Hash Bcrypt Password Hash Combined Password Hash Encrypted Password Hash History Password Hash Identity Password Hash LDAP Password Hash MD5 Base64 Password Hash MD5 Hex Password Hash Multi Password Hash (LDAP-style) Password Hash Configuration SHA1 Base64 Password Hash SHA1 Hex Password Hash SHA1 Password Hash SHA256 Base64 Password Hash SHA256 Hex Password Hash SHA256 Password Hash Scrypt Password Hash
Token List Renderer (
tokenListRenderer) Description
Specifies the token list renderer plugin used.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Delete Old Token Lists (
deleteOldTokenLists) Description
Deletes old rendered token lists of a user from the file system when a new one is rendered. Setting this to TRUE results in at most one rendered token list per user.
If this property is set to TRUE, the plugin must have permission to delete files from the directory.
If this property is set to TRUE, the plugin must have permission to delete files from the directory.
Attributes
Boolean
Optional
Default value
true
Working Directory (
workingDirectory) Description
A writable directory used to store partial reports.
If this property is defined, the token lists are not directly generated into the output directory (see other property) but they are generated into this working directory and are moved to the output directory once they are done.
This helps to solve problems with processes automatically reading the rendered token lists and reading partial token lists during the generation process. Make sure that the working directory and the output directory reside in the same file system (if not the moving of the generated file will not be atomic).
The directory is either absolute or relative to the JVMs current directory.
If this property is defined, the token lists are not directly generated into the output directory (see other property) but they are generated into this working directory and are moved to the output directory once they are done.
This helps to solve problems with processes automatically reading the rendered token lists and reading partial token lists during the generation process. Make sure that the working directory and the output directory reside in the same file system (if not the moving of the generated file will not be atomic).
The directory is either absolute or relative to the JVMs current directory.
Attributes
File/Path
Optional
Output Directory (
outputDirectory) Description
Directory in the file system to put the rendered token lists in. The directory is either absolute or relative to the JVMs current directory.
This property is not required if the renderer plugin (see separate property) does not write on the output stream (e.g. sends it somewhere else). It is required otherwise.
Note: If this property is not defined and the used renderer plugin writes on the output stream, then the result (e.g. a PDF file) is lost.
Attributes
File/Path
Optional
File Name Prefix (
fileNamePrefix) Description
Filename prefix for rendered report files. It is important to set this to a unique value for the kind of reports generated by this task. When this task deletes old reports, it looks at this prefix (and the user id) in order to find out what files to delete. Thus, if this prefix is the same as for other reports and the reside in the same directory, other reports may be deleted.
Do not use the prefix "pwd-" if password- reports are stored in the same directory. This prefix is the default for password letters (and not configurable in older plugin versions).
This property is optional to be backwards compatible. It is strongly recommended to define a prefix.
Attributes
String
Optional
Suggested values
tan-, matrix-, gridcard-
File Name Suffix (
fileNameSuffix) Description
Filename suffix for rendered token list files.
Attributes
String
Optional
Suggested values
.pdf, .docx, .txt
YAML Template (with default values)
type: MatrixCardGenerator
id: MatrixCardGenerator-xxxxxx
displayName:
comment:
properties:
deleteOldTokenLists: true
fileNamePrefix:
fileNameSuffix:
hashFunction:
outputDirectory:
tokenAlphabet:
tokenLength:
tokenListRenderer:
tokensPerList:
workingDirectory: