mTAN/SMS Token Controller
Description
Token controller plugin to handle mTAN (SMS) tokens. In addition to adding, changing and removing phone numbers, this plugin offers the following features:
- Send OTP code to user's phone (e.g. to authenticate user calling help desk or to verify the number entered manually).
- When changing the phone number, a notification about this can be sent to the old phone number.
- A notification about the registration of a phone number may be sent to the corresponding number.
- Part (or all of) the configured phone numbers may be masked, so the administrator does not see entire numbers.
May be used by
Properties
mTAN Settings (
mtanSettings) Description
Global mTAN settings configuring all kind of aspects concerning mTAN.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Notify Old Number (
notifyOldNumber) Description
Set to true to inform the old phone number when changing a user's phone number. The message defined by property "notifyOldNumberTemplate".
Attributes
Boolean
Optional
Default value
false
Notify Old Number Template (
notifyOldNumberTemplate) Description
Template text used to inform the old phone number when a new phone number is registered. The template may contain the token "$OLDNUMBER$". It is replaced by the old phone number. The template may contain the token "$NEWNUMBER$". It is replaced by the new phone number.
This property is only relevant if "notifyOldNumber" is true.
Attributes
String
Optional
Secret Letter Renderer (
secretLetterRenderer) Description
If configured, allows to generate an mTAN IAK directly from the admin tool. The administrator requires the 'generateMtanIak' right to perform the operation. Also note that whenever this property is configured, the mTAN Handler configured in the mTAN Settings must be configured such that it supports immediate generation of IAKs.
Attributes
Plugin-Link
Optional
Assignable plugins
Identifier (
identifier) Description
Identifier for the credential. This is used as value in the authentication method field in the persistence layer. Make sure this value is the same (for the same credential) in all Airlock IAM components.
Make sure the identifier is unique among all configured token controllers.
The identifier is also used as key to translate the display name of this token controller. The key is assembled as follows: edituserpage.cred.XYZ.title (where XYZ is the identifier).
Attributes
String
Optional
Default value
MTAN
Suggested values
MTAN, SMS
Auto Order Credential (
autoOrderCredential) Description
Set this flag to true to automatically order the credential when it is added to a user.
Attributes
Boolean
Optional
Default value
false
Auto Order For New Users (
autoOrderForNewUsers) Description
Set this flag to true to automatically order the credential if the user is created. This flag is not required if the "mTAN Letter User Event Listener" is configured in the "Database User Persister". It is no issue to have configured both.
Attributes
Boolean
Optional
Default value
false
Show Letter Attributes (
showLetterAttributes) Description
Set this flag to true to display the letter attributes (used to display generation and delivery dates of credential letters).
Attributes
Boolean
Optional
Default value
false
Delete Properties With Credential (
deletePropertiesWithCredential) Description
Defines a list of context data properties that are considered to part of the credential data. The specified context data properties are deleted (set to "null") when the credential is deleted (in addition to the credential data field, the serial number, the letter attribute and the order flag).
Make sure, the underlying persister plugin is configured to persist the specified context data properties.
Make sure, the underlying persister plugin is configured to persist the specified context data properties.
Attributes
String-List
Optional
YAML Template (with default values)
type: MtanTokenController
id: MtanTokenController-xxxxxx
displayName:
comment:
properties:
autoOrderCredential: false
autoOrderForNewUsers: false
deletePropertiesWithCredential:
identifier: MTAN
mtanSettings:
notifyOldNumber: false
notifyOldNumberTemplate:
secretLetterRenderer:
showLetterAttributes: false