OATH OTP Token Controller
Description
Manages OATH OTP (software OTP generators on mobile devices) tokens according to OATH standards based on H-MAC.
Time-based OTP ("TOTP" according to draft standard http://www.ietf.org/id/draft-mraihi-totp-timebased-06.txt) and counter-based OTP ("HOTP" according to RFC 4226) are supported.
There are number of freely available clients ("apps") for various mobile phone operating systems. The plugin has been tested with the "Google Authenticator" app.
May be used by
Properties
OATH OTP Settings (
oathOtpSettings) Description
The OATH OTP settings.
Attributes
Plugin-Link
Mandatory
License-Tags
OathOtp
Assignable plugins
Auto Order Activation Letter (
autoOrderCredential) Description
Set this flag to true to automatically order an activation letter once this token is added to a user.
Attributes
Boolean
Optional
Default value
false
Auto Order For New Users (
autoOrderForNewUsers) Description
Set this flag to true to automatically order the credential if the user is created.
Attributes
Boolean
Optional
Default value
false
Identifier (
identifier) Description
Identifier for the credential. This is used as value in the authentication method field in the persistence layer. Make sure this value is the same (for the same credential) in all Airlock IAM components.
Make sure the identifier is unique among all configured token controllers.
The identifier is also used as key to translate the display name of this token controller. The key is assembled as follows: edituserpage.cred.XYZ.title (where XYZ is the identifier).
Attributes
String
Optional
License-Tags
OathOtp
Default value
OATH_OTP
Suggested values
OATH_OTP
Delete Properties With Credential (
deletePropertiesWithCredential) Description
Defines a list of context data properties that are considered to part of the credential data. The specified context data properties are deleted (set to "null") when the credential is deleted (in addition to the credential data field, the serial number, the letter attribute and the order flag).
Make sure, the underlying persister plugin is configured to persist the specified context data properties.
Make sure, the underlying persister plugin is configured to persist the specified context data properties.
Attributes
String-List
Optional
License-Tags
OathOtp
YAML Template (with default values)
type: OathOtpTokenController
id: OathOtpTokenController-xxxxxx
displayName:
comment:
properties:
autoOrderCredential: false
autoOrderForNewUsers: false
deletePropertiesWithCredential:
identifier: OATH_OTP
oathOtpSettings: