← Back to plugin index

Password Token Controller

Description
Token controller used to display password information, generate and set the password of a user.
Type name
PasswordTokenController
Class
com.airlock.iam.admin.application.configuration.password.PasswordTokenController
May be used by
Properties
Password Settings (passwordSettings)
Description
Defines the most commonly used password settings.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Auto Order Password (autoOrderPassword)
Description
Set this flag to true to automatically order a password when a new user is created.
Attributes
Boolean
Optional
Default value
false
Password Reset Self Service (passwordResetSelfService)
Description
Configures a plugin that allows an admin to trigger a password reset service for a user: an email will be sent to the user, containing a link to change the password. The corresponding password reset self-service must be configured in the Loginapp, where the process can be completed by the user.
Attributes
Plugin-Link
Optional
License-Tags
PasswordSelfService
Assignable plugins
Password Generator (passwordGenerator)
Description
If defined, the administrator may generate a new password for the user. Depending on the configuration of the generator, the generated password is displayed or a password renderer plugin is called in order to generate (and e.g. print) a password letter.
Attributes
Plugin-Link
Optional
Assignable plugins
Identifier (identifier)
Description

Identifier for the password credential. This is used as value in the authentication method field in the persistence layer. Make sure this value is the same (for password credentials) in all Airlock IAM components.

Make sure the identifier is unique among all configured token controllers.

The identifier is also used as key to translate the display name of this token controller. The key is assembled as follows: edituserpage.cred.XYZ.title (where XYZ is the identifier).

Attributes
String
Optional
Default value
PASSWORD
Suggested values
PASSWORD, PWD
User Store (userStore)
Description

The user store is used to read and write password information for each user (order flag, latest password change, information used for policy enforcement, etc.). This is usually the same user store that is used to load and write user detail information.

There are two ways to "store" new passwords:

  • Using a password service. This method is chosen if a password service is defined (in the Password Settings).
  • Using this user store: This method is chosen if no password service is defined.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Show Letter Attributes (showLetterAttributes)
Description
Enable this property to display the order flag and the password letter generation date.
Attributes
Boolean
Optional
Default value
true
YAML Template (with default values)

type: PasswordTokenController
id: PasswordTokenController-xxxxxx
displayName: 
comment: 
properties:
  autoOrderPassword: false
  identifier: PASSWORD
  passwordGenerator:
  passwordResetSelfService:
  passwordSettings:
  showLetterAttributes: true
  userStore: