Authenticator-based One-Shot Target Application
Defines how to authenticate HTTP requests based on the original HTTP request sent by the client (provided to IAM in various Airlock Gateway environment cookies).
The following actions are applied for each request:
- Credential Extraction: Extract credential from the HTTP request (e.g. a bearer token or a cookie).
- Authentication: Call specified authenticator with credential (e.g. verify JWT ticket).
- Error handling: If authentication failes, the specified error mapper defines how to respond (e.g. send 401 to client).
- Authorization: Assure roles required to access application/services are given after authentication.
- ID-Propagation: provide information about authenticated user to target application/service.
- Set Airlock Gateway (WAF) roles: provide credentials/roles to Airlock Gateway to allow request to pass to target application/service.
credentialExtractorFactory) authenticator) Validates the credential from the credential extractor in order to authenticate the HTTP request.
Note:
- Only non-interactive authentication steps (there is no way to interact with the HTTP client at this point - use the REST authentication API to do so if desired) may be configured.
- The authenticator must know how to handle the credential type provided by the credential extractor.
A common use-case is to verify JWT tokens issued by an upfront authentication process (as "Authorization Bearer" header):
- Extract bearer token from HTTP header (using the "HTTP Header Token Extractor (as SSO Credential)").
- Authenticate the request using the "Lookup and Accept Authenticator" or the "SSO Credential Authenticator".
failureResponses) identityPropagator) enableUserTrailLog) If enabled, a message is logged to the user trail log for every successful or unsuccessful authentication.
Caution: If the Airlock Gateway (WAF) is used in stateless mode, every single request may have to be authenticated by IAM due to missing roles. Hence, every request may generate a message in the user trail log depending on the Airlock Gateway configuration.
urlPattern) The first pattern (in the list of target applications) that matches the forward URL is used.
The matching is case-insensitive.
The URL pattern is ignored for the default target application.
useDifferentUsername) - The name of the context data field in which this username is stored. Note that this field needs to be made persistent via the User Persister.
- A fixed username (which is the same for all users). This should start with FIXED: followed by the username. E.g.: if the username is "admin", set this to "FIXED:admin".
- Leave this empty, if no username is required or the standard username should be used.
The resulting username can be transformed further by using the Username Transformation property.
usernameTransformation) These transformations are applied after the "Use Different Username" property.
useDifferentPassword) - If no password is required for this application: leave empty.
- If the user has (or can have) a different password at this application: The name of the context data field in which this password is to be stored. Remember that this field needs to be made persistent via the User Persister.
- If a fixed password is used that is the same for all users: Prefix with FIXED: followed by the password, e.g. "FIXED:123456".
- If the user's main password (i.e. the password used to login to Airlock IAM) is used: Leave the field empty, but see the notes below.
- The main password can only be used if the user was required to enter the password upon login. This is not the case for Kerbos and other SSO-Logins. In those cases, this option is not possible.
- Normally, the user's password is only available directly after login. If the user comes back to the Loginapp later, e.g. to access a different application, the password is normally not available anymore.
- If only one target application is configured, this should not be a problem, since the user only needs to be authenticated at the very beginning (directly after the authentication).
- If the user's password is needed for several target application, then it is has to be available every time the user wants to access another application in the same session. In this case, the password should be saved in the session ticket (see Security Settings).
passwordEncryptionMethod) Leave empty if the password is not encrypted (not recommended if the password is read from a context data field).
requiredRoles) The user needs at least one of the roles in order to get access to the application.
If no roles are configured, all authenticated users may access the application.
The user's roles may be transformed before being compared to this list using the Role Transformation Rules (see separate property).
If the user doesn't have any of these roles, the "Step-Up Authenticators" (in Authentication Settings) are consulted in order to find out whether they can be obtained using a Step-Up.
airlockGatewayRoles) The Airlock Gateway (WAF) roles that should be set when accessing this target application, instead of using the users roles as Gateway roles.
The name of the role can be followed by a colon and the idle timeout of the role in seconds, e.g. "myrole:300" sets the role "myrole" that will expire after 5 minutes of client inactivity.
With a second colon and a second number, the life-time can be set, e.g. "myrole:300:3600" will set the role "myrole" for a maximum of 1 hour, but it will also expire after 5 minutes of client inactivity.
Note: If you want to replace (instead of add) target application's Gateway roles in the session upon the first visit of each target application, you have to disable the "Add Credentials To Session" flag in the "Airlock Gateway (WAF) Settings" of the Login Application.
roleTransformationRules) propagatedRolesToDelete) propagatedRolesToKeep) propagatedRolesTransformationRules) propagatedRolesToAdd)
type: AuthenticatorBasedOneShotTargetApplication
id: AuthenticatorBasedOneShotTargetApplication-xxxxxx
displayName:
comment:
properties:
airlockGatewayRoles:
authenticator:
credentialExtractorFactory:
enableUserTrailLog: true
failureResponses:
identityPropagator:
passwordEncryptionMethod:
propagatedRolesToAdd:
propagatedRolesToDelete:
propagatedRolesToKeep:
propagatedRolesTransformationRules:
requiredRoles:
roleTransformationRules:
urlPattern:
useDifferentPassword:
useDifferentUsername:
usernameTransformation: