RADIUS Password Repository
Description
Password repository that verifies the password by calling a RADIUS server.
This repository can only be used for password checks, not for changing or setting a password.
May be used by
Password Reset Step Password Repository Mapping Password-only Authentication Step Mandatory Password Change Step Username Password Authentication Step Voluntary Password Change Step Selection Password Repository Password Change Self-Service Step Username Password with FIDO Authentication Step Default End-To-End Encryption Password Repository Set Password Step HTTP Basic Authentication Step User Self-Registration Flow
Properties
Radius Servers (
radiusServers) Description
The RADIUS server(s) to connect to. If more than one is provided, the list is used for failover.
Attributes
Plugin-List
Mandatory
Assignable plugins
Log Radius Attributes (
logRadiusAttributes) Description
If enabled, the RADIUS attributes sent to the server and received from the server are logged at INFO level. This is useful during integration and for debugging but it is generally not suitable for productive systems.
Attributes
Boolean
Optional
Default value
false
NAS Identifier (
nasIdentifier) Description
The NAS-Identifier to set in all requests. The NAS-Identifier can be used instead of an IP address to identify the client.
Attributes
String
Optional
Length >= 3
Username Provider (
usernameProvider) Description
Provides the username to be sent to the RADIUS server.
Attributes
Plugin-Link
Optional
Assignable plugins
Roles Attribute Type (
rolesAttributeType) Description
In case of a successful password check, roles can be extracted from the "Access Accept" response. The roles are expected as comma-separated list in this attribute type. If not configured or no attribute of the expected type is present, no roles are extracted.
The configured value can either be one of the predefined attribute types (name and ID) or an attribute ID (number > 0).
Attributes
String
Optional
Suggested values
Reply-Message (18), Vendor Specific (26), Filter-Id (11), Class (25), Unassigned (21)
Encoding (
encoding) Description
The encoding for the RADIUS attributes in an authentication request. The encoding should be the same as used on the RADIUS server.
Attributes
String
Optional
Default value
UTF-8
Suggested values
UTF-8, ISO-8859-1, ISO-8859-15
YAML Template (with default values)
type: RadiusPasswordRepository
id: RadiusPasswordRepository-xxxxxx
displayName:
comment:
properties:
encoding: UTF-8
logRadiusAttributes: false
nasIdentifier:
radiusServers:
rolesAttributeType:
usernameProvider: