← Back to plugin index

Basic Secret Question Settings

Description
Configures common settings for secret questions. It is recommended to use the same settings for provisioning, administration and password reset.
Type name
BasicSecretQuestionSettings
Class
com.airlock.iam.common.application.configuration.secretquestion.BasicSecretQuestionSettings
May be used by
Properties
Question Resource Keys (questionResourceKeys)
Description
List of resource keys of the available questions. Each key represents one question. Removing a question (resource key) from this list, causes all answers to that question to become invalid.

Ensure that no new question with the same key is introduced later. Any user's answer to the previous question would not match the new question.

Attributes
String-List
Mandatory
Number of Questions (numberOfQuestions)
Description
This property defines the number of questions which have to be provisioned and answered.
Attributes
Integer
Optional
Default value
2
Normalization (normalization)
Description
Normalization is a string-transformation applied to answers before they are persisted, and before they are verified. Therefore, an answer can be accepted even if it has minor differences to the provisioned answer. Currently, the following options exist:
  • OFF:
    No normalization. Provisioned and challenged answers must match exactly.
  • TRIM:
    Removes whitespaces at the beginning and end of the answer string.
  • TRIM_CASEINSENSITIVE:
    Does the same as TRIM and additionally converts all characters to lowercase.
  • TRIM_CASEINSENSITIVE_NOWHITESPACE:
    Does the same as CASEINSENSITIVE_TRIM and additionally removes all whitespace.
  • TRIM_CASEINSENSITIVE_NOWHITESPACE_NOSPECIALCHARS:
    Does the same as CASEINSENSITIVE_TRIM_NOWHITESPACE and additionally removes all non-word characters (all characters except letters, digits and the underscore).
Attributes
Enum
Optional
Default value
TRIM_CASEINSENSITIVE
Token Data Provider (tokenDataProvider)
Description
The provider for token data for persisting the secret answers.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Hash Function Plugin (hashFunctionPlugin)
Description
This hash algorithm is used to hash the answers.

NOTE: Some password hashes, such as SHA 256 Password Hash or Scrypt Password Hash, produce binary output. If one of these is used, make sure the persistence layer supports binary data in the hash field and the corresponding persistence plugins (e.g. Database User Store or Ldap Connector) are configured to treat hash values as binary values.
In case the persistence layer expects a string, encode the password hash by wrapping it with an encoder. To achieve this, use the Password Hash Configuration plugin and specify the hash function (such as Scrypt Password Hash) together with the desired encoder. We recommend using the Base64 Password Hash Encoder.

Attributes
Plugin-Link
Optional
Assignable plugins
Min Length (minLength)
Description
Defines the minimum length of an answer.
Attributes
Integer
Optional
Default value
2
Max Length (maxLength)
Description
Defines the maximum length of an answer.
Attributes
Integer
Optional
Default value
100
Answer Regex Pattern (answerRegexPattern)
Description
Regex pattern to check the given answer (after normalization).
Attributes
RegEx
Optional
Duplicate Answers Forbidden (duplicateAnswersForbidden)
Description
Forbid the same answer for more than one question per user.
Attributes
Boolean
Optional
Default value
true
Check Using Latin1 Encoding (checkUsingLatin1Encoding)
Description

If enabled, answers containing special characters stored by IAM earlier than 6.3 are still accepted. This option does not have to be activated if all answers were set using IAM 6.3 or later or if all answers were set via webservices or REST.

To support legacy answers, those with special characters are additionally checked using their legacy encoding in latin1.

Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: BasicSecretQuestionSettings
id: BasicSecretQuestionSettings-xxxxxx
displayName: 
comment: 
properties:
  answerRegexPattern:
  checkUsingLatin1Encoding: false
  duplicateAnswersForbidden: true
  hashFunctionPlugin:
  maxLength: 100
  minLength: 2
  normalization: TRIM_CASEINSENSITIVE
  numberOfQuestions: 2
  questionResourceKeys:
  tokenDataProvider: