← Back to plugin index

Secret Questions Settings

Description
Secret Questions are a common way to check if a user is allowed to reset his password. This plugin centrally configures the details concerning set-up of secret answers and how to use them for recovery.

The 'questions' are part of this configuration, represented as resource keys. Their translation – the question as displayed to the user – are in the string resource files, like other translations.

In the set-up or provisioning phase a user answers some of the predefined 'secret questions'. These secret answers are persisted as secret-answer tokens in the IAM persistency model, so they can be verified later.

Type name
SecretQuestionsSettings
Class
com.airlock.iam.common.application.configuration.secretquestion.SecretQuestionsSettings
May be used by
Properties
Question Resource Keys (questionResourceKeys)
Description
List of resource keys of the available questions. Each key represents one question. If you remove a question (resource key) from this list, all answers to that question become invalid.

Ensure that no new question with the same key is introduced later. Any user's answer to the previous question would not match the new question.

The keys must contain a period "." somewhere to avoid name clashes in the REST API.

Attributes
String-List
Mandatory
Token Data Provider (tokenDataProvider)
Description
The provider for token data takes care of persisting the secret answers.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Hash Function Plugin (hashFunctionPlugin)
Description
It is recommended not to store the secret answers in plain text. The hash algorithm configured here is used to hash the answers.

NOTE: Some password hashes, such as SHA 256 Password Hash or Scrypt Password Hash, produce binary output. If one of these is used, make sure the persistence layer supports binary data in the hash field and the corresponding persistence plugins (e.g. Database User Store or Ldap Connector) are configured to treat hash values as binary values.
In case the persistence layer expects a string, encode the password hash by wrapping it with an encoder. To achieve this, use the Password Hash Configuration plugin and specify the hash function (such as Scrypt Password Hash) together with the desired encoder. We recommend using the Base64 Password Hash Encoder.

Attributes
Plugin-Link
Optional
Assignable plugins
Required Number Of Provisioned Answers (requiredNumberOfProvisionedAnswers)
Description
Defines how many questions a user has to answer during the provisioning phase. If not enough questions are answered yet, the user must answer additional questions upon login and the user cannot use Secret Questions for recovery.
Attributes
Integer
Optional
Default value
2
Allowed Number Of Attempts (allowedNumberOfAttempts)
Description
Defines the number of allowed failed attempts until a Secret answer token is blocked. When a question is answered correctly the counter on the specific answer-token will be reset. A blocked answer can be unblocked by an administrator.
Attributes
Integer
Optional
Default value
2
Normalization (normalization)
Description
Normalization is a string-transformation applied to answers before they are persisted, and before they are verified. Therefore, an answer can be accepted even if it has minor differences to the provisioned answer. Currently, the following options exist:
  • OFF:
    No normalization. Provisioned and challenged answers must match exactly.
  • TRIM:
    Removes whitespaces at the beginning and end of the answer string.
  • TRIM_CASEINSENSITIVE:
    Does the same as TRIM and additionally converts all characters to lower case.
  • TRIM_CASEINSENSITIVE_NOWHITESPACE:
    Does the same as CASEINSENSITIVE_TRIM and additionally removes all whitespace.
  • TRIM_CASEINSENSITIVE_NOWHITESPACE_NOSPECIALCHARS:
    Does the same as CASEINSENSITIVE_TRIM_NOWHITESPACE and additionally removes all non-word characters (all characters except letters, digits and the underscore).
Attributes
Enum
Optional
Default value
TRIM_CASEINSENSITIVE
Min Length (minLength)
Description
Defines the mininum length of an answer.
Attributes
Integer
Optional
Default value
2
Max Length (maxLength)
Description
Defines the maximum length of an answer.
Attributes
Integer
Optional
Default value
100
Number Of Challenge Questions (numberOfChallengeQuestions)
Description
Verifying if a user knows his provisioned secret answers involves two steps:
  1. Display some of the questions to the user (challenge).
  2. Check the user's answers to these questions.
This property defines the number of questions which are selected to challenge the user. If this field is empty, the challenge will show the "Required Number Of Provisioned Answers"
Attributes
Integer
Optional
Number Of Challenge Answers (numberOfChallengeAnswers)
Description
Defines how many of the questions from the challenge must be answered. A question is only unanswered if the answer string is empty.
Example: Show two questions to the user, but only one has to be answered.
Attributes
Integer
Optional
Answer Regex Pattern (answerRegexPattern)
Description
Regex pattern to check the given answer (after normalization).
Attributes
RegEx
Optional
Allow Admin Answer Check (allowAdminAnswerCheck)
Description
Allow admins to check answers of a user in the adminapp.
Attributes
Boolean
Optional
Default value
false
Duplicate Answers Forbidden (duplicateAnswersForbidden)
Description
Forbid the same answer for more than one question per user.
Attributes
Boolean
Optional
Default value
true
Check Using Latin1 Encoding (checkUsingLatin1Encoding)
Description

If enabled, answers containing special characters stored by IAM earlier than 6.3 are still accepted. This option does not have to be activated if all answers were set using IAM 6.3 or later or if all answers were set via webservices or REST.

To support legacy answers, those with special characters are additionally checked using their legacy encoding in latin1.

Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: SecretQuestionsSettings
id: SecretQuestionsSettings-xxxxxx
displayName: 
comment: 
properties:
  allowAdminAnswerCheck: false
  allowedNumberOfAttempts: 2
  answerRegexPattern:
  checkUsingLatin1Encoding: false
  duplicateAnswersForbidden: true
  hashFunctionPlugin:
  maxLength: 100
  minLength: 2
  normalization: TRIM_CASEINSENSITIVE
  numberOfChallengeAnswers:
  numberOfChallengeQuestions:
  questionResourceKeys:
  requiredNumberOfProvisionedAnswers: 2
  tokenDataProvider: