Secret Questions Settings
The 'questions' are part of this configuration, represented as resource keys. Their translation – the question as displayed to the user – are in the string resource files, like other translations.
In the set-up or provisioning phase a user answers some of the predefined 'secret questions'. These secret answers are persisted as secret-answer tokens in the IAM persistency model, so they can be verified later.
questionResourceKeys) Ensure that no new question with the same key is introduced later. Any user's answer to the previous question would not match the new question.
The keys must contain a period "." somewhere to avoid name clashes in the REST API.
tokenDataProvider) hashFunctionPlugin) NOTE: Some password hashes, such as SHA 256 Password Hash or Scrypt Password Hash, produce binary output. If one of these is used, make sure the persistence layer supports binary data in the hash field and the corresponding persistence plugins (e.g. Database User Store or Ldap Connector) are configured to treat hash values as binary values.
In case the persistence layer expects a string, encode the password hash by wrapping it with an encoder. To achieve this, use the Password Hash Configuration plugin and specify the hash function (such as Scrypt Password Hash) together with the desired encoder. We recommend using the Base64 Password Hash Encoder.
requiredNumberOfProvisionedAnswers) allowedNumberOfAttempts) normalization) - OFF:
No normalization. Provisioned and challenged answers must match exactly. - TRIM:
Removes whitespaces at the beginning and end of the answer string. - TRIM_CASEINSENSITIVE:
Does the same as TRIM and additionally converts all characters to lower case. - TRIM_CASEINSENSITIVE_NOWHITESPACE:
Does the same as CASEINSENSITIVE_TRIM and additionally removes all whitespace. - TRIM_CASEINSENSITIVE_NOWHITESPACE_NOSPECIALCHARS:
Does the same as CASEINSENSITIVE_TRIM_NOWHITESPACE and additionally removes all non-word characters (all characters except letters, digits and the underscore).
minLength) maxLength) numberOfChallengeQuestions) - Display some of the questions to the user (challenge).
- Check the user's answers to these questions.
numberOfChallengeAnswers) Example: Show two questions to the user, but only one has to be answered.
answerRegexPattern) allowAdminAnswerCheck) duplicateAnswersForbidden) checkUsingLatin1Encoding) If enabled, answers containing special characters stored by IAM earlier than 6.3 are still accepted. This option does not have to be activated if all answers were set using IAM 6.3 or later or if all answers were set via webservices or REST.
To support legacy answers, those with special characters are additionally checked using their legacy encoding in latin1.
type: SecretQuestionsSettings
id: SecretQuestionsSettings-xxxxxx
displayName:
comment:
properties:
allowAdminAnswerCheck: false
allowedNumberOfAttempts: 2
answerRegexPattern:
checkUsingLatin1Encoding: false
duplicateAnswersForbidden: true
hashFunctionPlugin:
maxLength: 100
minLength: 2
normalization: TRIM_CASEINSENSITIVE
numberOfChallengeAnswers:
numberOfChallengeQuestions:
questionResourceKeys:
requiredNumberOfProvisionedAnswers: 2
tokenDataProvider: