← Back to plugin index

Airlock Gateway Settings

Description
Configuration for Airlock Gateway (WAF) running in front of Airlock IAM. While active, IAM parses HTTP request environment cookies.
Type name
AirlockGateway
Class
com.airlock.iam.core.application.configuration.waf.AirlockGatewayConfig
May be used by
Properties
Add Credentials To Session (addCredentialsToSession)
Description
Usually, existing roles should be kept, i.e., the roles granted to a user in Airlock IAM should be added to the existing set of roles of an Airlock Gateway session. This is achieved by using the Airlock Control Cookie command ADD_CREDENTIALS. If every identity propagation shall replace all previously set roles, disable this property, which results in the Airlock Control Cookie command SET_CREDENTIALS.
Attributes
Boolean
Optional
Default value
true
Control Cookie Name (controlCookieName)
Description

The name of the control cookie used to communicate with the Airlock Gateway (WAF) backend control API. This must be the same as configured in Airlock.

A control cookie is set after successful authentication with the roles granted to the user as credentials/roles. Additionally, a new session ID is generated (to prevent session fixation attacks) and the global session ID is set as audit token.

This property also enables so-called "session tickets". After successful authentication the user's name and the granted roles are stored in the current session plus a session ticket cookie including this information is stored in the Airlock Gateway cookie store. The session ticket is needed to re-authenticate any new session later.

Attributes
String
Optional
Default value
AL_CONTROL
Environment Cookie Prefix (environmentCookiePrefix)
Description
The name of the prefix that Airlock Gateway (WAF) prepends to all environment cookies it sends to its backends. This must be the same as configured in Airlock Gateway. It is used to extract, for example, the client IP address or the client certificate.
Attributes
String
Optional
Default value
AL_ENV_
Audit Token (auditToken)
Description

Type of the audit token set in the Airlock Gateway (WAF) after the authentication.

  • "Username": The audit token contains just the username.
  • "SessionID": The audit token contains just the session id.
  • "Username and SessionID": The audit token contains the username followed by a "-" and the session ID.
  • "None": The audit token is empty.
Attributes
Enum
Optional
Default value
USERNAME
YAML Template (with default values)

type: AirlockGateway
id: AirlockGateway-xxxxxx
displayName: 
comment: 
properties:
  addCredentialsToSession: true
  auditToken: USERNAME
  controlCookieName: AL_CONTROL
  environmentCookiePrefix: AL_ENV_