Password Settings
Description
Settings related to handling passwords. Used by various components in Airlock IAM (Adminapp, RADIUS server etc.), but currently not in any Loginapp flows.
May be used by
Properties
Password Service (
passwordService) Description
Defines the password service plugin to be used for changing, resetting and checking user passwords.
This password service is used for the following:
- in the Adminapp for managing the user passwords
- in the "Password Authenticator" (typically in the RADIUS server)
- in the /<loginapp-uri>/rest/protected/my/password/change protected Loginapp REST endpoint
Attributes
Plugin-Link
Mandatory
Assignable plugins
Password Policy (
passwordPolicy) Description
Defines a password policy that must be passed when a new password is chosen (by the user or the administrator).
This password policy is used for the following:
- in the Adminapp for managing the user passwords
- in the /<loginapp-uri>/rest/public/password/policy/check public Loginapp REST endpoint
- in the RADIUS server
Attributes
Plugin-Link
Optional
Assignable plugins
Password Generator (
passwordGenerator) Description
Defines the generator plugin that produces random passwords. It is used for example to generate new passwords printed on letters or displayed in the Adminapp.
Attributes
Plugin-Link
Optional
Assignable plugins
May Be Selected As Auth Method (
mayBeSelectedAsAuthMethod) Description
Set this flag to true to allow password-authentication (i.e. only username and password, no additional credential) as active authentication method.
Attributes
Boolean
Optional
Default value
false
Admin May Generate Password (
adminMayGeneratePassword) Description
If enabled, the administrator may generate (and therefore see) new random passwords for the users.
Note that this settings can be overruled in the Password Credential Controller's settings (for backwards compatibility reasons).
Attributes
Boolean
Optional
Default value
false
Admin May Set Password (
adminMaySetPassword) Description
If enabled, the administrator may set (i.e. choose) new passwords for the users. The configured policy is applied.
Attributes
Boolean
Optional
Default value
false
New Passwords Must Be Changed (
newPasswordsMustBeChanged) Description
Normally, new passwords - set by the administrator or generated by the Adminapp - must be changed during the first login process. Disable this property in order to avoid the forced password change.
Attributes
Boolean
Optional
Default value
true
New Password Unlocks User (
newPasswordUnlocksUser) Description
If this flag is enabled, the (potentially locked) user is unlocked if a password is generated, set, or ordered.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)
type: PasswordSettings
id: PasswordSettings-xxxxxx
displayName:
comment:
properties:
adminMayGeneratePassword: false
adminMaySetPassword: false
mayBeSelectedAsAuthMethod: false
newPasswordUnlocksUser: false
newPasswordsMustBeChanged: true
passwordGenerator:
passwordPolicy:
passwordService: