Active Directory Connector
General Information
If a Microsoft Active Directory is used to manage the users, only this Plugin needs to be configured to handle the different user-related directory tasks. This MS AD connector implements the Airlock IAM Plugin interfaces: Authenticator, UserIterator, LicenseUserCounter, UserPersister, CredentialPersister, PasswordService, PasswordPolicy, and PasswordAuthenticator
- Only standard Active Directory user attributes are used. Therefore its not necessary to extend the schema.
- Active Directory features like recursive group membership, password policies and password histories are supported.
- Changing passwords is possible when the connection to the AD is secured using SSL/TLS.
- Multiple AD servers can be configured for failover or load balancing.
- Multiple "User Search Bases" and "Group Search Bases" can be specified.
This plugin works best with Microsoft Active Directory server 2008R2 and later.
Note on Stealth-Mode (Zero-Information Leakage)
This plugin provides "stealth" in the sense that it does not reveal information about the factor that prevented the successful login but it does not provide protection against denial of service attacks based on locking user accounts.
If used in conjunction with the "Stealth Mode" (see "Main Authenticator" plugin), it is strongly recommended to enable the "soft account lock" feature of this plugin (see property below).
Note on using this plugin only for password checks
When only using this plugin to check the user's password, additional features like role lookup or context data retrieval may not work as expected.
connectionPool) isReadOnly) If enabled, the Active Connector plugin does not write any data to the AD except for new passwords (changing and setting passwords can be disabled in the global password settings).
This allows using a service account user with only few privileges.
If enabled, the following data is not written to the AD (and therefore some features may not work as expected):
- Context data (e.g. changes to user's postal address)
- Credential data (e.g. change of mobile phone number)
- User unlocking (after password change or from the Adminapp)
- Enforcing password change (after setting a new password in the Adminapp)
Note that individual context attributes can be made read-only using the configuration property "Read-Only Attributes".
userIdAttributeName) credentialDataAttribute) The LDAP attribute with credential data (e.g. mobile phone number for mTAN/SMS authentication or email address for certificate validation).
If the same attribute is listed in the property "Binary Attributes", it will be treated as binary data, otherwise it is assumed to be UTF-8 string data.
This property is only required when an additional credential should be checked besides the password.
userSearchBases) The separate property "User Search Scope" controls whether users are only searched in the nodes defined by this property or in its subtrees as well.
userSearchScope) - ONE_LEVEL: Search users only in the specified "User Search Bases" - the subtree is ignored.
- SUBTREE: Search users recursively in the specified "User Search Bases" - considers the complete subtree.
- SUBORDINATE_SUBTREE: Search users recursively in the specified "User Search Bases" - considers the complete subtree from one level below the specified "User Search Bases" and ignores users directly in it.
- BASE: Only the exact entries in the specified "User Search Bases" are considered.
userSearchFilter) LDAP search filter expression applied when searching for users.
Note that this filter is automatically combined (logical AND) with a username filter based on the "Username Attribute".
The format and interpretation of filter follow RFC 2254.
Example 1 - Consider only entries with object class user: (objectCategory=user)
Example 2 - Consider only entries with object class person: (objectClass=person)
Example 3 - Consider only users in a specific group (no nested groups): (&(objectCategory=Person)(memberOf=cn=snakeOilDepartment,ou=groups,dc=company,dc=com))
Example 4 - Same as example 1 but considering nested groups: (&(objectCategory=Person)(memberOf:1.2.840.113556.1.4.1941:=cn=snakeOilDepartment,ou=groups,dc=company,dc=com))
usernameConversionPattern) Regular expression pattern containing a group (a region embraced by parentheses) that can be used in conjunction with property "Username Conversion Replacement" in order to transform the username before it is used for searching the user in the directory. If the username does not match the pattern at all, no transformation is performed.
Example: The pattern "(.*)" and the replacement pattern "user.$1" will transform the username "jdoe" to "user.jdoe" before it is used in the directory.
Example: The pattern "user\.(.*)" and the replacement pattern "$1" will transform the username "user.jdoe" to "jdoe" before it is used in the directory.
usernameConversionReplacement) groupSearchBases) Groups/roles are not searched if this property is not configured.
The separate property "Group Search Scope" controls whether groups are only searched in the nodes defined by this property or in its subtrees as well.
groupSearchScope) - ONE_LEVEL: Search groups only in the specified "Group Search Bases" - the subtree is ignored.
- SUBTREE: Search groups recursively in the specified "Group Search Bases" - considers the complete subtree.
- SUBORDINATE_SUBTREE: Search groups recursively in the specified "Group Search Bases" - considers the complete subtree from one level below the specified "Group Search Bases" and ignores groups directly in it.
- BASE: Only the exact entries in the specified "Group Search Bases" are considered.
groupSearchFilter) Note that this filter is automatically combined (logical AND) with a username filter based on the "Username Attribute".
The format and interpretation of filter follow RFC 2254.
resolveNestedGroups) Notice that in any case, only groups in the "Group Search Bases" will be found.
staticRoles) roleFilters) matchRolesCaseSensitive) useGroupsFromMemberOfAttribute) Note that nested roles can NOT be resolved via the memberOf attribute. This can only be done using the groups search. The role lookup through the memberOf attribute is readonly, as is the lookup through the groups search.
searchResultPageSize) If set to a value greater than zero and the Active Directory supports the SimplePaging control, "paging" is enabled for LDAP searches: This property defines the number of entries to fetch at once when searching in a directory.
This setting may be useful if the Active Directory limits the number of entries in a search result.
If the property is set to zero (the default) or if the server does not announce to support the SimplePaging control, paging is disabled
suppressSubstringSearch) This may greatly improve search performance in large directories.
softAccountLock) Lock users when they have more than the configured number of successive incorrect password checks on the AD. (E.g.: the value "2" means that 2 incorrect passwords are still OK).
If the number is smaller than the corresponding setting in AD, this allows "soft-locking" the account if accessed via Airlock IAM without actually locking the account on the AD. This feature may be used to prevent AD accounts from being locked by unsuccessful remote logins.
Note: if "Stealth Mode" is used (see "Main Authenticator" plugin), it is strongly recommended to enable this feature.
unlockUserOnPasswordReset) checkServersidePasswordPoliciesOnChange) If enabled the server side password policy is checked when a user changes or resets the password (not when an administrator sets one). This is for example useful to enforce advanced server-side policies like password histories.
Note that the AD might impose further password constraints (e.g. minimal length), that cannot be weakened or disabled with these settings.
contextDataAttributes) Notice: Context data attributes are string based. Values will be read as strings and are converted to string when written.
To prevent attributes from being changed by Airlock IAM/Login, add them also to the list of "Read-only Attributes".
Notice: The attributes "objectGUID" and "ImmutableID" are always considered read-only.
binaryAttributes) Those attributes are Base64 encoded for use in Airlock IAM/Login.
If the attribute name from "Credential Data Attribute" is also listed here, the credential data will be treated as binary.
readOnlyAttributes) realmAttribute) Setting this attribute is mandatory when using the Multi-Realm feature. The column specificied here must not also be in the list of Context Data Attributes.
userDNContextDataAttribute) This DN is in the format "uid=user,ou=People,dc=company,dc=ch"
userChangeEventListeners) domainDN) passwordSettingsContainerDN) userCountSearchFilter) Note: The user count is relevant for the product license. This filter should therefore describe the set of users who are able to authenticate through Airlock IAM.
adLdsMode)
type: ActiveDirectoryConnector
id: ActiveDirectoryConnector-xxxxxx
displayName:
comment:
properties:
adLdsMode: false
binaryAttributes:
checkServersidePasswordPoliciesOnChange: true
connectionPool:
contextDataAttributes:
credentialDataAttribute: mobile
domainDN:
groupSearchBases:
groupSearchFilter: (objectClass=group)
groupSearchScope: SUBTREE
isReadOnly: false
matchRolesCaseSensitive: true
passwordSettingsContainerDN:
readOnlyAttributes:
realmAttribute:
resolveNestedGroups: true
roleFilters:
searchResultPageSize: 1000
softAccountLock:
staticRoles:
suppressSubstringSearch: false
unlockUserOnPasswordReset: true
useGroupsFromMemberOfAttribute: false
userChangeEventListeners:
userCountSearchFilter:
userDNContextDataAttribute:
userIdAttributeName: sAMAccountName
userSearchBases:
userSearchFilter: (objectCategory=user)
userSearchScope: SUBTREE
usernameConversionPattern:
usernameConversionReplacement: