Dummy Two Step Authenticator
Description
Dummy authenticator expecting a credential with a username alone (UserCredential ) or a username and a password (UserPasswordCredential ) in the first authentication step. The reaction depends solely on the input (username or password).
This plugin can be used for testing and MUST NOT BE USED PRODUCTIVELY.
Note that all comparisons are done case-insensitive, i.e. NOT regarding case.
The responses are dependent on the credentials as follows:
- User "unknown" is unknown.
- User "ambiguous" is ambiguous.
- User "locked" is a locked user.
- User "invalid" is an invalid user.
- User "unspec" results in an unspecified authentication failure.
- User "exception" results in an authenticator exception being thrown.
- For user "mtan" no password is expected but a mtan code is required in the second step.
- For user "token" no password is expected but a token is required in the second step.
- For user "nexttoken" no password is expected but the next token will be requested.
- For user "index" no password is expected but a index-token challenge (with 3 challenges) is sent in the second step.
- For user "index1" no password is expected but a index-token challenge (with 1 challenge) is sent in the second step.
- For user "matrix" no password is expected but a matrix card challenge (with 3 challenges) is sent in the second step.
- For user "matrix1" no password is expected but a matrix card challenge (with 1 challenge) is sent in the second step.
- For user "smartcard" no password is expected but a string challenge is sent in the second step.
- For user "newpin" no password is expected but a new pin is required in the next step.
- For user "unassigned" the result is CREDENTIAL_NOT_ASSIGNED.
- All other users are valid users and a password is expected.
- The password "password" is accepted and no further steps are required.
- The password "step" or "pwstep" is accepted and leads to password-required in the second step.
- The password "mtan" is accepted and leads to a mtan code required in the second step.
- The password "token" is accepted and leads to token-required in the second step. The last used token is 123456.
- The password "nexttoken" is accepted and leads to next-token-required in the next step. The last used token is 123456.
- The password "index" is accepted and leads to an index-challenge (with 3 challenges) in the second step.
- The password "index1" is accepted and leads to an index-challenge (with 1 challenge) in the second step.
- The password "matrix" is accepted and leads to a matrix-challenge (with 3 challenges) in the second step.
- The password "matrix1" is accepted and leads to a matrix-challenge (with 1 challenge) in the second step.
- The password "smartcard" is accepted and leads to a string challenge in the second step.
- The password "newpin" is accepted and leads to a new pin being required in the second step.
- The password "pwdchange" or "pwch" is accepted but forces a password change.
- The password "usergotlocked" is considered to be wrong AND the user-got-locked flag is set.
- All other passwords are not accepted.
- Any value containing the string "accept" or "acpt" will be accepted as token and as response to the index-challenge and the matrix challenge.
- Any value containing the string "pwdchange" or "pwch" accepts the response and leads to forced password change.
- Any value containing the string "mtan" accepts the response and leads to requiring a mtan code.
- Any value containing the string "token" accepts the response and leads to requiring a token.
- Any value containing the string "nexttoken" accepts the response and leads to requiring a next token.
- Any value containing the string "matrix" accepts the response and leads to a matrix challenge.
- Any value containing the string "newpin" accepts the response and leads to requiring a new pin.
- Any value containing the string "index" accepts the response and leads to an index challenge.
- Any value containing the string "unspec" results in an unspecified authentication failure.
- Any value containing the string "except" results in an authenticator exception being thrown.
- All other values are not accepted.
If the authentication succeeds, the roles "role1" and "role2" are granted to the user.
The plugin writes the canonical class name description of this plugin to the context data container. The class name is stored under the key authPluginClassName . A short description of this authentication method is stored under the key authMethodShortDesc . This information may be used by callers.
May be used by
Administrators Configuration Meta Authenticator Meta Authenticator Meta Authenticator Persister Password Service Authenticator-based One-Shot Target Application User to Authenticator Mapping Authentication Method Identifier Mapping Fallback Authenticator Selection Authenticator Main Authenticator Auth Method-based Authenticator Selector Credential-based Authenticator Selector Credential to Authenticator Mapping Radius Authentication Service Roles-to-Authenticator Mapping Role-based Authenticator Selector User-based Authenticator Selector
Properties
Instance Name (
instanceName) Description
Used to distinguish one instance from another in unit tests.
Attributes
String
Optional
YAML Template (with default values)
type: DummyTwoStepAuthenticator
id: DummyTwoStepAuthenticator-xxxxxx
displayName:
comment:
properties:
instanceName: