← Back to plugin index

Dynamic Active Directory String Generator

Description
Dynamic Active Directory String Generator plugin can be used to generate random passwords or one time passwords. Passwords are generated based on a password policy retrieved from an Active Directory for a specific user.

A fixed pattern is used that will generate passwords based on the restrictions given by an Active Directory, i.e. a password must meet three out of the following four requirements:

  • Contains a lowercase character.
  • Contains an uppercase character.
  • Contains a special character.
  • Contains a number.
  • Type name
    DynamicActiveDirectoryStringGenerator
    Class
    com.airlock.iam.core.misc.impl.authen.DynamicActiveDirectoryStringGenerator
    May be used by
    Properties
    Password Policy (passwordPolicy)
    Description
    A freshly generated string will be checked by the policy stated here.

    Remark: The pattern must be able to construct strings that will be accepted by the policy.

    After the policy rejected 10'000 generated strings (for each string to create) the plugin gives up and throws a runtime exception. This should not occur in real-life, since during initialization of this plugin, 100 test strings are generated to ensure the compatibility of the pattern with the policy. During this initial check, only 200 rejections from the policy are allowed. This is a much harder constraint, than 10'000 allowed rejections afterwards when the plugin is used. Therefore in practice the probability of a failure after initialization of the plugin should be negligible.

    Attributes
    Plugin-Link
    Optional
    Assignable plugins
    YAML Template (with default values)
    
    type: DynamicActiveDirectoryStringGenerator
    id: DynamicActiveDirectoryStringGenerator-xxxxxx
    displayName: 
    comment: 
    properties:
      passwordPolicy: