← Back to plugin index

Email Otp Authenticator

Description

The Email OTP Authenticator is an authenticator plug-in designed for an additional authentication step and also suitable for transaction verification.

The user receives an Email message containing a code. He has to provide this code for successful authentication.

The message template used to form the messages sent to the user is taken from the credential object passed in the first step. If no such template is available (or if the property "dont-use-credential-message" is TRUE) the message template is taken from the configuration of this plugin (see property "message-template").

Note: The Email OTP Authenticator should only be used as an additional step in an authentication process and not stand-alone.

Note: Emails are neither confidential nor authentic in any way (i.e. the user cannot be sure that the email is really from Airlock IAM and Airlock IAM cannot be sure that the email is delivered to the correct user). This must be considered regarding security. This authenticator is not to be used for high-security applications!

The plugin writes the canonical class name description of this plugin to the context data container. The class name is stored under the key authPluginClassName . A short description of this authentication method is stored under the key authMethodShortDesc . This information may be used by callers.

Type name
EmailOtpAuthenticator
Class
com.airlock.iam.core.misc.impl.authen.EmailOtpAuthenticator
May be used by
Properties
Email Service (emailService)
Description
Email service plugin. This defines what mail server is used for sending the email. It also defines the sender address and whether the email should be signed or not.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Message Template (messageTemplate)
Description
Message template used to create the message text sent to the user.

Note: The template is used if no message template is available in the credential passed in the first authentication step or if the property "dont-use-credential-message" is set to TRUE.

The email message contains only the token if no template specified at all.

The string $TOKEN$ in the message template is mandatory and is replaced by the token.
If the message text is HTML code, you must set the property "message-template-is-html" to true.

Attributes
String
Optional
Multi-line-text
Default value
$TOKEN$
Example
Authentication Code

In order to access our services, please provide the following security code: $TOKEN$

Best Regards,
Your Airlock IAM Server
Subject (subject)
Description
The subject used in the email.
Attributes
String
Mandatory
Example
Security Code for Login
Message Template Is HTML (messageTemplateIsHtml)
Description
Set to true if the message template is HTML code.
Attributes
Boolean
Optional
Default value
true
Ignore Token Case (ignoreTokenCase)
Description
If set to true the case of characters is ignored when checking tokens.
Attributes
Boolean
Optional
Default value
false
Max Token Retransmissions (maxTokenRetransmissions)
Description
Maximum number of times a token may be retransmitted during one authentication process. Authentication is aborted if this limit is exceeded. Token retransmissions are disabled if this value is 0. Restricting this value to a small number prevents the abusive use of email delivery.
Attributes
Integer
Optional
Default value
0
Retransmit Same Token (retransmitSameToken)
Description
If token retransmissions are enabled this sets whether the same token code should be retransmitted or whether a new code should be generated for each retransmission. Setting this property to true is less secure but helps avoiding erroneous user input when the initial token code is received before its retransmission.
Attributes
Boolean
Optional
Default value
false
Credential Persister (credentialPersister)
Description
Credential persister to load additional user data, in this case the email address of the specific user.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Token Validity Millis (tokenValidityMillis)
Description
The number of milliseconds a token is valid for. If the token is entered correctly but after its expiration, authentication will fail. (TOKEN_EXPIRED).

The value 0 (zero) disables this feature, i.e. tokens never expire (this is the default).

Attributes
Long
Optional
Default value
0
Max Token Retries (maxTokenRetries)
Description
The number of times the user may enter a wrong token before the authentication process is aborted (and the token gets useless). If set to zero (the default), only one attempt is possible for each token. This is more secure but may increase costs (if sending a token is costly) and decrease usability.
Attributes
Integer
Optional
Default value
0
Token Generator (tokenGenerator)
Description
The string generator plugin which will generate the one time password token.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: EmailOtpAuthenticator
id: EmailOtpAuthenticator-xxxxxx
displayName: 
comment: 
properties:
  credentialPersister:
  emailService:
  ignoreTokenCase: false
  maxTokenRetransmissions: 0
  maxTokenRetries: 0
  messageTemplate: $TOKEN$
  messageTemplateIsHtml: true
  retransmitSameToken: false
  subject:
  tokenGenerator:
  tokenValidityMillis: 0