Email Otp Authenticator
The Email OTP Authenticator is an authenticator plug-in designed for an additional authentication step and also suitable for transaction verification.
The user receives an Email message containing a code. He has to provide this code for successful authentication.
The message template used to form the messages sent to the user is taken from the credential object passed in the first step. If no such template is available (or if the property "dont-use-credential-message" is TRUE) the message template is taken from the configuration of this plugin (see property "message-template").
Note: The Email OTP Authenticator should only be used as an additional step in an authentication process and not stand-alone.
Note: Emails are neither confidential nor authentic in any way (i.e. the user cannot be sure that the email is really from Airlock IAM and Airlock IAM cannot be sure that the email is delivered to the correct user). This must be considered regarding security. This authenticator is not to be used for high-security applications!
The plugin writes the canonical class name description of this plugin to the context data container. The class name is stored under the key authPluginClassName . A short description of this authentication method is stored under the key authMethodShortDesc . This information may be used by callers.
emailService) messageTemplate) Note: The template is used if no message template is available in the credential passed in the first authentication step or if the property "dont-use-credential-message" is set to TRUE.
The email message contains only the token if no template specified at all.
The string $TOKEN$ in the message template is mandatory and is replaced by the token.
If the message text is HTML code, you must set the property "message-template-is-html" to true.
In order to access our services, please provide the following security code: $TOKEN$
Your Airlock IAM Server
subject) messageTemplateIsHtml) ignoreTokenCase) true the case of characters is ignored when checking tokens. maxTokenRetransmissions) retransmitSameToken) true is less secure but helps avoiding erroneous user input when the initial token code is received before its retransmission. credentialPersister) tokenValidityMillis) The value 0 (zero) disables this feature, i.e. tokens never expire (this is the default).
maxTokenRetries) tokenGenerator)
type: EmailOtpAuthenticator
id: EmailOtpAuthenticator-xxxxxx
displayName:
comment:
properties:
credentialPersister:
emailService:
ignoreTokenCase: false
maxTokenRetransmissions: 0
maxTokenRetries: 0
messageTemplate: $TOKEN$
messageTemplateIsHtml: true
retransmitSameToken: false
subject:
tokenGenerator:
tokenValidityMillis: 0