Pattern-based Random String Generator
- The pattern may consist of multiple parts, where a part is either a fixed string or a random part.
- Random parts are defined by an alphabet and the number of characters.
- Characters are chosen from the alphabet with uniform distribution using a secure PRNG (random generator).
pattern) Pattern syntax:
pattern = fix_part | random_part [fix_part | random_part]*
random_part = {alphabet_name:number_of_characters}
fix_part = any_string_without_'{'
The alphabet_name refers either to a built-in alphabet (see below) or to a custom alphabet defined in the separate Alphabets property below.
Examples:
{digits:6} → 482913
OTP-{digits:4} → OTP-4821
{HEX:8} (with HEX defined in the custom Alphabets property below) → A9F03C1B
Built-in and ready-to-use alphabets are:
- "
digits" all decimal digits (i.e. the characters 0123456790) - "
lower26" standard alphabet with 26 lowercase letters (i.e. the characters abcdefghijklmnopqrstuvwxyz) - "
upper26" standard alphabet with 26 uppercase letters (i.e. the characters ABCDEFGHIJKLMNOPQRSTUVWXYZ) - "
alpha52" standard alphabet with 26 upper- and 26 lowercase letters (i.e. the characters ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz) - "
distinct" distinct standard characters: digits, upper- and lowercase letter without the hard to distinguish '0,O,1,l,I' (i.e. the characters 23456789abcdefghijkmnopqrstuvwxyzABCDEFGHJKLMNPQRSTUVWXYZ) - "
DISTINCT" distinct standard characters (with uppercase letters): digits and uppercase letter without the hard to distinguish '0,O,1,I' (i.e. the characters 23456789ABCDEFGHJKLMNPQRSTUVWXYZ) - "
extended" contains most of the characters visible on a computer keyboard without the hard to distinguish '0,O,1,l,I' (i.e. the characters +-.,:;$<>()[]{}%&!?/*@#=_23456789abcdefghijkmnopqrstuvwxyzABCDEFGHJKLMNPQRSTUVWXYZ)
NOTE: Characters in this pattern do not pass the input filter for tokens (OTP, SMS, and alike). Choose a different pattern for tokens or relax the corresponding pattern (in the Loginapp's security settings). Characters may be blocked by a WAF deny rule.
Using custom alphabets:
1. Define an alphabet in the Alphabets property below.
2. Reference it in the pattern using {alphabet_name:number_of_characters} where the is the key of the alphabet in the Alphabets property.
alphabets) How it works:
The map key defines the alphabet_name:number_of_characters.
The plugin (alphabet) defines the characters used for sampling during random generation.
The alphabet can then be referenced in the Pattern property above using {alphabet_name:number_of_characters}.
Example configuration:
Key (alphabet_name): HEX
Plugin: Alphabet with the following characters 0123456789ABCDEF
Example usage in the Pattern property above:
{HEX:8} → A9F03C1B
OTP-{HEX:6} → OTP-4F9A2C
passwordPolicy) A generated string can be checked against the configured password policy. The configured Pattern must generate strings that are accepted by the policies.
If generating a string fails 10'000 times because none of the candidates fulfills the password policies, a runtime exception is thrown. To minimize the probability of such a failure during operations, 100 test strings are generated before the initialization of the plugin to verify the compatibility of the pattern with the policies. During this initial check, only 200 rejections from policies are allowed to further minimize the probability of a failure later.
checkPolicyOnInitialize)
type: ExtendedStringGenerator
id: ExtendedStringGenerator-xxxxxx
displayName:
comment:
properties:
alphabets:
checkPolicyOnInitialize: true
passwordPolicy:
pattern: {distinct:8}