Fallback Authenticator
Description
Combines two or more authenticator plugins in the way that the next authenticator in the list is tried if one fails to authenticate.
The reason of "failing" can be configured (see separate properties):
- Error during authentication process
- User not found
- User not valid (outside validity period or flagged as invalid)
- Credential not assigned
- Credential not active
- Authentication failed (e.g. password wrong)
In general, when switching to the next authenticator, the credential object (e.g. username and password) used with the first authenticator that led to the "failure" is used again with the next authenticator. A new session is obtained from the next authenticator. After trying all authenticators, the result from the last authenticator is returned regardless of its result.
Example usage: Use the reason "user not found" if it is not clear what system to authenticate against in case of multiple user directories.
May be used by
Properties
Authenticators (
authenticators) Description
List of authenticator plug-ins to be used. There must be at least one authenticator in the list.
Attributes
Plugin-List
Mandatory
Assignable plugins
Accepting Authenticator Active Directory Connector Airlock 2FA Authenticator Certificate Authenticator Certificate Token Authenticator Configuration-based Authenticator Credential-based Authenticator Selector Denying Authenticator Dummy Matrix Authenticator Dummy Polling Authenticator Dummy Two Step Authenticator Email Otp Authenticator Fallback Authenticator LDAP Connector LDAP Password Authenticator Lookup and Accept Authenticator MTAN/SMS Authenticator Main Authenticator Matrixcard Authenticator (TAN Challenge) Meta Authenticator NextGenPSD2 Certificate Authenticator OATH OTP Authenticator OAuth 2.0 Access Token Authenticator Password Authenticator RADIUS Authenticator SSO Credential Authenticator STET PSD2 Authenticator Selection Authenticator Static Authenticator Token Authenticator User-based Authenticator Selector
Failover On Error (
failoverOnAuthenticationError) Description
Enable to switch to the next authenticator if an unrecoverable error occurs.
Typical errors arise from unreachable databases or other dependent systems.
Attributes
Boolean
Optional
Default value
true
Failover If User Not Found (
failoverIfUserNotFound) Description
Enable to switch to the next authenticator if the previous returns "user not found".
Attributes
Boolean
Optional
Default value
true
Failover If User Not Valid (
failoverIfUserNotValid) Description
Enable to switch to the next authenticator if the previous returns "user not valid". This is the case if the user record has been flagged invalid or if the current point in time is outside the validity period of the account.
Attributes
Boolean
Optional
Default value
true
Failover If Credential Not Assigned (
failoverIfCredentialNotAssigned) Description
Enable to switch to the next authenticator if the previous returns "credential not assigned".
Attributes
Boolean
Optional
Default value
false
Failover If Credential Not Active (
failoverIfCredentialNotActive) Description
Enable to switch to the next authenticator if the previous returns "credential not active".
Attributes
Boolean
Optional
Default value
false
Failover If Authentication Fails (
failoverIfAuthenticationFails) Description
Enable to switch to the next authenticator on arbitrary authentication failures (e.g. password wrong).
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)
type: FallbackAuthenticator
id: FallbackAuthenticator-xxxxxx
displayName:
comment:
properties:
authenticators:
failoverIfAuthenticationFails: false
failoverIfCredentialNotActive: false
failoverIfCredentialNotAssigned: false
failoverIfUserNotFound: true
failoverIfUserNotValid: true
failoverOnAuthenticationError: true