← Back to plugin index

Main Authenticator

Description
Standard Authenticator for Airlock IAM/Login.

This is used for simple username/password authentication or for combining a password authenticator with a second authentication step (e.g. mTAN, Cronto, OTP, matrix card, mobile app token, etc.).

Type name
MainAuthenticator
Class
com.airlock.iam.core.misc.impl.authen.MainAuthenticator
May be used by
Properties
First (first)
Description
The password authenticator for the first step.
Attributes
Plugin-Link
Mandatory
Assignable plugins
User Persister (userPersister)
Description

The user persister used to update latest-login dates and number of failed logins (and some other fields if present).

This assumes that the first and the second authentication steps do not update the information.

The persister is also used to check whether the user is locked or a password change is enforced. The persister does not load any roles; this must be performed by the enclosed authenticators.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Enable Stealth Mode (enableStealthMode)
Description

Enables the "Stealth Mode": if enabled and the overall authentication process fails, the authentication process does not give away information about whether the first or the second factor was wrong.

This mode increases security by preventing attacks on passwords (since not even a small number of potential passwords can be tested for a given user) and prevents user enumeration under certain conditions (i.e. when the simulation of the second factor cannot be distinguished from the real authentication).

However, note that legitimate users get less information about what went wrong during the authentication process, which could lead to increased help desk demand.

Not all authenticaton steps support this mode.

Attributes
Boolean
Optional
Default value
false
Max Failed Logins (maxFailedLogins)
Description
The number of failed logins before a user is locked. Set to zero (0) to disable this feature. This feature only works if a user persister is configured.
Attributes
Integer
Optional
Default value
5
Display Last Login Timestamp (displayLastLoginTimestamp)
Description
If enabled, displays the timestamp of the last login attempt and the information, whether it was successful or not. The information is displayed on the page of the second authentication step (if available).
Attributes
Boolean
Optional
Default value
false
Use Username From User Persister (useUsernameFromUserPersister)
Description
If enabled, the username from the credential is always replaced with the username of the persisted user. Only disable to support legacy use-cases.
Attributes
Boolean
Optional
Default value
true
Additional User Validators (additionalUserValidators)
Description
To validate users beyond the usual tests for being locked or invalid, additional plugins can be added, which e.g. check context data fields. This is only functional if a User Persister is configured.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: MainAuthenticator
id: MainAuthenticator-xxxxxx
displayName: 
comment: 
properties:
  additionalUserValidators:
  displayLastLoginTimestamp: false
  enableStealthMode: false
  first:
  maxFailedLogins: 5
  second:
  useUsernameFromUserPersister: true
  userPersister: