Main Authenticator
This is used for simple username/password authentication or for combining a password authenticator with a second authentication step (e.g. mTAN, Cronto, OTP, matrix card, mobile app token, etc.).
first) second) userPersister) The user persister used to update latest-login dates and number of failed logins (and some other fields if present).
This assumes that the first and the second authentication steps do not update the information.
The persister is also used to check whether the user is locked or a password change is enforced. The persister does not load any roles; this must be performed by the enclosed authenticators.
enableStealthMode) Enables the "Stealth Mode": if enabled and the overall authentication process fails, the authentication process does not give away information about whether the first or the second factor was wrong.
This mode increases security by preventing attacks on passwords (since not even a small number of potential passwords can be tested for a given user) and prevents user enumeration under certain conditions (i.e. when the simulation of the second factor cannot be distinguished from the real authentication).
However, note that legitimate users get less information about what went wrong during the authentication process, which could lead to increased help desk demand.
Not all authenticaton steps support this mode.
maxFailedLogins) displayLastLoginTimestamp) useUsernameFromUserPersister) additionalUserValidators)
type: MainAuthenticator
id: MainAuthenticator-xxxxxx
displayName:
comment:
properties:
additionalUserValidators:
displayLastLoginTimestamp: false
enableStealthMode: false
first:
maxFailedLogins: 5
second:
useUsernameFromUserPersister: true
userPersister: