Matrixcard Authenticator (TAN Challenge)
This authenticator always authenticates in two steps:
In the first call a
In the second step, the answer to the challenge is expected: The credential instance must be of type
This authenticator takes its authentication decisions by calling the configured tan service.
The plugin writes the canonical class name description of this plugin to the context data container. The class name is stored under the key authPluginClassName . A short description of this authentication method is stored under the key authMethodShortDesc. This information may be used by callers.
tanService) tanListType) - INDEXED_LIST: A token list with an index next to each token. The tokens are queried in random order.
- MATRIX_CARD: A matrix card with the tokens organized in rows and columns. The tokens are queried in random order.
- TOKEN_LIST: (not recommended) A normal token list that is processed from left to right (or top to bottom, depending on used token list renderer). There are no indices on the list.
tokenListRenderer) This property is only required if TAN List Type is set to MATRIX_CARD.
startIndex) If the "TAN List Type" is not INDEXED_LIST, this property is ignored.
responseValidityMillis) The value 0 (zero) disables this feature, i.e. tokens never expire (this is the default).
maxRetries) newChallengeOnRetry) countUnansweredChallenges) If enabled, any pending challenge that is abandoned will be counted as an unanswered challenge. After too many unanswered challenges (see the "Max Unanswered Challenges" property), further attempts will always fail. This prevents an attacker from being able to "wait" for a specific challenge that has been leaked.
Important: This feature requires the fields 'Challenge Open Since' and 'Unanswered Challenges' on the Token List Persister to be configured, otherwise it will not work properly.
unansweredChallengeTimeout) maxUnansweredChallenges)
type: MatrixcardAuthenticator
id: MatrixcardAuthenticator-xxxxxx
displayName:
comment:
properties:
countUnansweredChallenges: true
maxRetries: 0
maxUnansweredChallenges: 3
newChallengeOnRetry: true
responseValidityMillis: 0
startIndex: 1
tanListType:
tanService:
tokenListRenderer:
unansweredChallengeTimeout: 12