← Back to plugin index

Meta Authenticator

Description
This authenticator combines two authenticators and presents them as one. It is can be used to combine for example username/password authentication with another authentication step.

First, the first authenticator is called. If authentication with the first authenticator succeeds (or only a password change is enforced), the second authenticator is called. The second authenticator can also depend on user data. Therefore a user dependent second authentication step can be achieved.
Example: Username and password verification in the first step and token verification in the second step for user A but challenge-response authentication for user B.

The first authenticator must be one that accepts credentials with a user name (UserCredential or subclass).
The second authenticator is then called for the first time with the credential that was passed to the first authenticator in the first step. This is always a credential with a user name.

The overall authentication is considered to be successful if (and only if) the first authentication step succeeds (or a password change is required) and the second authentication step succeeds. The resulting authentee returned with the successful authentication result is a combination of the results from both authenticators. The set of roles contains both roles from the first and the second authenticator. The context data container contains both the data from the first and the second authenticator. If a key in the context data container is used in both the results from the first and the second authenticators, then the value from the second authenticator's result overwrites the one from the first. If the first and the second authenticators provide a different user name in the authentee object, the one from the second authenticator is used.

Be careful when using authenticator plug-ins that automatically adjust user information after successful or failed authentication. If an authenticator, for example, resets the number of failed logins after successful authentication, it will not produce what you want when used as first authenticator. It would reset the number of failed logins even if the second authentication step fails. Most authenticators provided by Airlock IAM allow to turn off automatic used data updates for this purpose. Make sure to configure them accordingly when using them as part of a bigger authentication process with this plug-in.

Typical example application: Check username and password against a directory or database and then check a third credential (token, smart card, matrix card) with a separate, used-dependent authentication mechanism.

For the configured authenticator plugins used in the second step, a channel-prefix can be configured (optionally). If configured, this prefix is prepended to the current channel when loading the plugins. This is useful for example when two authentiators use the same plugin with different configuration sets or if the an authenticator plugin is used multiple times with a different configuration.

If a user persister is configured (this is mandatory if different second authenticator plugins are configured), it is also consulted to check whether the user is locked or if a password change is required after the first authenticator said ok. This is useful if the first authenticator does not support these concepts.

The plugin writes the canonical class name description (including packages) of the authenticator plugin used in the second step into the context data container of the authentication result. The information is written into the context data container as soon as the second authenticator is defined (i.e. after successful authentication with first authenticator). The class name is stored under the key authPluginClassName
A short description of the second authentication method (and only the second one) is stored under the key authMethodShortDesc . This information may be used by callers.

Type name
MetaAuthenticator
Class
com.airlock.iam.core.misc.impl.authen.MetaAuthenticator
May be used by
Properties
Second Authenticators By Auth Method (secondAuthenticatorsByAuthMethod)
Description
A map of auth method identifiers to authenticator plugins used in the second step.

All specified second authenticators must accept a credential with a username only (UserCredential) when called for the first time.

If no authenticator is found for the chosen method identifier the default second authenticator is used.

The key in the map corresponds to the authentication method identifier (e.g. "MTAN" or "EMAIL") which must be chosen identically in all Airlock IAM modules for each authentication method. Example values are:

  • PASSWORD
  • MATRIX
  • MTAN
  • OATH_OTP
  • CERTIFICATE
  • EMAILOTP
  • SECURID
  • SECOVID

Attributes
Plugin-Map
Optional
Assignable plugins
Second Authenticator Selector (secondAuthenticatorSelector)
Description
Optional property used to select the second authenticator from a list of authenticators (see properties "second.XXX") based on the context data of the user instead of the user's auth-method field. This property specifies the name of a context data value selecting the authenticator for the second authentication step. This property is now obsolete and exists to be backwards compatible with Airlock IAM releases before the introduction of the user's auth method field. If neither this property nor the user's auth method field is specified, the authenticator specified by property second is always used.
Attributes
String
Optional
Example
auth_method
User Persister (userPersister)
Description

The user persister used to update latest-login dates and number of failed logins (and some other fields if present).

This assumes that the first and the second authenticators do not update the information.

The persister is also used to the authentication method from the user to select the second authenticator plugin and to check whether the user is locked or a password change is enforced according to the persister.

Attributes
Plugin-Link
Optional
Assignable plugins
Max Failed Logins (maxFailedLogins)
Description
The number of failed logins before a user is locked. Set to zero (0) to disable this feature. This feature only works if a user persister is configured.
Attributes
Integer
Optional
Default value
5
Display Last Login Timestamp (displayLastLoginTimestamp)
Description
If enabled, displays the timestamp of the last login attempt and the information, whether it was successful or not. The information is displayed on the page of the second authentication step (if available).
Attributes
Boolean
Optional
Default value
false
Use Username From User Persister (useUsernameFromUserPersister)
Description
If enabled, the username from the credential is always replaced with the username of the persisted user. Only disable to support legacy use-cases.
Attributes
Boolean
Optional
Default value
true
Additional User Validators (additionalUserValidators)
Description
To validate users beyond the usual tests for being locked or invalid, additional plugins can be added, which e.g. check context data fields. This is only functional if a User Persister is configured.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: MetaAuthenticator
id: MetaAuthenticator-xxxxxx
displayName: 
comment: 
properties:
  additionalUserValidators:
  defaultSecondAuthenticator:
  displayLastLoginTimestamp: false
  first:
  maxFailedLogins: 5
  secondAuthenticatorSelector:
  secondAuthenticatorsByAuthMethod:
  useUsernameFromUserPersister: true
  userPersister: