← Back to plugin index

Persister Password Service

Description
A comprehensive password service plugin that operates directly on the configured user store plugin (exception: password check, see below).

This plugin allows the implementation of arbitrary password policies and supports password histories.

If the existing (current) password before the change is not correct, this plugin does increase the number of failed logins if "Maximum Wrong Old Passwords" is not 0.

The existing (current) password can be checked in two ways:

  1. Using the configured user store by comparing the stored password hash value to the recomputed hash value. This variant requires only the configuration of a hash function plugin (see property "Hash Function").
  2. Using a separate authenticator plugin called to verify the password. The specified authenticator plugin is called with a new authentication session and with the username and the password as credential. This variant requires the configuration of an authenticator plugin (see property "Password Check Authenticator") and a hash function plugin (see property "Hash Function").

Type name
PersisterPasswordService
Class
com.airlock.iam.core.misc.impl.authen.PersisterPasswordService
May be used by
Properties
User Store (userStore)
Description
The user store to verify and change passwords.

The capabilities and the configuration of the user store influence the capabilities of this plugin. If, for example, the user store does not load or store information about the latest password change, this plugin will not be able to use this information.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Password Validity Days (passwordValidityDays)
Description
The number of days a password may be used before it must be changed.

If a password is changed, this plugin sets the latest-password-change-timestamp and (if this property is defined) also updates the next-enforced-password-change-timestamp.

If this property is not defined, the next-enforced-password-change-timestamp is not updated.

Attributes
Integer
Optional
Hash Function (hashFunction)
Description
The password hash function used for verification and password change. This property is required if the existing (current) password should be checked directly using the user store plugin (see also plugin description above) and also when storing a new password.

Note that the password hash function may or may not support password history checks. If the configured password hash function does not support password history checks but a policy checker requires this capability, the history check is omitted and a log warning is written.

NOTE: Some password hashes, such as SHA 256 Password Hash or Scrypt Password Hash, produce binary output. If one of these is used, make sure the persistence layer supports binary data in the hash field and the corresponding persistence plugins (e.g. Database User Store or Ldap Connector) are configured to treat hash values as binary values.
In case the persistence layer expects a string, encode the password hash by wrapping it with an encoder. To achieve this, use the Password Hash Configuration plugin and specify the hash function (such as Scrypt Password Hash) together with the desired encoder. We recommend using the Base64 Password Hash Encoder.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Legacy Hash Functions (legacyHashFunctions)
Description

If the password cannot be verified using the main "Hash Function" above, all hashes in this list are tried as well. If any hash of this list matches, the password is stored using the current main hash function (see property "Hash Function"). In this case, a potential password history is lost.

This feature allows changing the password hash function with automatic migration of all users that log in.

Notice that having a legacy hash function in this list producing the same output length as the main hash function can pose a security risk since it might be possible for an attacker to provoke a match using a weaker hash method.

Attributes
Plugin-List
Optional
Assignable plugins
Check Using Latin1 Encoding (checkUsingLatin1Encoding)
Description

If enabled, passwords containing special characters stored by IAM earlier than 6.3 are still accepted. This option does not have to be activated if all passwords were set using IAM 6.3 or later or if all passwords were set via webservices or REST.

To support legacy passwords, those with special characters are additionally checked using their legacy encoding in latin1 and if matching, they are rehashed and stored using the current hash function. In this case, a potential password history is lost.

Attributes
Boolean
Optional
Default value
false
Check Truncated Password (checkTruncatedPassword)
Description

If enabled, all failed checks on passwords longer than 50 characters will lead to a second check using only the first 50 characters. If successful, the full password is stored.

Prior to IAM 7.3 the password input field on JSPs was limited to 50 characters, with overflowing characters being truncated by the browser. This limit has been removed with IAM 7.3, leading to the full password being sent to IAM. For new installations with IAM 7.3 or later, this setting should not be enabled.

Attributes
Boolean
Optional
Default value
false
Maximum Wrong Old Passwords (maximumWrongOldPasswords)
Description
The number of wrong old passwords during a password change before a user is locked.

Warning: Make sure that number of logins is not increased by the calling application, too.

Note: The number of failed logins is increased when providing a wrong password in a password change call. When only checking a wrong password, the number of failed logins is not increased.

Attributes
Integer
Optional
Default value
5
YAML Template (with default values)

type: PersisterPasswordService
id: PersisterPasswordService-xxxxxx
displayName: 
comment: 
properties:
  checkTruncatedPassword: false
  checkUsingLatin1Encoding: false
  hashFunction:
  legacyHashFunctions:
  maximumWrongOldPasswords: 5
  passwordCheckAuthenticator:
  passwordValidityDays:
  userStore: