Persister Password Service
This plugin allows the implementation of arbitrary password policies and supports password histories.
If the existing (current) password before the change is not correct, this plugin does increase the number of failed logins if "Maximum Wrong Old Passwords" is not 0.
The existing (current) password can be checked in two ways:
- Using the configured user store by comparing the stored password hash value to the recomputed hash value. This variant requires only the configuration of a hash function plugin (see property "Hash Function").
- Using a separate authenticator plugin called to verify the password. The specified authenticator plugin is called with a new authentication session and with the username and the password as credential. This variant requires the configuration of an authenticator plugin (see property "Password Check Authenticator") and a hash function plugin (see property "Hash Function").
userStore) The capabilities and the configuration of the user store influence the capabilities of this plugin. If, for example, the user store does not load or store information about the latest password change, this plugin will not be able to use this information.
passwordValidityDays) If a password is changed, this plugin sets the latest-password-change-timestamp and (if this property is defined) also updates the next-enforced-password-change-timestamp.
If this property is not defined, the next-enforced-password-change-timestamp is not updated.
hashFunction) Note that the password hash function may or may not support password history checks. If the configured password hash function does not support password history checks but a policy checker requires this capability, the history check is omitted and a log warning is written.
NOTE: Some password hashes, such as SHA 256 Password Hash or Scrypt Password Hash, produce binary output. If one of these is used, make sure the persistence layer supports binary data in the hash field and the corresponding persistence plugins (e.g. Database User Store or Ldap Connector) are configured to treat hash values as binary values.
In case the persistence layer expects a string, encode the password hash by wrapping it with an encoder. To achieve this, use the Password Hash Configuration plugin and specify the hash function (such as Scrypt Password Hash) together with the desired encoder. We recommend using the Base64 Password Hash Encoder.
passwordCheckAuthenticator) If this property is provided, the specified plugin is called with the username and password to verify the existing (current) password instead of loading the user data and comparing the password hashes (see also plugin description).
legacyHashFunctions) If the password cannot be verified using the main "Hash Function" above, all hashes in this list are tried as well. If any hash of this list matches, the password is stored using the current main hash function (see property "Hash Function"). In this case, a potential password history is lost.
This feature allows changing the password hash function with automatic migration of all users that log in.
Notice that having a legacy hash function in this list producing the same output length as the main hash function can pose a security risk since it might be possible for an attacker to provoke a match using a weaker hash method.
checkUsingLatin1Encoding) If enabled, passwords containing special characters stored by IAM earlier than 6.3 are still accepted. This option does not have to be activated if all passwords were set using IAM 6.3 or later or if all passwords were set via webservices or REST.
To support legacy passwords, those with special characters are additionally checked using their legacy encoding in latin1 and if matching, they are rehashed and stored using the current hash function. In this case, a potential password history is lost.
checkTruncatedPassword) If enabled, all failed checks on passwords longer than 50 characters will lead to a second check using only the first 50 characters. If successful, the full password is stored.
Prior to IAM 7.3 the password input field on JSPs was limited to 50 characters, with overflowing characters being truncated by the browser. This limit has been removed with IAM 7.3, leading to the full password being sent to IAM. For new installations with IAM 7.3 or later, this setting should not be enabled.
maximumWrongOldPasswords) Warning: Make sure that number of logins is not increased by the calling application, too.
Note: The number of failed logins is increased when providing a wrong password in a password change call. When only checking a wrong password, the number of failed logins is not increased.
type: PersisterPasswordService
id: PersisterPasswordService-xxxxxx
displayName:
comment:
properties:
checkTruncatedPassword: false
checkUsingLatin1Encoding: false
hashFunction:
legacyHashFunctions:
maximumWrongOldPasswords: 5
passwordCheckAuthenticator:
passwordValidityDays:
userStore: