User Data Blacklist Password Policy
The items on the black-list - which will not be accepted as new password - must be part of the context data of the user or the username itself.
The plugin can be configured to either look at all context data or selected pieces of context data (see configuration properties below). The user name is handled separately.
Because birth dates (and other dates) are of special interest in this check, the configuration allows to specify one or more date-conversion patterns. If they are provided, the plugin converts any dates in the context data using all specified patterns when comparing them to the new password.
All pieces of context data that are not of type string and not of type date are converted to a string by calling the toString()-method on the object.
checkUserName) Note that this property does not depend on the selected context data items. Example: If the username is part of the context data and this property is FALSE, the username will be used nevertheless because it is part of context data.
selectedContextData) conversionPatterns) All dates or timestamps (everything with type java.util.Date or a subclass) in the context data is converted using all provided date-format patterns with this property.
The data-format patterns are as specified in JDK 1.6 Java class SimpleDateFormat.
ignoreCase) comparisonStrategy) - EQUALS: the policy triggers if user data exactly matches the password (default).
- CONTAINS: the policy triggers if the password contains user data.
type: PwdPolicyUserDataBlacklistCheck
id: PwdPolicyUserDataBlacklistCheck-xxxxxx
displayName:
comment:
properties:
checkUserName: true
comparisonStrategy: EQUALS
conversionPatterns:
ignoreCase: false
selectedContextData: