← Back to plugin index

RADIUS Authenticator

Description

Authenticator that calls a RADIUS server to check credentials.

Note: If used as second step in a two-step authentication process, this plugin must ask for a token in the first step (before calling the RADIUS server). Please check the property "If Credential Is Missing" to enable this.

Stealth Mode Support: For unknown users this plugin will always ask for a token (OTP) and never use a different challenge type. Example: The RADIUS server always responds with a matrix challenge. Therefore the expected response would be a matrix challenge and the attacker - knowing the setup - knows that a user id does not exist, if asked for an OTP token.

Type name
RadiusAuthenticator
Class
com.airlock.iam.core.misc.impl.authen.RadiusAuthenticator
May be used by
Properties
Radius Servers (radiusServers)
Description
The RADIUS server(s) to talk to.
If more than one is provided, the list is used for failover.
Attributes
Plugin-List
Mandatory
Assignable plugins
If Credential Is Missing (ifCredentialIsMissing)
Description
Determines how the authenticator handles missing credentials.
  • Access-Reject: Rejects all requests with missing credential information.
  • Ask for token in first step: If the first credential does not encompass a token, the plugin prompts the user to enter a token before calling the RADIUS server. This is useful if this authenticator is used as second factor in an authentication process.
  • Send fixed password to RADIUS server: Sends the username and a fixed password to the RADIUS server. In such a case, the server is expected to respond with an Access-Challenge. This setting is useful if the Radius Authenticator is used as second step of a Main Authenticator.
Attributes
Enum
Optional
Default value
ACCESS_REJECT
NAS Identifier (nasIdentifier)
Description
The NAS-Identifier to set in all requests.
Attributes
String
Optional
Length >= 3
Static Roles (staticRoles)
Description
The set of roles granted to a user successfully authenticated using this authenticator.
Attributes
String-List
Optional
Access Reject Rules (accessRejectRules)
Description

Defines a list of rules (processed in order of definition) that define how to map RADIUS access reject response's reply messages to authentication results.

If no rules are defined or no rule matches, an unspecified authentication failure is used for access reject responses.
Attributes
Plugin-List
Optional
Assignable plugins
Access Challenge Rules (accessChallengeRules)
Description

Defines a list of rules (processed in order of definition) that define how to map RADIUS access challenge response's reply messages to authentication results.

If no rules are defined or no rule matches, an unspecified authentication failure is used for access challenge responses.
Attributes
Plugin-List
Optional
Assignable plugins
Access Accept Rules (accessAcceptRules)
Description

Configures rules that influence the authenticationr result in case of successful authentication ("AccessAccept").
This can be used for example to extract roles from the response.

Note: In contrast to the access challenge and access reject rules, all rules in the list are processed as long as the authentication result is successful.

Attributes
Plugin-List
Optional
Assignable plugins
Reported Auth Method (reportedAuthMethod)
Description
Defines how the RADIUS authentication process is reported in the log (used for auditing, information and statistics): It can be desirable to report the actual authentication process type used on the RADIUS server side.
If not defined, "RADIUS" will be used as Authentication Method.
Attributes
Enum
Optional
Default value
RADIUS
Log Radius Attributes (logRadiusAttributes)
Description
If enabled, the RADIUS attributes sent to the server and received from the server are logged at info level.
This is useful during integration and for debugging but it is generally not suitable for productive sytems.
Attributes
Boolean
Optional
Default value
false
Password And Token Usage (passwordAndTokenUsage)
Description
Airlock IAM supports login pages with username, password, and token input values. In this case all three values are available in this Radius authenticator. With this property, we can specify which information to use as secret attribute in the Radius protocol

Example:
password = pass
token = 1234

Result:
PASSWORD_ONLY = pass
TOKEN_ONLY = 1234
CONCATENATE = pass1234
Attributes
Enum
Optional
Default value
TOKEN_ONLY
Username Transformation (usernameTransformers)
Description
Transforms the login user name to the user name that is sent to the RADIUS server.
Attributes
Plugin-List
Optional
Assignable plugins
Encoding (encoding)
Description
The encoding for the RADIUS attributes in an authentication request. The encoding should be the same as used on the RADIUS server.
Attributes
String
Optional
Default value
UTF-8
Suggested values
UTF-8, ISO-8859-1, ISO-8859-15
YAML Template (with default values)

type: RadiusAuthenticator
id: RadiusAuthenticator-xxxxxx
displayName: 
comment: 
properties:
  accessAcceptRules:
  accessChallengeRules:
  accessRejectRules:
  encoding: UTF-8
  ifCredentialIsMissing: ACCESS_REJECT
  logRadiusAttributes: false
  nasIdentifier:
  passwordAndTokenUsage: TOKEN_ONLY
  radiusServers:
  reportedAuthMethod: RADIUS
  staticRoles:
  usernameTransformers: