← Back to plugin index

Token Authenticator

Description
Provides the functionality of a token verifier (TokenVerifier) as Authenticator plugin.

This authenticator loads and initializes the specified token verifier plug-in and presents its functionality as an Authenticator.

There are two modes of operation:

  • Stand-alone: In this mode, the authenticator can be used itself to authenticate users against a token verifier (e.g. an RSA/ACE server).
    It expects the first credential type to be a UserTokenCredential and passes the username and the token value to the token verifier.
    Note:This mode of operation is automatically selected when the type of credential passed in the first step of authentication is UserTokenCredential and does not contain a token.
  • Authentication-step: In this mode, the authenticator is used in conjunction with the MetaAuthenticator as second (or following) step in the authentication process. It thus expects a credential of type UserCredential when called first.
    Note:This mode of operation is automatically selected when the type of credential passed in the first step of authentication is UserCredential

An authentication session is always required by this authenticator.

A credential persister plugin can be used (optionally) to translate the username presented to this plugin to an "internal" ACE-user. The username in the authentee object returned after successful authentication is always the one presented to this plugin and not the one on the ACE-Server.

In the case of successful authentication, the returned authentee consists of the username only.

The plugin writes the canonical class name description of this plugin to the context data container. The class name is stored under the key authPluginClassName . A short description of this authentication method is stored under the key authMethodShortDesc . This information may be used by callers.

Type name
TokenAuthenticator
Class
com.airlock.iam.core.misc.impl.authen.TokenAuthenticator
May be used by
Properties
Token Verifier (tokenVerifier)
Description
Plugin class name of the token verifier.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Credential Persister (credentialPersister)
Description
Defines a credential persister plugin. If this property is defined, the configured credential persister plugin is used to look up the username used in communication with the ACE-server (the "ACE-user") given the username presented to this plugin:
A credential bean is fetched with the username used with this plugin and the credential-data (string or binary) of the credential bean is used as ACE-user.

This property can be used if a mapping between the actual username and the ACE-username is used.

Attributes
Plugin-Link
Optional
Assignable plugins
Pin (pin)
Description
If required, a PIN may be defined using this property. The specified PIN will be used together with the provided token code to authenticate the user. This may be useful if a PIN is associated to the token but you don't want the authenticating users to type it.

The PIN can be defined as a static value or its value may be retrieved from a context-value field of a persisted credential. Latter case requires that a credential persister is configured. Prepend the value with the @-character to use it as a reference to a context-data field.

Attributes
String
Optional
Sensitive
Example
1234
Example
secret
Example
@token_pin
Example
@securid_pin
Use Password As Pin (usePasswordAsPin)
Description
If set to TRUE the password of the credential is used as token PIN.
Attributes
Boolean
Optional
Default value
false
Use Password As Token (usePasswordAsToken)
Description
If set to TRUE the password is used as token. This mode cannot be used in conjunction with the "MetaAuthenticator".
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: TokenAuthenticator
id: TokenAuthenticator-xxxxxx
displayName: 
comment: 
properties:
  credentialPersister:
  pin:
  tokenVerifier:
  usePasswordAsPin: false
  usePasswordAsToken: false