Token Authenticator
This authenticator loads and initializes the specified token verifier plug-in and presents its functionality as an Authenticator.
There are two modes of operation:
- Stand-alone: In this mode, the authenticator can be used itself to authenticate users against a token verifier (e.g. an RSA/ACE server).
It expects the first credential type to be aUserTokenCredential and passes the username and the token value to the token verifier.
Note:This mode of operation is automatically selected when the type of credential passed in the first step of authentication isUserTokenCredential and does not contain a token. - Authentication-step: In this mode, the authenticator is used in conjunction with the
MetaAuthenticatoras second (or following) step in the authentication process. It thus expects a credential of typeUserCredentialwhen called first.
Note:This mode of operation is automatically selected when the type of credential passed in the first step of authentication isUserCredential
An authentication session is always required by this authenticator.
A credential persister plugin can be used (optionally) to translate the username presented to this plugin to an "internal" ACE-user. The username in the authentee object returned after successful authentication is always the one presented to this plugin and not the one on the ACE-Server.
In the case of successful authentication, the returned authentee consists of the username only.
The plugin writes the canonical class name description of this plugin to the context data container. The class name is stored under the key authPluginClassName . A short description of this authentication method is stored under the key authMethodShortDesc . This information may be used by callers.
tokenVerifier) credentialPersister) A credential bean is fetched with the username used with this plugin and the credential-data (string or binary) of the credential bean is used as ACE-user.
This property can be used if a mapping between the actual username and the ACE-username is used.
pin) The PIN can be defined as a static value or its value may be retrieved from a context-value field of a persisted credential. Latter case requires that a credential persister is configured. Prepend the value with the @-character to use it as a reference to a context-data field.
usePasswordAsPin) usePasswordAsToken)
type: TokenAuthenticator
id: TokenAuthenticator-xxxxxx
displayName:
comment:
properties:
credentialPersister:
pin:
tokenVerifier:
usePasswordAsPin: false
usePasswordAsToken: false