← Back to plugin index

Certificate Token Authenticator

Description
Authenticator for client certificates (e.g. from smart cards or USB sticks) using the token model. This allows for more than one certificate per user.

Warning 1: This authenticator assumes that some external process can guarantee that the certificate belongs to the authenticating entity. This is typically done by challenging the entity to sign something with the corresponding private key. This is, for example, the case in an SSL handshake involving client certificate verification.

Warning 2: This authenticator does not check whether the certificate was signed by a trusted entity. This must be done prior to calling this authenticator, typically during an SSL handshake.

Type name
CertificateTokenAuthenticator
Class
com.airlock.iam.core.misc.impl.authen.certificate.CertificateTokenAuthenticator
May be used by
Properties
Certificate Matcher (certificateMatcher)
Description
Plugin to lookup the client certificate in the persistency layer or an external service.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Static Roles (staticRoles)
Description
A list of roles (role names, optionally followed by a colon and a role idle timeout in seconds) that are granted to authenticated users.
Attributes
String-List
Optional
Update User Statistics (updateUserStatistics)
Description
If the user statistics (last successful login, total logins) should be updated.
Attributes
Boolean
Optional
Default value
true
Update Token Statistics (updateTokenStatistics)
Description
If the token statistics (last usage, total usages) should be updated.
Attributes
Boolean
Optional
Default value
true
User Persister (userPersister)
Description
Class name of a user persister used after successful certificate verification and user extraction. The user is loaded from the persister in order to check the "locked" status and update statistics. In one of the following cases, the authentication fails (after successful certificate verification!):
  • User is not found
  • Username is ambiguous
  • User is locked
  • User is not valid
In the case of successful authentication, user data (roles, context data) is loaded and added to the result.
Attributes
Plugin-Link
Optional
Assignable plugins
Max Failed Logins (maxFailedLogins)
Description
The number of failed logins before a user is locked. Set to zero (0) to disable this feature. This feature only works if a user persister is configured.
Attributes
Integer
Optional
Default value
0
Expiring Certificate Warning Days (expiringCertificateWarningDays)
Description
This displays a warning page to the user if the client certificate is about to expire within the configured number of days.
Attributes
Integer
Optional
Additional User Validators (additionalUserValidators)
Description
To validate users beyond the usual tests for being locked or invalid, additional plugins can be added, which e.g. check context data fields. This is only functional if a User Persister is configured.
Attributes
Plugin-List
Optional
Assignable plugins
Check Validity Period (checkValidityPeriod)
Description
If enabled, the validity period of the certificate is checked. If disabled, expired (or not-yet-valid) certificates are also accepted.
Attributes
Boolean
Optional
Default value
true
Certificate Status Checkers (certStatusCheckers)
Description
A list of certificate status checkers used to check the revocation status of the client certificate. If more than one checker is configured, all of them are consulted and the certificate is considered revoked if at least one of them tells so.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: CertificateTokenAuthenticator
id: CertificateTokenAuthenticator-xxxxxx
displayName: 
comment: 
properties:
  additionalUserValidators:
  certStatusCheckers:
  certificateMatcher:
  checkValidityPeriod: true
  expiringCertificateWarningDays:
  maxFailedLogins: 0
  staticRoles:
  updateTokenStatistics: true
  updateUserStatistics: true
  userPersister: