← Back to plugin index

LDAP Password Authenticator

Description
Authenticator (and PasswordService plugin) checking (and setting) passwords against an LDAP directory (also Microsoft Active Directory).

The plug-in uses a "technical" LDAP user to bind to the directory and search the user to check the password for. If the user can be found, a bind operation using the user's distinguished name (DN) and password is performed. If the bind operation succeeds, the password is considered to be correct.

The plugin may distinguish different types of authentication failures (e.g. "password wrong", "password change enforced") by looking at the error message returned by the LDAP directory. To use this feature, specify the corresponding configuration properties defining error message patterns (see list of LdapFailureMappers config property...). The default authentication failure (i.e. if no pattern is defined or none matches) is PASSWORD_WRONG.

This plug-in does only check the password and does not consider other user attributes, such as locked-flags or forced password change flags. To do this, use the LdapUserPersister together with the PasswordServicePasswordAuthenticator.

Because each password check is independent, this plug-in does not need authentication sessions.

This plugin also implements the PasswordService extension point, i.e. it can be used to reset or change a password in an LDAP directory.
If doing so, you must specify the password attribute name (property password-attribute).
Note that most LDAP directories require to connect using SSL (LDAPS) if setting passwords. If using a Microsoft Active Airectory as LDAP server, set the following properties:

  • Set Password Attribute to UnicodePwd.
  • Set Active Directory Password Encoding to TRUE. This will tell this plug-in that it has to deal with an MSAD and therefore set the password slightly different. (It encodes the new password specially for MSAD.)

The plugin writes the canonical class name description of this plugin to the context data container. The class name is stored under the key authPluginClassName . A short description of this authentication method is stored under the key authMethodShortDesc . This information may be used by callers.

Type name
LdapPasswordAuthenticator
Class
com.airlock.iam.core.misc.impl.authen.ldap.LdapPasswordAuthenticator
May be used by
Properties
Connection Pool (connectionPool)
Description
The settings used to talk to the LDAP directory (or active directory).
Attributes
Plugin-Link
Mandatory
Assignable plugins
Search Contexts (searchContexts)
Description
Defines a list of search contexts (search trees with search levels) to use when looking for users. The search contexts are used in the defined order.
Attributes
Plugin-List
Mandatory
Assignable plugins
Bind Dn Template (bindDnTemplate)
Description
The DN (distinguished name) used to bind to the LDAP. Use ${userId} for the username variable. Binding to the LDAP using this DN is done for both password checking and changing. If this property is empty, the user is first searched.
Attributes
String
Optional
Example
uid=${userId},dc=users,dc=test.com
Additional Search Filter (searchFilter)
Description
The additional LDAP search filter expression used when searching the user to check the password for. This filter is automatically combined (by a logical and) with a username filter based on the Username Attribute name.

The format and interpretation of filter follows RFC 2254.

Attributes
Plugin-Link
Optional
Assignable plugins
Username Attribute (searchAttrName)
Description
The name of the attribute to match the user name against when looking for the user data.
Attributes
String
Mandatory
Suggested values
cn, sAMAccountName, userPrincipalName, uid
Username Conversion Pattern (usernameConversionPattern)
Description

Regular expression pattern containing a group (a region embraced by parentheses) that can be used in conjunction with property "Username Conversion Replacement" in order to transform the username before it is used for searching the user in the directory. If the username does not match the pattern at all, no transformation is performed.

Example: The pattern "(.*)" and the replacement pattern "user.$1" will transform the username "jdoe" to "user.jdoe" before it is used in the directory.

Example: The pattern "user\.(.*)" and the replacement pattern "$1" will transform the username "user.jdoe" to "jdoe" before it is used in the directory.

Attributes
RegEx
Optional
Username Conversion Replacement (usernameConversionReplacement)
Description
The replacement string used in conjunction with property "Username Conversion Pattern" in order to transform the username. The token "$1" is used to reference the string matching the group in the pattern. See property "Username Conversion Pattern" for examples.
Attributes
String
Optional
Example
user.$1
Example
$1
Ldap Failure Mappers (ldapFailureMappers)
Description
A list of plugins mapping ldap failure messages (exception message returned by the LDAP directory in case of bind failures) to authentication result types.
Attributes
Plugin-List
Optional
Assignable plugins
Static Roles (staticRoles)
Description
List of roles granted to authenticated users.
Attributes
String-List
Optional
Password Attribute (passwordAttribute)
Description
The LDAP attribute which holds the password.

Note: This is required if the plugin is used for setting or changing passwords.

Attributes
String
Optional
Suggested values
password, userPassword, unicodePwd
Active Directory Password Encoding (activeDirectoryPasswordEncoding)
Description
Optional flag telling the plug-in that is has to deal with a Microsoft Active Directory (MSAD). Set this property to TRUE when using an active directory.

Note: This is only used if the plugin is used for setting or changing passwords.

Attributes
Boolean
Optional
Default value
false
Active Directory Unlock User On Reset (activeDirectoryUnlockUserOnReset)
Description
If set to TRUE a password change will also unlock the user on Active Directory by resetting the lockoutTime.
Attributes
Boolean
Optional
Default value
false
Active Directory Account Control On Reset (activeDirectoryAccountControlOnReset)
Description
Optional flag telling the plug-in that it should set the MSAD attribute userAccountControl to the given value on reset. A value of -1 means that the userAccountControl attribute is not changed.
Attributes
Integer
Optional
Default value
-1
Active Directory Check Password Policies For User Initiated Modification (activeDirectoryCheckPasswordPoliciesForUserInitiatedModification)
Description
If set to TRUE the Active Directory server side password policy checks are enabled if the user resets or changes his password. This is useful to enforce advanced Active Directory server-side policies like password histories.
Attributes
Boolean
Optional
Default value
true
Active Directory Reset Pwd Last Set For User Initiated Modification (activeDirectoryResetPwdLastSetForUserInitiatedModification)
Description
Optional flag telling the plug-in that it should reset the MSAD attribute pwdLastSet to the current time when the user resets or changes his password.
Attributes
Boolean
Optional
Default value
false
Constraint Violation Result Code (constraintViolationResultCode)
Description
Optional LDAP result code value that should be treated as password constraint violation.
Attributes
Integer
Optional
Default value
-1
Use Password Modify Extended Operation (passwordModifyExtendedOperation)
Description
If enabled, an 'LDAP Password Modify Extended Operation' is used instead of a modify request to change or reset a user password. Please refer to RFC-3062 for further information.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: LdapPasswordAuthenticator
id: LdapPasswordAuthenticator-xxxxxx
displayName: 
comment: 
properties:
  activeDirectoryAccountControlOnReset: -1
  activeDirectoryCheckPasswordPoliciesForUserInitiatedModification: true
  activeDirectoryPasswordEncoding: false
  activeDirectoryResetPwdLastSetForUserInitiatedModification: false
  activeDirectoryUnlockUserOnReset: false
  bindDnTemplate:
  connectionPool:
  constraintViolationResultCode: -1
  ldapFailureMappers:
  passwordAttribute:
  passwordModifyExtendedOperation: false
  searchAttrName:
  searchContexts:
  searchFilter:
  staticRoles:
  usernameConversionPattern:
  usernameConversionReplacement: