LDAP Password Authenticator
The plug-in uses a "technical" LDAP user to bind to the directory and search the user to check the password for. If the user can be found, a bind operation using the user's distinguished name (DN) and password is performed. If the bind operation succeeds, the password is considered to be correct.
The plugin may distinguish different types of authentication failures (e.g. "password wrong", "password change enforced") by looking at the error message returned by the LDAP directory. To use this feature, specify the corresponding configuration properties defining error message patterns (see list of LdapFailureMappers config property...). The default authentication failure (i.e. if no pattern is defined or none matches) is PASSWORD_WRONG.
This plug-in does only check the password and does not consider other user attributes, such as locked-flags or forced password change flags. To do this, use the
Because each password check is independent, this plug-in does not need authentication sessions.
This plugin also implements the PasswordService extension point, i.e. it can be used to reset or change a password in an LDAP directory.
If doing so, you must specify the password attribute name (property password-attribute).
Note that most LDAP directories require to connect using SSL (LDAPS) if setting passwords. If using a Microsoft Active Airectory as LDAP server, set the following properties:
- Set
Password AttributetoUnicodePwd. - Set
Active Directory Password EncodingtoTRUE. This will tell this plug-in that it has to deal with an MSAD and therefore set the password slightly different. (It encodes the new password specially for MSAD.)
The plugin writes the canonical class name description of this plugin to the context data container. The class name is stored under the key authPluginClassName . A short description of this authentication method is stored under the key authMethodShortDesc . This information may be used by callers.
connectionPool) searchContexts) bindDnTemplate) ${userId} for the username variable. Binding to the LDAP using this DN is done for both password checking and changing. If this property is empty, the user is first searched. searchFilter) The format and interpretation of filter follows RFC 2254.
searchAttrName) usernameConversionPattern) Regular expression pattern containing a group (a region embraced by parentheses) that can be used in conjunction with property "Username Conversion Replacement" in order to transform the username before it is used for searching the user in the directory. If the username does not match the pattern at all, no transformation is performed.
Example: The pattern "(.*)" and the replacement pattern "user.$1" will transform the username "jdoe" to "user.jdoe" before it is used in the directory.
Example: The pattern "user\.(.*)" and the replacement pattern "$1" will transform the username "user.jdoe" to "jdoe" before it is used in the directory.
usernameConversionReplacement) ldapFailureMappers) staticRoles) passwordAttribute) Note: This is required if the plugin is used for setting or changing passwords.
activeDirectoryPasswordEncoding) TRUE when using an active directory.
Note: This is only used if the plugin is used for setting or changing passwords.
activeDirectoryUnlockUserOnReset) activeDirectoryAccountControlOnReset) activeDirectoryCheckPasswordPoliciesForUserInitiatedModification) activeDirectoryResetPwdLastSetForUserInitiatedModification) constraintViolationResultCode) passwordModifyExtendedOperation)
type: LdapPasswordAuthenticator
id: LdapPasswordAuthenticator-xxxxxx
displayName:
comment:
properties:
activeDirectoryAccountControlOnReset: -1
activeDirectoryCheckPasswordPoliciesForUserInitiatedModification: true
activeDirectoryPasswordEncoding: false
activeDirectoryResetPwdLastSetForUserInitiatedModification: false
activeDirectoryUnlockUserOnReset: false
bindDnTemplate:
connectionPool:
constraintViolationResultCode: -1
ldapFailureMappers:
passwordAttribute:
passwordModifyExtendedOperation: false
searchAttrName:
searchContexts:
searchFilter:
staticRoles:
usernameConversionPattern:
usernameConversionReplacement: