Credential Data mTAN Handler
credentialPersister) perUserFlashContextField) If a context data field is configured, sending of flash messages is decided per user, based on the value in this field. If this field is empty, the default flash setting is used.
Important: The referenced context data field must be of type String and accepts only one of the following values:
true- send flash SMSfalse- send normal SMS<empty/null>- use the default flash settings
Note: The same configuration value must also be added to the credential persister's context data fields.
iakVerifier) The IAK verifier is used to check initial activation keys. It is only used during credential self-registration and not during credential self-migration.
CAUTION: Not specifying an IAK verifier plugin means that no IAK is checked during the self-registration process. Be careful to not create unsafe processes! Usually, self-registration is unsafe without IAK verification.
iakGenerator) iakHashFunction) NOTE: Some password hashes, such as SHA 256 Password Hash or Scrypt Password Hash, produce binary output. If one of these is used, make sure the persistence layer supports binary data in the hash field and the corresponding persistence plugins (e.g. Database User Store or Ldap Connector) are configured to treat hash values as binary values.
In case the persistence layer expects a string, encode the password hash by wrapping it with an encoder. To achieve this, use the Password Hash Configuration plugin and specify the hash function (such as Scrypt Password Hash) together with the desired encoder. We recommend using the Base64 Password Hash Encoder.
hashValueIsBinary) iakCredentialPersister)
type: CredentialDataMtanHandler
id: CredentialDataMtanHandler-xxxxxx
displayName:
comment:
properties:
credentialPersister:
hashValueIsBinary: false
iakCredentialPersister:
iakGenerator:
iakHashFunction:
iakVerifier:
perUserFlashContextField: