← Back to plugin index

Credential Data mTAN Handler

Description
An mTAN handler that uses the credential data (in the user table of the IAM database). Supports only one mTAN number per user.
Type name
CredentialDataMtanHandler
Class
com.airlock.iam.core.misc.impl.authen.mtan.CredentialDataMtanHandler
May be used by
Properties
Credential Persister (credentialPersister)
Description
Credential persister to load the mobile phone number from user data.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Per User Flash Context Field (perUserFlashContextField)
Description

If a context data field is configured, sending of flash messages is decided per user, based on the value in this field. If this field is empty, the default flash setting is used.

Important: The referenced context data field must be of type String and accepts only one of the following values:

  • true - send flash SMS
  • false - send normal SMS
  • <empty/null> - use the default flash settings

Note: The same configuration value must also be added to the credential persister's context data fields.

Attributes
String
Optional
Suggested values
flashSms
IAK Verifier (iakVerifier)
Description

The IAK verifier is used to check initial activation keys. It is only used during credential self-registration and not during credential self-migration.

CAUTION: Not specifying an IAK verifier plugin means that no IAK is checked during the self-registration process. Be careful to not create unsafe processes! Usually, self-registration is unsafe without IAK verification.

Attributes
Plugin-Link
Optional
Assignable plugins
IAK Generator (iakGenerator)
Description
The string generator plugin which will generate the new IAKs.
Attributes
Plugin-Link
Optional
Assignable plugins
IAK Hash Function (iakHashFunction)
Description
This property is only used when new IAKs are generated. The hash function specifies how generated IAKs are hashed. It must be the same (or hash value compatible) to the one used for checking IAKs.

NOTE: Some password hashes, such as SHA 256 Password Hash or Scrypt Password Hash, produce binary output. If one of these is used, make sure the persistence layer supports binary data in the hash field and the corresponding persistence plugins (e.g. Database User Store or Ldap Connector) are configured to treat hash values as binary values.
In case the persistence layer expects a string, encode the password hash by wrapping it with an encoder. To achieve this, use the Password Hash Configuration plugin and specify the hash function (such as Scrypt Password Hash) together with the desired encoder. We recommend using the Base64 Password Hash Encoder.

Attributes
Plugin-Link
Optional
Assignable plugins
Hash Value Is Binary (hashValueIsBinary)
Description
Enable, if the hash value produced by the configured hash function is binary (and not a string). It will the be stored using the credential persisters "binary" data slot.
Attributes
Boolean
Optional
Default value
false
IAK Credential Persister (iakCredentialPersister)
Description
If immediate generation of IAK letters in the Admin Tool should be allowed, an IAK credential persister must be configured.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: CredentialDataMtanHandler
id: CredentialDataMtanHandler-xxxxxx
displayName: 
comment: 
properties:
  credentialPersister:
  hashValueIsBinary: false
  iakCredentialPersister:
  iakGenerator:
  iakHashFunction:
  iakVerifier:
  perUserFlashContextField: