← Back to plugin index

Reply Message Access Challenge Rule

Description
Maps a RADIUS access challenge response's reply messages to a authentication result type.
Type name
ReplyMessageAccessChallengeRule
Class
com.airlock.iam.core.misc.impl.authen.radius.ReplyMessageAccessChallengeRule
May be used by
Properties
Pattern (pattern)
Description

The regular expression matched against the reply message of the RADIUS access challenge response.

To extract challenges from the reply messages, exactly one regular expression capture group must be present in the pattern.
Example reply message: "Challenge: G4"
Example pattern with capture group: "Challenge: (.+)"

Attributes
RegEx
Mandatory
Authentication Result (authenticationResult)
Description
Defines the authentication result when the reply message matches the configured pattern.

Attention: When using the "Authentication successful" result, please notice that obtaining additional roles from the response is not possible as it is with AccessAccept packets. Interpreting a challenge message as successful authentication result is a shortcut not usually intended by the RADIUS server.
However this can be useful especially when using an RSA ACE Server which requests another authentication step after successfully changing the PIN, which can be ignored by treating the "PIN Accepted." challenge as successful authentication.

Attributes
String
Mandatory
Allowed values
Password required, Password wrong, try again, Password change required, Token required, Token wrong, try again, Next token required, New PIN required, Authentication pending, Credential not assigned, Challenge: matrix, Challenge: index, Challenge: string, Authentication successful
YAML Template (with default values)

type: ReplyMessageAccessChallengeRule
id: ReplyMessageAccessChallengeRule-xxxxxx
displayName: 
comment: 
properties:
  authenticationResult:
  pattern: