← Back to plugin index

Cipher Credential Persister

Description

Encrypts and decrypts selected fields of credential data. Uses an underlying other credential persister plugin to load and store data, i.e. it is applicable to any other credential persister plugin.

Note that data that is not (yet) encrypted can be read as plaintext. The first time the field is written(because of a change in the very field itself), it will be encrypted. This makes migration of data and mixture with encrypted and non-encrypted data possible. It also implies that this encryption provides secrecy (confidentiality) but no authenticity!

The following restrictions apply when using data field encryption:

  • Encryption can only be applied to the serial number, the credential data and context data fields.
  • Encryption of context data properties can only be applied to string type properties.
  • Encryption cannot be applied to the username (even if part of the context data container)
  • Searching on encrypted fields is not supported.
  • If encrypting a context data property that is also used by other persister plugins (e.g. a user persister plugin), make sure that the other plugin also encrypts the field.
  • Note that encrypted strings are larger than their plain counterpart. Make sure to allow long strings in the underlying persister plugin. The shortest encrypted string is 38 characters long. For longer strings, doubling the plain string length makes a good upper boundary.

Type name
CipherCredentialPersister
Class
com.airlock.iam.core.misc.impl.persistency.cipher.CipherCredentialPersister
May be used by
License-Tags
DataEncryption
Properties
Credential Persister (credentialPersister)
Description
The underlying persister plugin used to load and store data.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Encrypt Serial (encryptSerial)
Description
Set to TRUE if the serial number of the credential should be encrypted.
Attributes
Boolean
Optional
Default value
false
Encrypt Credential Data (encryptCredentialData)
Description
Set to TRUE if the credential data of the credential should be encrypted.
Attributes
Boolean
Optional
Default value
true
Encrypted Context Properties (encryptedContextProperties)
Description

Specifies a list of names of string context data properties that have to be stored encrypted on the database.

Attributes
String-List
Mandatory
Cipher Password (cipherPassword)
Description

Password used for the encryption and decryption.

If other persister plugins (e.g. a UserPersister plugin) also use encryption on data fields encrypted in this plugin, make sure they use the same password.

This property supports the extended string syntax, i.e. its value may be configured scrambled or in an external file (see example values).

Attributes
String
Mandatory
Sensitive
YAML Template (with default values)

type: CipherCredentialPersister
id: CipherCredentialPersister-xxxxxx
displayName: 
comment: 
properties:
  cipherPassword:
  credentialPersister:
  encryptCredentialData: true
  encryptSerial: false
  encryptedContextProperties: