← Back to plugin index

Cipher Token List Persister

Description

Encrypts and decrypts selected context data fields of token list data structure. Uses an underlying other token list persister plugin to load and store data, i.e. it is applicable to any other token list persister plugin.

Note that data that is not (yet) encrypted can be read as plaintext. The first time the field is written(because of a change in the very field itself), it will be encrypted. This makes migration of data and mixture with encrypted and non-encrypted data possible. It also implies that this encryption provides secrecy (confidentiality) but no authenticity!

The following restrictions apply when using data field encryption:

  • Encryption can only be applied to context data fields.
  • Encryption can only be applied to string type properties.
  • Encryption cannot be applied to the username (even if part of the context data container)
  • Searching on encrypted fields is not supported.
  • If encrypting a context data property that is also used by other persister plugins (e.g. a user persister plugin), make sure that the other plugin also encrypts the field.
  • Note that encrypted strings are larger than their plain counterpart. Make sure to allow long strings in the underlying persister plugin. The shortest encrypted string is 38 characters long. For longer strings, doubling the plain string length makes a good upper boundary.

Type name
CipherTokenListPersister
Class
com.airlock.iam.core.misc.impl.persistency.cipher.CipherTokenListPersister
May be used by
License-Tags
DataEncryption
Properties
Token List Persister (tokenListPersister)
Description
The underlying persister plugin used to load and store data.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Encrypted Context Properties (encryptedContextProperties)
Description

Specifies a list of names of string context data properties that have to be stored encrypted on the database.

Attributes
String-List
Mandatory
Cipher Password (cipherPassword)
Description

Password used for the encryption and decryption.

If other persister plugins (e.g. a UserPersister plugin) also use encryption on data fields encrypted in this plugin, make sure they use the same password.

This property supports the extended string syntax, i.e. its value may be configured scrambled or in an external file (see example values).

Attributes
String
Mandatory
Sensitive
YAML Template (with default values)

type: CipherTokenListPersister
id: CipherTokenListPersister-xxxxxx
displayName: 
comment: 
properties:
  cipherPassword:
  encryptedContextProperties:
  tokenListPersister: