← Back to plugin index

LDAP Connector

Description

Provides the following services by connecting to an LDAP directory (for MS Active Directory, please use the Active Directory Connector plugin):

Main Features

  • LDAP directory as user data repository (User Store)
  • LDAP directory as password service (check password, reset password, change password)
  • LDAP directory as simple token storage for one user-related token (e.g. for mobile number – not recommended: requires schema extension and provides limited support)

Requirements on Directory Schema

  • For the basic features, users should have object class inetOrgPerson. More limited usage is possible with organizationalPerson and even Person.
  • All attribute names are configurable. Therefore, custom schemas are supported as long as all user data is stored as attributes in one directory entry (except for roles/groups).
  • To use all features of this plugin, custom attributes are required. Please refer to the Airlock IAM documentation page "Generic LDAP directories for IAM" for more information.
    For details about the meaning of an attribute, please refer to the corresponding attribute setting's help in this plugin.
    Depending on the configured attributes, more or fewer features can be used.
  • User roles/groups can be read from the following:
    • From a user attribute with one or more values (see "Roles Attribute"). RDNs can be extracted from DNs stored in this attribute. This set of roles can also be written.
    • Roles can be looked up in other directory trees (e.g. groups subtree) by configuring the corresponding query, search depth and filters.
    • Nested/hierarchical roles are supported.

How Users are found
For all operations (load, store user, check password, change password, etc.), this plugin first looks up the user entry in the directory using the service account specified in the connection pool settings.
Multiple search trees can be specified in order to limit the search space (and therefore improve performance) when users are stored in multiple subtrees.

Reading / Writing Credential Information
This plugin only provides very limited features for reading / writing credential information: It only reads and writes a single attribute stored as user attribute (see "Credential Data Attribute").
It can be used, for example, to use the mobile phone number authentication token (for 2-factor authentication).
The plugin does not support token order flags, serial numbers, delivery dates, and alike. Please use a relational database instead for more features.

Differences to "LDAP Password Authenticator"
This plugin offers all features of the "LDAP Password Authenticator". Whereas the "LDAP Password Authenticator" only checks or sets the password, this plugin also considers user information such as:
  • Locked flag
  • User validity attributes
  • Failed logins counter
  • Password change enforced flag
  • Password expiry date
  • etc.
The user information is also updated unless "Update Login Statistics" is disabled.

Read-only Attributes and Operational Attributes
In the property "Read-only Attributes", attributes can be defined that are only read and never written by this plugin. This works not only for context data attributes but for all attributes potentially written by this plugin.
This enables the plugin to read operational attributes and use them in authentication or password management: some directories provide automatically updated operational attributes (e.g. latest password change) that may be read but not be written by LDAP clients. They can be configured in the corresponding attribute settings and put in the list of read-only attributes.
NOTE: Some directories do not provide operational attributes to LDAP clients and always return empty values when read using LDAP.

Limitation of Usage
Unlike the "LDAP User Persister", this plugin is not able to read the password hash from the directory. It can therefore not be used with a custom schema where the password hash is computed in Airlock IAM and only stored (and read) by this plugin.

Note on using this plugin only for password checks
When only using this plugin to check the user's password, additional features like role lookup or context data retrieval may not work as expected.

Type name
LdapConnector
Class
com.airlock.iam.core.misc.impl.persistency.ldap.LdapConnector
May be used by
Email User Profile Item Certificate Data Extractor Task Certificate Data Extractor Task User Store Configuration User Store Configuration Basic Auth Request Authentication Combining User Persister Email Notification Task Email Notification Task Destroy Last User Session Lock Expired Initial Passwords Task Lock Expired Initial Passwords Task Administrators Configuration Administrators Configuration Custom User Persister-based User Store Provider Cronto Report Strategy Delete Users Task Delete Users Task Admin SSO Ticket Request Authentication User Persister-based User Store XML File Importer Task OATH OTP Settings Credential Secret Batch Task Credential Secret Batch Task Airlock 2FA Activation Letter Task Meta Authenticator Meta Authenticator Meta Authenticator Meta Authenticator OAuth 2.0 Token Request Authentication Email Notifier Self Reg Users Clean Up Task Self Reg Users Clean Up Task User to Password Service Mapping User to Password Service Mapping OAuth 2.0/OIDC Authorization Server Token Data mTAN Handler Extended User Persister-based User Store Provider OATH OTP Letter Task New Email Clean-up Strategy Vasco Letter Generator Persister Password Service Persister Password Service Authenticator-based One-Shot Target Application User Persister Email Certificate Provider Password Batch Task Password Batch Task HTTP Password Service Static Request Authentication Unique Across Services Password Policy Password Settings Self Reg Users Reminder Task Self Reg Users Reminder Task Composite Password Service Composite Password Service Composite Password Service Secret Questions Token Controller Certificate Authenticator Certificate Authenticator User-based Password Service Selector User to Authenticator Mapping Combining Extended User Persister Combining Extended User Persister User Persister Configuration User Persister Configuration User Persister Configuration Administrators Management Token Authenticator Credential Report Task Credential Report Task Cipher User Persister String User Profile Item Credential-based Generic Token Repository mTAN IAK Token Report Strategy Fallback Authenticator Lock Inactive Accounts Task Lock Inactive Accounts Task Context Data Username Transformer Token Activation On Delivery Strategy Service Container Primary Key Lookup Has Email Address Password Authenticator Selection Authenticator Main Authenticator Main Authenticator Auth Method-based Authenticator Selector User Sync Task User Sync Task Extended String User Profile Item Certificate Token Authenticator Integer User Profile Item Vasco Token Report Strategy Transaction Approval Cipher Credential Persister Persister IAK Verifier SSO Ticket Request Authentication Email Otp Authenticator Data Sources Radius Authentication Service Radius Authentication Service Lookup and Accept Authenticator SMS Notifier Role-based Authenticator Selector Credential Data mTAN Handler Credential Data mTAN Handler Export Users Task Export Users Task LDAP Password Repository Airlock 2FA Authenticator Password Token Controller Credential Data Certificate Matcher Loginapp Legacy Email OTP Authentication Step Client Certificate (X.509) Request Authentication User-based Authenticator Selector
Properties
Connection Pool (connectionPool)
Description
The connection pool connecting to the LDAP directory (or active directory).
Attributes
Plugin-Link
Mandatory
Assignable plugins
Username Attribute (usernameAttribute)
Description
The LDAP attribute which holds the user id.
Attributes
String
Mandatory
Suggested values
uid, cn, mail
Credential Data Attribute (credentialDataAttribute)
Description
The LDAP attribute with credential data (e.g. mobile phone number for MTAN/SMS authentication or email address for certificate validation). It is supposed to be UTF-8 string data.
Attributes
String
Optional
Suggested values
mobile, mail
User Container Nodes (userContainerNodes)
Description
Defines a list of search contexts (search trees with search levels) to use when looking for users. The search contexts are used in the defined order.
Attributes
String-List
Mandatory
User Search Scope (userSearchScope)
Description
Specifies whether the search should also recurse down the subtrees of the user container nodes or only the direct children nodes of the user container nodes should be searched.
Attributes
Enum
Optional
Default value
subtree
User Search Filter (userSearchFilter)
Description
The additional LDAP search filter expression used when searching the users.
The format and interpretation of filter follows RFC 2254.
Attributes
String
Optional
Multi-line-text
Default value
(objectClass=inetOrgPerson)
Example
(objectClass=inetOrgPerson)
Example
(objectClass=organizationalPerson)
Example
(objectClass=person)
Username Conversion Pattern (usernameConversionPattern)
Description

Regular expression pattern containing a group (a region embraced by parentheses) that can be used in conjunction with property "Username Conversion Replacement" in order to transform the username before it is used for searching the user in the directory. If the username does not match the pattern at all, no transformation is performed.

Example: The pattern "(.*)" and the replacement pattern "user.$1" will transform the username "jdoe" to "user.jdoe" before it is used in the directory.

Example: The pattern "user\.(.*)" and the replacement pattern "$1" will transform the username "user.jdoe" to "jdoe" before it is used in the directory.

Attributes
RegEx
Optional
Username Conversion Replacement (usernameConversionReplacement)
Description
The replacement string used in conjunction with property "Username Conversion Pattern" in order to transform the username. The token "$1" is used to reference the string matching the group in the pattern. See property "Username Conversion Pattern" for examples.
Attributes
String
Optional
Example
user.$1
Example
$1
Insert DN Template (insertDnTemplate)
Description
Distinguished name (DN) template used for inserting new users into the LDAP directory. Use ${userId} to specify the user id (username). Use ${xxx} to use the context data value with name xxx and make sure xxx ist part of the context data attributes!
The resulting string must be a correct DN for a newly inserted user.

If no value is specified, the user id attribute (see separate property) together with the user insert tree and the username is used to form a DN for new entries.(resulting in =${userId},).

Attributes
String
Optional
Example
uid=${userId},ou=users,o=test
Example
cn=${cn},cn=users,dc=exchangeserver,dc=yourcompany,dc=com
User Insert Tree (userInsertTree)
Description

Distinguished name (DN) of the container node (subtree) to insert new users to. If not specified, the first user container node (see separate property) is used. Use ${xxx} to include the context data value with name xxx in the DN (may result in errors if the data does not form a valid subtree).

This property is only used if no "Insert DN Template" is specified and cannot be combined with it.

Attributes
String
Optional
Example
ou=users,o=test
Example
cn=users,dc=exchangeserver,dc=yourcompany,dc=com
Example
ou=users,ou=${company},dc=com
Insert Object Classes (insertObjectClasses)
Description
Object class(es) used for newly inserted users. At least one object class must be structural.

Note: When inserting a new entry into an LDAP, the object class defines a number of mandatory attributes. You must make sure that the corresponding attributes are inserted by adding the corresponding values to the new user's context data container and/or mapping other user values to the required attributes (e.g. map the user name to the cn attribute).

This property is only used if users are inserted using this plugin.

Attributes
String-List
Optional
Default value
[inetOrgPerson]
Default Auth Method (defaultAuthMethod)
Description
The default authentication method value used when inserting new users that have no auth method set. This is only used if an authentication method attribute is configured.
Attributes
String
Optional
Suggested values
PASSWORD, MATRIX, MTAN, OATH_OTP, CERTIFICATE, CRONTO, EMAILOTP, SECURID, SECOVID
Default Next Auth Method (defaultNextAuthMethod)
Description
The default next authentication method value used when inserting new users that have no next auth method set. This is only used if a next authentication method attribute is configured.
Attributes
String
Optional
Suggested values
PASSWORD, MATRIX, MTAN, OATH_OTP, CERTIFICATE, EMAILOTP, SECURID, SECOVID
Additional Insert Data (additionalInsertData)
Description
A List of additional user insert data. If the same attribute is already defined, an exception will be thrown.
Attributes
Plugin-List
Optional
Assignable plugins
Password Attribute (passwordAttribute)
Description
The LDAP attribute which holds the password. It is used to set the password (not for checking the password).

Note that this attribute is ignored if a 'Password Modify Extended Operation' is used.

Attributes
String
Optional
Default value
userPassword
Suggested values
userPassword
Password Validity Days (passwordValidityDays)
Description
The number of days a password may be used before it must be changed.

If a password is changed, this plugin sets the latest-password-change-timestamp and (if the corresponding property is defined) also updates the next-enforced-password-change-timestamp.

If this property is not defined, the "Next Enforced Password Change Timestamp" is not updated.

Attributes
Integer
Optional
Maximum Wrong Old Passwords (maximumWrongOldPasswords)
Description
The number of wrong old passwords during a password change before a user is locked.

Warning: Make sure that number of logins is not increased by the calling application, too.

Attributes
Integer
Optional
Default value
5
Force Password Change Attribute (forcePasswordChangeAttribute)
Description
The name of the LDAP attribute holding the force password flag.
Attributes
String
Optional
Suggested values
forcePasswordChange
Order Password Attribute (orderPasswordAttribute)
Description
The name of the LDAP attribute holding the order password flag. This attribute is used for batch processes generating password letters and alike.
Attributes
String
Optional
Suggested values
orderPassword
Password Order User Attribute (passwordOrderUserAttribute)
Description
The name of the LDAP attribute holding the user by whom the new password was ordered. This attribute is used for batch processes generating password letters and alike.
Attributes
String
Optional
Suggested values
orderPasswordUser
Password Order Date Attribute (passwordOrderDateAttribute)
Description
The name of the LDAP attribute holding the date when the new password was ordered. This attribute is used for batch processes generating password letters and alike.
Attributes
String
Optional
Suggested values
orderPasswordDate
Latest Password Change Date Attribute (latestPasswordChangeDateAttribute)
Description
The name of the LDAP attribute holding the date of the latest password change.
Attributes
String
Optional
Suggested values
latestPasswordChangeDate
Next Enforced Password Change Date Attribute (nextEnforcedPasswordChangeDateAttribute)
Description
The name of the LDAP attribute holding the date of the next enforced password change.
Attributes
String
Optional
Suggested values
nextEnforcedPasswordChangeDate
Password Generation Date Attribute (passwordGenerationDateAttribute)
Description
The name of the LDAP attribute holding the password generation date. This attribute is used for batch processes generating password letters and alike.
Attributes
String
Optional
Suggested values
passwordGenerationDate
Password Delivery Date Attribute (passwordDeliveryDateAttribute)
Description
The name of the LDAP attribute holding the password delivery date. This attribute is used for batch processes generating password letters and alike.
Attributes
String
Optional
Suggested values
passwordDeliveryDate
Failed Password Resets Attribute (failedPasswordResetsAttribute)
Description

The name of the LDAP attribute holding the number of failed password reset attempts for flow-based password reset.

Security note: If this column is not specified, failed password reset attempts are not counted, which enables brute-force attacks.

Attributes
String
Optional
Suggested values
failedPasswordResets
Other Credentials Delivery Timestamp Attributes (otherCredentialsDeliveryTimestampAttributes)
Description
list of column names with the delivery dates of other credentials.
The type of every referenced column is either a DATE or TIMESTAMP.
This information can be used by components that care about not delivering more than one user credential at the same time.
If this column is not specified, no delivery dates are provided to callers.
Attributes
String-List
Optional
Auth Method Attribute (authMethodAttribute)
Description
The name of the LDAP attribute holding the user's authentication method.
Attributes
String
Optional
Suggested values
authMethod
Next Auth Method Attribute (nextAuthMethodAttribute)
Description
The name of the LDAP attribute holding the user's authentication method after migration.
Attributes
String
Optional
Suggested values
nextAuthMethod
Auth Migration Date Attribute (authMigrationDateAttribute)
Description
The name of the LDAP attribute holding the date until which the migration of the auth method has to be performed.
Attributes
String
Optional
Suggested values
authMigrationDate
Valid Attribute (validAttribute)
Description
The name of the LDAP attribute telling if the user is valid or not.
Attributes
String
Optional
Suggested values
valid
Not Valid Before Attribute (notValidBeforeAttribute)
Description
The name of the LDAP attribute indicating the point in time before which a user is considered not valid yet. The attribute must contain a timestamp.
Attributes
String
Optional
Suggested values
notValidBefore
Not Valid After Attribute (notValidAfterAttribute)
Description
The name of the LDAP attribute indicating the point in time after which a user is considered not valid anymore. The attribute must contain a timestamp.
Attributes
String
Optional
Suggested values
notValidAfter
Failed Logins Attribute (failedLoginsAttribute)
Description
The name of the LDAP attribute holding the number of failed logins (for the classic Loginapp). If this attribute is not specified, the number of failed logins is not counted and the user is not locked after a certain amount of failed logins even if the maximum number of failed logins is specified in the authenticator.
Attributes
String
Optional
Suggested values
failedLogins
Failed Token Counts Attribute (failedTokenCountsAttribute)
Description
The name of the LDAP attribute holding the failed attempts on authentication tokens (for the flow-based REST API). If this attribute is not specified, the failed token attempts are not counted.
Attributes
String
Optional
Suggested values
failedTokenCounts
Failed Logins Before Latest Successful Login Attribute (failedLoginsBeforeLatestSuccessfulLoginAttribute)
Description
The name of the LDAP attribute holding the number of failed logins before the latest successful login. If this attribute is not specified, the number of failed logins before the latest successful login is not counted.
Attributes
String
Optional
Suggested values
failedLoginsBeforeLatestSuccessfulLogin
Total Logins Attribute (totalLoginsAttribute)
Description
The name of the LDAP attribute holding the total number of successful logins. If this attribute is not specified, the total number of logins is not counted.
Attributes
String
Optional
Suggested values
totalLogins
Latest Login Attempt Attribute (latestLoginAttemptAttribute)
Description
The name of the LDAP attribute holding the date and time of the latest login attempt.
Attributes
String
Optional
Suggested values
latestLoginAttempt
Latest Successful Login Attribute (latestSuccessfulLoginAttribute)
Description
The name of the LDAP attribute holding the date and time of the latest successful login.
Attributes
String
Optional
Suggested values
latestSuccessfulLogin
Second Latest Successful Login Attribute (secondLatestSuccessfulLoginAttribute)
Description
The name of the LDAP attribute holding the date and time of the second latest successful login.
Attributes
String
Optional
Suggested values
secondLatestSuccessfulLogin
First Login Attribute (firstLoginAttribute)
Description
The name of the LDAP attribute holding the date and time of the very first login.
Attributes
String
Optional
Suggested values
firstLogin
Unlock Attempts Attribute (unlockAttemptsAttribute)
Description
The name of the LDAP attribute holding the number of failed unlock attempts.
Attributes
String
Optional
Suggested values
unlockAttempts
Latest Unlock Attempt Attribute (latestUnlockAttemptAttribute)
Description
The name of the LDAP attribute holding the date and time of the latest unlock attempt.
Attributes
String
Optional
Suggested values
latestUnlockAttempt
Self Registered Attribute (selfRegisteredAttribute)
Description
The name of the LDAP attribute holding the flag indicating if a user is self-registered.
Attributes
String
Optional
Suggested values
selfRegisteredFlag
Self Registration Date Attribute (selfRegistrationDateAttribute)
Description
The name of the LDAP attribute holding the self-registration date (if applicable).
Attributes
String
Optional
Suggested values
selfRegistrationDate
Channel Verification Resends Attribute (channelVerificationResendsAttribute)
Description
Name of the LDAP attribute holding the number of completed resends of the channel verification token during the user's self-registration.
Attributes
String
Optional
Suggested values
channelVerificationResends
Realm Attribute (realmAttribute)
Description
Name of the LDAP attribute holding the realm of the user.
Setting this attribute is mandatory when using the Multi-Realm feature. The column specificied here must not also be in the list of Context Data Attributes.
Attributes
String
Optional
Suggested values
realm
Last GSID Value Attribute (lastGSIDValueAttribute)
Description
Name of the LDAP attribute holding the last global session id.
Attributes
String
Optional
Suggested values
lastGsidValue
Last GSID Date Attribute (lastGSIDDateAttribute)
Description
Name of the LDAP attribute holding the last update timestamp for the global session id.
Attributes
String
Optional
Suggested values
lastGsidDate
Secret Questions Enabled Attribute (secretQuestionsEnabledAttribute)
Description
Name of the LDAP attribute holding the secret questions enable/disable flag.
Attributes
String
Optional
Suggested values
secretQuestionsEnabled
Context Data Attributes (contextDataAttributes)
Description
A list of attribute names that are loaded into the context data container of the user. This can be used to transport arbitrary information such as user address information to calling plug-ins.
Note: Context data attributes are string based. Values will be read as strings and are converted to string when written.Note: When referring operational attributes, also configure them in the "Attributes to Request" in "Advanced Settings" below.
Attributes
String-List
Optional
Read-only Attributes (readOnlyAttributes)
Description
A list of attribute names that will never be written to (even for non-context-data attributes).
Attributes
String-List
Optional
Binary Attributes (binaryAttributes)
Description
A list of attribute names that should be treated as binary data (instead of string data).

Those attributes are Base64 encoded before they are loaded into the context data container of the user.

Note: To be able to use a an attribute configured here, it must additionally be added to the property "Context Data Attributes".

Attributes
String-List
Optional
User DN Context Data Attribute (userDNContextDataAttribute)
Description
The name of the context data attribute to store the user's DN into.
This DN is in the format "uid=user,ou=People,dc=company,dc=ch".
Attributes
String
Optional
Example
dn
Max Failed Logins (maxFailedLogins)
Description
The maximum number of consecutively failed logins before a user account is locked. If not defined, locking is turned off.
This is only relevant if the property "Update Login Statistics" is on (the default).
Note: User locking only works if the number of failed logins and the locked state can be written/read to/from the directory (see attribute settings).
Important: This feature is disabled in case the Ldap Connector is used as authenticator in a Main Authenticator. In that case, the Main Authenticator is responsible for counting failed logins.
Attributes
Integer
Optional
Locked Attribute (lockedAttribute)
Description
The name of the LDAP attribute holding the locked status flag.
Attributes
String
Optional
Suggested values
isLocked
Lock Reason Attribute (lockReasonAttribute)
Description
The name of the LDAP attribute contains the reason why the users is locked.
This can be the hole description of the reason or a key to the string resource.
Attributes
String
Optional
Suggested values
lockReason
Lock Date Attribute (lockDateAttribute)
Description
The name of the LDAP attribute contains the timestamp of the user locking.
.
Attributes
String
Optional
Suggested values
lockDate
Static Roles (staticRoles)
Description
List of roles granted to authenticated users. These roles are never persisted on the LDAP.

Note that there are other ways to retrieve a user's roles from the directory. See configuration properties "Role Search ..." and "Roles Attribute".

Attributes
String-List
Optional
Roles Attribute (rolesAttribute)
Description
Name of the attribute holding a list of roles granted to the user after successful authentication.
The attribute can have multiple values (= multiple occurrences of the attribute in the directory; not a comma-separated list of values).

Note that there are other ways to write and retrieve a user's roles from the directory. See configuration properties "Role Update: User Attribute In Roles", "Role Search ..." and "Static Roles".

Attributes
String
Optional
Suggested values
roles
Roles can be changed (rolesEditable)
Description
If enabled and either the property "Roles Attribute" or "Role Update: User Attribute In Roles" is specified, the role set of a user can be changed (e.g. using the Adminapp). Otherwise, the role set is read-only.
If enabled, the way roles are determined (see other role-related properties) is limited.
Attributes
Boolean
Optional
Default value
true
Roles Attribute RDN (rolesAttributeRdn)
Description
When using the property "Roles Attribute" and when the role value is given as a full DN, e.g. "cn=admin,dc=groups,dc=auth,o=acme", you can specify the RDN which identifies the role name. In the previous example if you specify "cn" as the RDN then the value "admin" will be extracted.
Attributes
String
Optional
Example
cn
Example
role
Roles Nested Resolution Depth (rolesNestedResolutionDepth)
Description
When using the property "Roles Attribute" you can specify the depth of nested role resolution.

That is, if the user has a role superusers, which again has a role users then both roles are returned. A value of 0 turns off nested role resolution and looks for roles only on the current user object.

Attributes
Integer
Optional
Default value
0
Roles Nested Resolution Top Only (rolesNestedResolutionTopOnly)
Description
When using the property "Roles Nested Resolution Depth" with a value >0 you can specify whether all nested roles are selected or only the top-most roles.

For example, assume the user has a role superusers, which has a role users, which again has a role basicusers. If this property is enabled and the resolution depth is at least 2 then only the role basicusers is returned. If this property is enabled and the resolution depth is set to 1 the role users is returned. If this property is disabled all visited roles are returned (all three if the resolution depth is at least 2).

Attributes
Boolean
Optional
Default value
false
Roles Search Base (rolesSearchBase)
Description
Together with the attributes "Roles Search Level", "Roles Search Filter", and "Roles Search Attribute", this forms a flexible way to retrieve a user's role from the LDAP directory. The selected roles are granted to the user after successful authentication.
This attribute specifies the search context (subtree) where roles are searched. It must identify a subtree in the directory.

Note that there are other ways to retrieve a user's roles from the directory. See configuration properties "Roles Search ..." and "Roles Attribute".

Attributes
String
Optional
Example
CN=roles,dc=exchangeserver,dc=company,dc=com
Roles Search Level (rolesSearchLevel)
Description
Together with the attributes "Roles Search Base", "Roles Search Filter", and "Roles Search Attribute", this forms a flexible way to retrieve a user's role from the LDAP directory. The selected roles are granted to the user after successful authentication.
This attribute specifies whether the user search scope is the node selected by the configuration property "Roles Search Base" only or whether the serach scope is the whole subtree.

Note that there are other ways to retrieve a user's roles from the directory. See configuration properties "Roles Search ..." and "Roles Attribute".

Attributes
Enum
Optional
Default value
onelevel
Roles Search Filter (rolesSearchFilter)
Description
Together with the attributes "Roles Search Base", "Roles Search Level", and "Roles Search Attribute", this forms a flexible way to retrieve a user's role from the LDAP directory. The selected roles are granted to the user after successful authentication.
This attribute specifies an arbitrary filter applied when searching the roles. In the filter, you can refer to the user's DN by ${DN}, the username by ${userId} and you can use any attribute value listed of the context data container (values of attributes listed in configuration property "Context Data Attributes") by referring to it in the following way: ${attribute-name}.

Note that there are other ways to retrieve a user's roles from the directory. See configuration properties "Roles Search ..." and "Roles Attribute".

Attributes
String
Optional
Example
(member=${DN})
Example
(userId=${userId})
Example
&(userId=${userId})(memberOf=CN=@VPNMail,OU=${town},DC=company,DC=com))
Roles Search Attribute (rolesSearchAttribute)
Description
Together with the attributes "Roles Search Base", "Roles Search Level", and "Roles Search Filter", this forms a flexible way to retrieve a user's role from the LDAP directory. The selected roles are granted to the user after successful authentication.
This attribute specifies the name of the attribute with the role name in the result of the search. The attribute must select a string type attribute.

Note that there are other ways to retrieve a user's roles from the directory. See configuration properties "Roles Search ..." and "Roles Attribute".

Attributes
String
Optional
Example
role
Example
cn
Role Update: User Attribute In Roles (userAttributeInRolesForRoleUpdate)
Description
Only relevant if roles can be changed and are found by search using "Roles Search Base" and its dependent properties.

Defines the attribute on a role entry containing the users of this role. This attribute will be updated when roles managed in separate LDAP groups are being changed.

If your directory does not automatically update the user entry when writing a user DN to a role entry, configure the property "Role Update: Roles Attribute In User" as well.
Attributes
String
Optional
Example
member
Role Update: Roles Attribute In User (rolesAttributeInUserForRoleUpdate)
Description
Only relevant if roles can be changed and are found by search using "Roles Search Base" and its dependent properties.

Defines the attribute on a user entry containing the roles of this user. If set, this attribute will be updated when roles are being changed. Configure this property if your directory does not automatically update the user entry when its DN is added to a role entry.

Attributes
String
Optional
Example
memberOf
Role Filters (roleFilters)
Description
Allows filtering of retrieved user roles. If configured, only roles that match at least one of the filter patterns are assigned to the user. Static roles are not filtered.
Attributes
RegEx-List
Optional
Match Roles Case Sensitive (matchRolesCaseSensitive)
Description
If enabled, roles are matched against the role filters considering the case (the default).
Attributes
Boolean
Optional
Default value
true
Attributes To Request (attributesToRequest)
Description
The list of explicit attributes to request from the LDAP server.
If left empty, all attributes are requested (default).

Operational attributes are attributes which the directory organizes for internal use. Normally, such attributes are not returned to an LDAP client in a standard request for object data. Therefore, they have to be configured explicitly here. In order to return all available operational attributes, the value '+' can be used for certain directories like OpenLDAP.
Some directories return only the operational attributes with the value '+', thus the normal attributes need to be requested in addition by also requesting '*' for all normal attributes.
Alternatively (and if supported by the directory), when only one specific operational attributes is required, configure "*" and the operational attribute (for example "creatorsName") to specifically request this operational attribute in addition to the normal attributes.

Attributes
String-List
Optional
Update Login Statistics (updateLoginStatistics)
Description
If enabled, login statistics (failed logins, timestamps, etc.) are updated during the authentication process. If disabled, they are not.
Disabling this flag makes the plugin suitable as step in a multi-step authentication process (e.g. using the Meta Authenticator or the Main Authenticator).

Note: Login statistic data can only be updated, if the corresponding attributes are configured to be read/written from/to the directory.

Attributes
Boolean
Optional
Default value
true
Search Result Page Size (searchResultPageSize)
Description
If set to a value greater than zero and the LDAP server supports the SimplePaging control, "paging" is enabled for LDAP searches: This property defines the amount of entries to fetch at once when searching in a directory. This setting may be useful if the LDAP directory server limits the amount of entries in a search result.
If the property undefined (the default) or if the server does not announce to support the SimplePaging control, paging is disabled.
Attributes
Integer
Optional
Special Date Time Pattern (specialDateTimePattern)
Description
Optional special date formatter / parser pattern used to read and write timestamps in a different way than in standard LDAP. This may be useful if timestamps are stored in some proprietary way as strings in a directory.
The used timezone is UTC or the local one if the flag "Special Date Time Pattern Use Local Timezone" ist set to true.

If this property is not defined, the LDAP-standard pattern yyyyMMddHHmmss.SSS'Z' is used.

Attributes
String
Optional
Suggested values
yyyyMMddHHmmss, yyyyMMddHHmmss'Z', MM-dd-yyyy HH:mm:ss
Special Date Time Pattern Use Local Timezone (specialDateTimePatternUseLocalTimezone)
Description
Optional flag telling the plug-in that the special date formatter should use the local timezone instead of UTC.
Attributes
Boolean
Optional
Default value
false
Suppress Substring Search (suppressSubstringSearch)
Description
If enabled, substring string searches are suppressed, i.e. attributes do only match a filter if the whole filter string matches.
This may greatly improve search performance in large directories.
Attributes
Boolean
Optional
Default value
false
User Count Search Filter (userCountSearchFilter)
Description
The LDAP search filter expression applied to count the users. If no filter expression is given here, the "User Search Filter" expression is used to determine the user count. The format and interpretation of filter follows RFC 2254.

Note: The user count is relevant for the product license. This filter should therefore describe the set of users who should be able to authenticate by Airlock IAM.

Attributes
Plugin-Link
Optional
Assignable plugins
Ldap Failure Mappers (ldapFailureMappers)
Description
A list of plugins mapping ldap failure messages (exception message returned by the LDAP directory in case of bind failures) to authentication result types.
Attributes
Plugin-List
Optional
Assignable plugins
Constraint Violation Result Code (constraintViolationResultCode)
Description
Optional LDAP result code value that should be treated as password constraint violation.
Attributes
Integer
Optional
Default value
-1
Use Password Modify Extended Operation (passwordModifyExtendedOperation)
Description
If enabled, an 'LDAP Password Modify Extended Operation' is used instead of a modify request to change or reset a user password. Please refer to RFC-3062 for further information.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: LdapConnector
id: LdapConnector-xxxxxx
displayName: 
comment: 
properties:
  additionalInsertData:
  attributesToRequest:
  authMethodAttribute:
  authMigrationDateAttribute:
  binaryAttributes:
  channelVerificationResendsAttribute:
  connectionPool:
  constraintViolationResultCode: -1
  contextDataAttributes:
  credentialDataAttribute:
  defaultAuthMethod:
  defaultNextAuthMethod:
  failedLoginsAttribute:
  failedLoginsBeforeLatestSuccessfulLoginAttribute:
  failedPasswordResetsAttribute:
  failedTokenCountsAttribute:
  firstLoginAttribute:
  forcePasswordChangeAttribute:
  insertDnTemplate:
  insertObjectClasses: [inetOrgPerson]
  lastGSIDDateAttribute:
  lastGSIDValueAttribute:
  latestLoginAttemptAttribute:
  latestPasswordChangeDateAttribute:
  latestSuccessfulLoginAttribute:
  latestUnlockAttemptAttribute:
  ldapFailureMappers:
  lockDateAttribute:
  lockReasonAttribute:
  lockedAttribute:
  matchRolesCaseSensitive: true
  maxFailedLogins:
  maximumWrongOldPasswords: 5
  nextAuthMethodAttribute:
  nextEnforcedPasswordChangeDateAttribute:
  notValidAfterAttribute:
  notValidBeforeAttribute:
  orderPasswordAttribute:
  otherCredentialsDeliveryTimestampAttributes:
  passwordAttribute: userPassword
  passwordDeliveryDateAttribute:
  passwordGenerationDateAttribute:
  passwordModifyExtendedOperation: false
  passwordOrderDateAttribute:
  passwordOrderUserAttribute:
  passwordValidityDays:
  readOnlyAttributes:
  realmAttribute:
  roleFilters:
  rolesAttribute:
  rolesAttributeInUserForRoleUpdate:
  rolesAttributeRdn:
  rolesEditable: true
  rolesNestedResolutionDepth: 0
  rolesNestedResolutionTopOnly: false
  rolesSearchAttribute:
  rolesSearchBase:
  rolesSearchFilter:
  rolesSearchLevel: onelevel
  searchResultPageSize:
  secondLatestSuccessfulLoginAttribute:
  secretQuestionsEnabledAttribute:
  selfRegisteredAttribute:
  selfRegistrationDateAttribute:
  specialDateTimePattern:
  specialDateTimePatternUseLocalTimezone: false
  staticRoles:
  suppressSubstringSearch: false
  totalLoginsAttribute:
  unlockAttemptsAttribute:
  updateLoginStatistics: true
  userAttributeInRolesForRoleUpdate:
  userChangeEventListeners:
  userContainerNodes:
  userCountSearchFilter:
  userDNContextDataAttribute:
  userInsertTree:
  userSearchFilter: (objectClass=inetOrgPerson)
  userSearchScope: subtree
  usernameAttribute:
  usernameConversionPattern:
  usernameConversionReplacement:
  validAttribute: