LDAP Connector
Provides the following services by connecting to an LDAP directory (for MS Active Directory, please use the Active Directory Connector plugin):
Main Features
- LDAP directory as user data repository (User Store)
- LDAP directory as password service (check password, reset password, change password)
- LDAP directory as simple token storage for one user-related token (e.g. for mobile number – not recommended: requires schema extension and provides limited support)
Requirements on Directory Schema
-
For the basic features, users should have object class
inetOrgPerson. More limited usage is possible withorganizationalPersonand evenPerson. - All attribute names are configurable. Therefore, custom schemas are supported as long as all user data is stored as attributes in one directory entry (except for roles/groups).
-
To use all features of this plugin, custom attributes are required.
Please refer to the Airlock IAM documentation page "Generic LDAP directories for IAM" for more information.
For details about the meaning of an attribute, please refer to the corresponding attribute setting's help in this plugin.
Depending on the configured attributes, more or fewer features can be used. -
User roles/groups can be read from the following:
- From a user attribute with one or more values (see "Roles Attribute"). RDNs can be extracted from DNs stored in this attribute. This set of roles can also be written.
- Roles can be looked up in other directory trees (e.g. groups subtree) by configuring the corresponding query, search depth and filters.
- Nested/hierarchical roles are supported.
How Users are found
For all operations (load, store user, check password, change password, etc.),
this plugin first looks up the user entry in the directory using the service account specified in the connection pool settings.
Multiple search trees can be specified in order to limit the search space (and therefore improve performance) when users are stored in multiple subtrees.
Reading / Writing Credential Information
This plugin only provides very limited features for reading / writing credential information:
It only reads and writes a single attribute stored as user attribute (see "Credential Data Attribute").
It can be used, for example, to use the mobile phone number authentication token (for 2-factor authentication).
The plugin does not support token order flags, serial numbers, delivery dates, and alike. Please use a relational database instead for more features.
This plugin offers all features of the "LDAP Password Authenticator". Whereas the "LDAP Password Authenticator" only checks or sets the password, this plugin also considers user information such as:
- Locked flag
- User validity attributes
- Failed logins counter
- Password change enforced flag
- Password expiry date
- etc.
Read-only Attributes and Operational Attributes
In the property "Read-only Attributes", attributes can be defined that are only read and never written by this plugin.
This works not only for context data attributes but for all attributes potentially written by this plugin.
This enables the plugin to read operational attributes and use them in authentication or password management:
some directories provide automatically updated operational attributes (e.g. latest password change) that may be read but not be written by LDAP clients.
They can be configured in the corresponding attribute settings and put in the list of read-only attributes.
NOTE: Some directories do not provide operational attributes to LDAP clients and always return empty values when read using LDAP.
Limitation of Usage
Unlike the "LDAP User Persister", this plugin is not able to read the password hash from the directory.
It can therefore not be used with a custom schema where the password hash is computed in Airlock IAM and only stored (and read) by this plugin.
Note on using this plugin only for password checks
When only using this plugin to check the user's password, additional features like role lookup or context data retrieval
may not work as expected.
connectionPool) usernameAttribute) credentialDataAttribute) userContainerNodes) userSearchScope) userSearchFilter) The format and interpretation of filter follows RFC 2254.
usernameConversionPattern) Regular expression pattern containing a group (a region embraced by parentheses) that can be used in conjunction with property "Username Conversion Replacement" in order to transform the username before it is used for searching the user in the directory. If the username does not match the pattern at all, no transformation is performed.
Example: The pattern "(.*)" and the replacement pattern "user.$1" will transform the username "jdoe" to "user.jdoe" before it is used in the directory.
Example: The pattern "user\.(.*)" and the replacement pattern "$1" will transform the username "user.jdoe" to "jdoe" before it is used in the directory.
usernameConversionReplacement) insertDnTemplate) The resulting string must be a correct DN for a newly inserted user.
If no value is specified, the user id attribute (see separate property) together with the user insert tree and the username is used to form a DN for new entries.(resulting in =${userId},).
userInsertTree) Distinguished name (DN) of the container node (subtree) to insert new users to. If not specified, the first user container node (see separate property) is used. Use ${xxx} to include the context data value with name xxx in the DN (may result in errors if the data does not form a valid subtree).
This property is only used if no "Insert DN Template" is specified and cannot be combined with it.
insertObjectClasses) Note: When inserting a new entry into an LDAP, the object class defines a number of mandatory attributes. You must make sure that the corresponding attributes are inserted by adding the corresponding values to the new user's context data container and/or mapping other user values to the required attributes (e.g. map the user name to the cn attribute).
This property is only used if users are inserted using this plugin.
defaultAuthMethod) defaultNextAuthMethod) additionalInsertData) passwordAttribute) Note that this attribute is ignored if a 'Password Modify Extended Operation' is used.
passwordValidityDays) If a password is changed, this plugin sets the latest-password-change-timestamp and (if the corresponding property is defined) also updates the next-enforced-password-change-timestamp.
If this property is not defined, the "Next Enforced Password Change Timestamp" is not updated.
maximumWrongOldPasswords) Warning: Make sure that number of logins is not increased by the calling application, too.
forcePasswordChangeAttribute) orderPasswordAttribute) passwordOrderUserAttribute) passwordOrderDateAttribute) latestPasswordChangeDateAttribute) nextEnforcedPasswordChangeDateAttribute) passwordGenerationDateAttribute) passwordDeliveryDateAttribute) failedPasswordResetsAttribute) The name of the LDAP attribute holding the number of failed password reset attempts for flow-based password reset.
Security note: If this column is not specified, failed password reset attempts are not counted, which enables brute-force attacks.
otherCredentialsDeliveryTimestampAttributes) The type of every referenced column is either a
DATE or TIMESTAMP.
This information can be used by components that care about not delivering more than one user credential at the same time.
If this column is not specified, no delivery dates are provided to callers.
authMethodAttribute) nextAuthMethodAttribute) authMigrationDateAttribute) validAttribute) notValidBeforeAttribute) notValidAfterAttribute) failedLoginsAttribute) failedTokenCountsAttribute) failedLoginsBeforeLatestSuccessfulLoginAttribute) totalLoginsAttribute) latestLoginAttemptAttribute) latestSuccessfulLoginAttribute) secondLatestSuccessfulLoginAttribute) firstLoginAttribute) unlockAttemptsAttribute) latestUnlockAttemptAttribute) selfRegisteredAttribute) selfRegistrationDateAttribute) channelVerificationResendsAttribute) realmAttribute) Setting this attribute is mandatory when using the Multi-Realm feature. The column specificied here must not also be in the list of Context Data Attributes.
lastGSIDValueAttribute) lastGSIDDateAttribute) secretQuestionsEnabledAttribute) contextDataAttributes) Note: Context data attributes are string based. Values will be read as strings and are converted to string when written.Note: When referring operational attributes, also configure them in the "Attributes to Request" in "Advanced Settings" below.
readOnlyAttributes) binaryAttributes) Those attributes are Base64 encoded before they are loaded into the context data container of the user.
Note: To be able to use a an attribute configured here, it must additionally be added to the property "Context Data Attributes".
userDNContextDataAttribute) This DN is in the format "uid=user,ou=People,dc=company,dc=ch".
maxFailedLogins) This is only relevant if the property "Update Login Statistics" is on (the default).
Note: User locking only works if the number of failed logins and the locked state can be written/read to/from the directory (see attribute settings).
Important: This feature is disabled in case the Ldap Connector is used as authenticator in a Main Authenticator. In that case, the Main Authenticator is responsible for counting failed logins.
lockedAttribute) lockReasonAttribute) This can be the hole description of the reason or a key to the string resource.
lockDateAttribute) .
staticRoles) Note that there are other ways to retrieve a user's roles from the directory. See configuration properties "Role Search ..." and "Roles Attribute".
rolesAttribute) The attribute can have multiple values (= multiple occurrences of the attribute in the directory; not a comma-separated list of values).
Note that there are other ways to write and retrieve a user's roles from the directory. See configuration properties "Role Update: User Attribute In Roles", "Role Search ..." and "Static Roles".
rolesEditable) If enabled, the way roles are determined (see other role-related properties) is limited.
rolesAttributeRdn) rolesNestedResolutionDepth) That is, if the user has a role superusers, which again has a role users then both roles are returned. A value of 0 turns off nested role resolution and looks for roles only on the current user object.
rolesNestedResolutionTopOnly) For example, assume the user has a role superusers, which has a role users, which again has a role basicusers. If this property is enabled and the resolution depth is at least 2 then only the role basicusers is returned. If this property is enabled and the resolution depth is set to 1 the role users is returned. If this property is disabled all visited roles are returned (all three if the resolution depth is at least 2).
rolesSearchBase) This attribute specifies the search context (subtree) where roles are searched. It must identify a subtree in the directory.
Note that there are other ways to retrieve a user's roles from the directory. See configuration properties "Roles Search ..." and "Roles Attribute".
rolesSearchLevel) This attribute specifies whether the user search scope is the node selected by the configuration property "Roles Search Base" only or whether the serach scope is the whole subtree.
Note that there are other ways to retrieve a user's roles from the directory. See configuration properties "Roles Search ..." and "Roles Attribute".
rolesSearchFilter) This attribute specifies an arbitrary filter applied when searching the roles. In the filter, you can refer to the user's DN by
${DN}, the username by ${userId} and you can use any attribute value listed of the context data container (values of attributes listed in configuration property "Context Data Attributes") by referring to it in the following way: ${attribute-name}.
Note that there are other ways to retrieve a user's roles from the directory. See configuration properties "Roles Search ..." and "Roles Attribute".
rolesSearchAttribute) This attribute specifies the name of the attribute with the role name in the result of the search. The attribute must select a string type attribute.
Note that there are other ways to retrieve a user's roles from the directory. See configuration properties "Roles Search ..." and "Roles Attribute".
userAttributeInRolesForRoleUpdate) Defines the attribute on a role entry containing the users of this role. This attribute will be updated when roles managed in separate LDAP groups are being changed.
If your directory does not automatically update the user entry when writing a user DN to a role entry, configure the property "Role Update: Roles Attribute In User" as well.rolesAttributeInUserForRoleUpdate) Defines the attribute on a user entry containing the roles of this user. If set, this attribute will be updated when roles are being changed. Configure this property if your directory does not automatically update the user entry when its DN is added to a role entry.
roleFilters) matchRolesCaseSensitive) attributesToRequest) If left empty, all attributes are requested (default).
Operational attributes are attributes which the directory organizes for internal use. Normally, such attributes are not returned to an LDAP client in a standard request for object data. Therefore, they have to be configured explicitly here. In order to return all available operational attributes, the value '+' can be used for certain directories like OpenLDAP.
Some directories return only the operational attributes with the value '+', thus the normal attributes need to be requested in addition by also requesting '*' for all normal attributes.
Alternatively (and if supported by the directory), when only one specific operational attributes is required, configure "*" and the operational attribute (for example "creatorsName") to specifically request this operational attribute in addition to the normal attributes.
updateLoginStatistics) Disabling this flag makes the plugin suitable as step in a multi-step authentication process (e.g. using the Meta Authenticator or the Main Authenticator).
Note: Login statistic data can only be updated, if the corresponding attributes are configured to be read/written from/to the directory.
searchResultPageSize) If the property undefined (the default) or if the server does not announce to support the SimplePaging control, paging is disabled.
specialDateTimePattern) The used timezone is UTC or the local one if the flag "Special Date Time Pattern Use Local Timezone" ist set to true.
If this property is not defined, the LDAP-standard pattern yyyyMMddHHmmss.SSS'Z' is used.
specialDateTimePatternUseLocalTimezone) suppressSubstringSearch) This may greatly improve search performance in large directories.
userCountSearchFilter) Note: The user count is relevant for the product license. This filter should therefore describe the set of users who should be able to authenticate by Airlock IAM.
userChangeEventListeners) ldapFailureMappers) constraintViolationResultCode) passwordModifyExtendedOperation)
type: LdapConnector
id: LdapConnector-xxxxxx
displayName:
comment:
properties:
additionalInsertData:
attributesToRequest:
authMethodAttribute:
authMigrationDateAttribute:
binaryAttributes:
channelVerificationResendsAttribute:
connectionPool:
constraintViolationResultCode: -1
contextDataAttributes:
credentialDataAttribute:
defaultAuthMethod:
defaultNextAuthMethod:
failedLoginsAttribute:
failedLoginsBeforeLatestSuccessfulLoginAttribute:
failedPasswordResetsAttribute:
failedTokenCountsAttribute:
firstLoginAttribute:
forcePasswordChangeAttribute:
insertDnTemplate:
insertObjectClasses: [inetOrgPerson]
lastGSIDDateAttribute:
lastGSIDValueAttribute:
latestLoginAttemptAttribute:
latestPasswordChangeDateAttribute:
latestSuccessfulLoginAttribute:
latestUnlockAttemptAttribute:
ldapFailureMappers:
lockDateAttribute:
lockReasonAttribute:
lockedAttribute:
matchRolesCaseSensitive: true
maxFailedLogins:
maximumWrongOldPasswords: 5
nextAuthMethodAttribute:
nextEnforcedPasswordChangeDateAttribute:
notValidAfterAttribute:
notValidBeforeAttribute:
orderPasswordAttribute:
otherCredentialsDeliveryTimestampAttributes:
passwordAttribute: userPassword
passwordDeliveryDateAttribute:
passwordGenerationDateAttribute:
passwordModifyExtendedOperation: false
passwordOrderDateAttribute:
passwordOrderUserAttribute:
passwordValidityDays:
readOnlyAttributes:
realmAttribute:
roleFilters:
rolesAttribute:
rolesAttributeInUserForRoleUpdate:
rolesAttributeRdn:
rolesEditable: true
rolesNestedResolutionDepth: 0
rolesNestedResolutionTopOnly: false
rolesSearchAttribute:
rolesSearchBase:
rolesSearchFilter:
rolesSearchLevel: onelevel
searchResultPageSize:
secondLatestSuccessfulLoginAttribute:
secretQuestionsEnabledAttribute:
selfRegisteredAttribute:
selfRegistrationDateAttribute:
specialDateTimePattern:
specialDateTimePatternUseLocalTimezone: false
staticRoles:
suppressSubstringSearch: false
totalLoginsAttribute:
unlockAttemptsAttribute:
updateLoginStatistics: true
userAttributeInRolesForRoleUpdate:
userChangeEventListeners:
userContainerNodes:
userCountSearchFilter:
userDNContextDataAttribute:
userInsertTree:
userSearchFilter: (objectClass=inetOrgPerson)
userSearchScope: subtree
usernameAttribute:
usernameConversionPattern:
usernameConversionReplacement:
validAttribute: