← Back to plugin index

LDAP Credential Persister

Description
Credential persister and iterator using a LDAP directory (also Active Directory) as repository.

Access to the directory is done using the UnboudID library.

This plug-in binds to the LDAP server using a technical user. With this technical user, credentials are searched, read and updated. Make sure the technical user has enough access rights to perform these actions.

Type name
LdapCredentialPersister
Class
com.airlock.iam.core.misc.impl.persistency.ldap.LdapCredentialPersister
May be used by
Properties
Connection Pool (connectionPool)
Description
The connection pool connecting to the LDAP directory (or active directory).
Attributes
Plugin-Link
Mandatory
Assignable plugins
Search Contexts (searchContexts)
Description
Defines a list of search contexts (search trees with search levels) to use when looking for credential records. The search contexts are used in the defined order.
Attributes
Plugin-List
Mandatory
Assignable plugins
Search Filter (searchFilter)
Description
The LDAP search filter expression to extract a single credential object given the user's name. You must make sure, that the query - performed relative to the specified search-tree - results in exactly one entry. Use the variable notation ${userId} to specify the user id in the search filter. The format and interpretation of filter follows RFC 2254.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Iterator Search Filter (iteratorSearchFilter)
Description
The LDAP search filter expression applied when iterating over credential nodes (only used if used as CredentialIterator). If no filter is given, all entries in the specified search tree are returned from the directory. The format and interpretation of filter follows RFC 2254.
Attributes
Plugin-Link
Optional
Assignable plugins
Userid Attribute (useridAttribute)
Description
The LDAP attribute which holds the username. This is in most cases the same attribute used in the search filter.
Attributes
String
Mandatory
Suggested values
cn, sAMAccountName, userId
Update Dn Template (updateDnTemplate)
Description
Distinguished name (DN) template used for updating the node in the LDAP directory. Use ${userId} to specify the user id. The resulting DN must uniquely identify the credential's LDAP entry.

Note: Usually it is not necessary (and not recommended) using an update template because it requires that the resulting DN is unique which is often not possible when searching with scope "subtree". This setting, however, can be very useful if the user directory service has no notion of "full names" and can therefore not determine the DN of search result by it-self.

Attributes
String
Optional
Example
uid=${userId},ou=users,o=test
Example
cn=${userId},cn=users,dc=exchangeserver,dc=yourcompany,dc=com
Binary Credential Data Attribute (binaryCredentialDataAttribute)
Description
The LDAP attribute with binary credential data for the current inner item.
The presence of this property indicates that the credential data is stored in binary form and not in string form. If this property is set, this class returns (and expects) instances of CredentialBean returning false in method "CredentialBean.isCredentialDataStringType()".
You cannot specify both this property and property "col-string-credential-type".
Attributes
String
Optional
Suggested values
currentCredentialBinaryData, currentTokenBinaryData
Next Binary Credential Data Attribute (nextBinaryCredentialDataAttribute)
Description
The LDAP attribute with binary credential data for the next inner item.
The presence of this property indicates that the credential data is stored in binary form and not in string form. If this property is set, this class returns (and expects) instances of CredentialBean returning false in method "CredentialBean.isCredentialDataStringType()".
You cannot specify both this property and property "col-string-credential-type".
Attributes
String
Optional
Suggested values
nextCredentialBinaryData, nextTokenBinaryData
String Credential Data Attribute (stringCredentialDataAttribute)
Description
The LDAP attribute with string-type credential data for the current inner item.
The presence of this property indicates that the credential data is stored as string and not in binary form. If this property is set, this class returns (and expects) instances of CredentialBean returning true in method "CredentialBean.isCredentialDataStringType()".
You cannot specify both this property and property "col-binary-credential-type".
Attributes
String
Optional
Suggested values
currentCredentialStringData, currentTokenStringData
Next String Credential Data Attribute (nextStringCredentialDataAttribute)
Description
The LDAP attribute with string-type credential data for the next inner item.
The presence of this property indicates that the credential data is stored as string and not in binary form. If this property is set, this class returns (and expects) instances of CredentialBean returning true in method "CredentialBean.isCredentialDataStringType()".
You cannot specify both this property and property "col-binary-credential-type".
Attributes
String
Optional
Suggested values
nextCredentialStringData, nextTokenStringData
Serial Attribute (serialAttribute)
Description
The name of the LDAP attribute with the credential serial number for the current inner item.
Attributes
String
Optional
Suggested values
currentCredentialSerialNumber, currentTokenSerialNumber
Next Serial Attribute (nextSerialAttribute)
Description
The name of the LDAP attribute with the credential serial number for the next inner item.
Attributes
String
Optional
Suggested values
nextCredentialSerialNumber, nextTokenSerialNumber
Active Attribute (activeAttribute)
Description
The name of the LDAP attribute column with the flag indicating whether the credential is active or not. Inactive credentials may not be used by the callers.
If the column is not specified, all credentials are considered to be active.
Attributes
String
Optional
Suggested values
credentialActive, tokenActive
Delivery Date Attribute (deliveryDateAttribute)
Description
The name of the LDAP attribute column with the date and time of the (latest) credential delivery of the current inner CredentialData item.
Attributes
String
Optional
Suggested values
currentCredentialDeliveryDate, currentTokenDeliveryDate
Next Delivery Date Attribute (nextDeliveryDateAttribute)
Description
The name of the LDAP attribute column with the date and time of the credential delivery of the next inner CredentialData item.
Attributes
String
Optional
Suggested values
nextCredentialDeliveryDate, nextTokenDeliveryDate
Other Credentials Delivery Dates Attributes (otherCredentialsDeliveryDatesAttributes)
Description
Comma-separated list of LDAP attribtues with the delivery dates of other credentials. This information may be used in order to delay the delivery time for credentials so no two credentials of the same user are delivered the same day.
Attributes
String-List
Optional
Generation Date Attribute (generationDateAttribute)
Description
The name of the LDAP attributes with the date and time of the credential generation or assignment of the current CredentialData item.
Attributes
String
Optional
Suggested values
currentCredentialGenerationDate, matrixLetterGeneration, cardAssignmentDate
Next Generation Date Attribute (nextGenerationDateAttribute)
Description
The name of the LDAP attributes with the date and time of the credential generation or assignment of the next CredentialData item.
Attributes
String
Optional
Suggested values
nextCredentialGenerationDate, matrixLetterGeneration, cardAssignmentDate
Ordered Attribute (orderedAttribute)
Description
The name of the LDAP attribute with the flag indicating whether a new credential should be generated or assigned for the user.
Attributes
String
Optional
Suggested values
credentialOrdered, orderNewTokenlist, tokenLetterOrdered
Ordered User Attribute (orderedUserAttribute)
Description
The name of the LDAP attribute with the user by whom the new credential was ordered to be generated or assigned for the user.
Attributes
String
Optional
Suggested values
orderNewTokenlistUser, tokenLetterOrderedUser
Ordered Date Attribute (orderedDateAttribute)
Description
The name of the LDAP attribute with the date when the new credential was ordered to be generated or assigned for the user.
Attributes
String
Optional
Suggested values
orderNewTokenlistDate, tokenLetterOrderedDate
Context Data Attributes (contextDataAttributes)
Description
A list of attribute names that are loaded into the context data container of the credential. This can be used to transport arbitrary information such as address information to calling plug-ins.
Attributes
String-List
Optional
Read Only Attributes (readOnlyAttributes)
Description
A list of attribute names that are to be treated read-only.
Attributes
String-List
Optional
Search Result Page Size (searchResultPageSize)
Description
If set to a value greater than zero, "paging" is enabled for LDAP searches: This property defines the amount of entries to fetch at once when searching in a directory. This setting may be useful if the LDAP directory server limits the amount of entries in a search result.
If the property is set to zero (the default), paging is disabled.
Attributes
Integer
Optional
Default value
0
Special Date Time Pattern (specialDateTimePattern)
Description
Optional special date formatter / parser pattern used to read and write timestamps in a different way than in standard LDAP. This may be useful if timestamps are stored in some proprietary way as strings in a directory.
The used timezone is UTC or the local one if the flag special-date-time-pattern-use-local-timezone ist set to true.

If this property is not defined, the LDAP-standard pattern yyyyMMddHHmmss.SSS'Z' is used.

Attributes
String
Optional
Suggested values
yyyyMMddHHmmss, yyyyMMddHHmmss'Z', MM-dd-yyyy HH:mm:ss
Special Date Time Pattern Use Local Timezone (specialDateTimePatternUseLocalTimezone)
Description
Optional flag telling the plug-in that the special date formatter should use the local timezone.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: LdapCredentialPersister
id: LdapCredentialPersister-xxxxxx
displayName: 
comment: 
properties:
  activeAttribute:
  binaryCredentialDataAttribute:
  connectionPool:
  contextDataAttributes:
  deliveryDateAttribute:
  generationDateAttribute:
  iteratorSearchFilter:
  nextBinaryCredentialDataAttribute:
  nextDeliveryDateAttribute:
  nextGenerationDateAttribute:
  nextSerialAttribute:
  nextStringCredentialDataAttribute:
  orderedAttribute:
  orderedDateAttribute:
  orderedUserAttribute:
  otherCredentialsDeliveryDatesAttributes:
  readOnlyAttributes:
  searchContexts:
  searchFilter:
  searchResultPageSize: 0
  serialAttribute:
  specialDateTimePattern:
  specialDateTimePatternUseLocalTimezone: false
  stringCredentialDataAttribute:
  updateDnTemplate:
  useridAttribute: