LDAP Token List Persister
Access to the directory is done using UnboundID LDAP SDK.
This plug-in binds to the LDAP server using a technical user. With this technical user, users are searched, read and updated. Make sure the technical user has enough access rights to perform these actions.
Note that setting passwords is done in an LDAP specific way such that it only works in conjunction with the password hash plug-in IdentityPasswordHash.
Make sure that users of this implementation (e.g. Loginapp and password change applications) use the IdentityPasswordHash plug-in as password hash function.
The method changeUsername(String oldUsername, String newUsername) is not implemented and will throw a NotImplementedException.
Working with Microsoft Active Directory (MSAD)
When setting passwords using this plug-in and an MSAD, the following settings must be used:- Set
password-attributetoUnicodePwd. - Set
password-attribute-is-stringtoFALSE. - Set
ad-like-password-settoTRUE. This will tell this plug-in that it has to deal with an MSAD and therefore set the password slightly different. (It encodes the new password specially for MSAD.)
connectionPool) searchContexts) searchFilter) ${userId} to specify the user id in the search filter. The format and interpretation of filter follows RFC 2254. iteratorSearchFilter) UserIterator). If no filter is given, all entries in the specified search tree are returned from the directory. The format and interpretation of filter follows RFC 2254. useridAttribute) updateDnTemplate) Note: Usually it is not necessary (and not recommended) using an update template because it requires that the resulting DN is unique which is often not possible when searching with scope "subtree". This setting, however, can be very useful if the user directory service has no notion of "full names" and can therefore not determine the DN of search result by it-self.
tokenListAttribute) The corresponding attribute must be able to store binary data.
nextTokenListAttribute) The corresponding attribute must be able to store binary data.
activeAttribute) If the column is not specified, all tokenlists are considered to be active.
challengeOpenSinceAttribute) unansweredChallengesAttribute) deliveryDateAttribute) otherCredentialsDeliveryDatesAttributes) generationDateAttribute) orderedAttribute) orderedUserAttribute) orderedDateAttribute) contextDataAttributes) readOnlyAttributes) searchResultPageSize) If the property is set to zero (the default), paging is disabled.
specialDateTimePattern) The used timezone is UTC or the local one if the flag
special-date-time-pattern-use-local-timezone ist set to true.
If this property is not defined, the LDAP-standard pattern yyyyMMddHHmmss.SSS'Z' is used.
specialDateTimePatternUseLocalTimezone)
type: LdapTokenListPersister
id: LdapTokenListPersister-xxxxxx
displayName:
comment:
properties:
activeAttribute:
challengeOpenSinceAttribute:
connectionPool:
contextDataAttributes:
deliveryDateAttribute:
generationDateAttribute:
iteratorSearchFilter:
nextTokenListAttribute:
orderedAttribute:
orderedDateAttribute:
orderedUserAttribute:
otherCredentialsDeliveryDatesAttributes:
readOnlyAttributes:
searchContexts:
searchFilter:
searchResultPageSize: 0
specialDateTimePattern:
specialDateTimePatternUseLocalTimezone: false
tokenListAttribute:
unansweredChallengesAttribute:
updateDnTemplate:
useridAttribute: