← Back to plugin index

LDAP Token List Persister

Description
User persister (extended) and iterator using a LDAP directory (also Active Directory) as repository.

Access to the directory is done using UnboundID LDAP SDK.

This plug-in binds to the LDAP server using a technical user. With this technical user, users are searched, read and updated. Make sure the technical user has enough access rights to perform these actions.

Note that setting passwords is done in an LDAP specific way such that it only works in conjunction with the password hash plug-in IdentityPasswordHash.
Make sure that users of this implementation (e.g. Loginapp and password change applications) use the IdentityPasswordHash plug-in as password hash function.

The method changeUsername(String oldUsername, String newUsername) is not implemented and will throw a NotImplementedException.

Working with Microsoft Active Directory (MSAD)

When setting passwords using this plug-in and an MSAD, the following settings must be used:
  • Set password-attribute to UnicodePwd.
  • Set password-attribute-is-string to FALSE.
  • Set ad-like-password-set to TRUE. This will tell this plug-in that it has to deal with an MSAD and therefore set the password slightly different. (It encodes the new password specially for MSAD.)
Type name
LdapTokenListPersister
Class
com.airlock.iam.core.misc.impl.persistency.ldap.LdapTokenListPersister
May be used by
Properties
Connection Pool (connectionPool)
Description
The connection pool connecting to the LDAP directory (or active directory).
Attributes
Plugin-Link
Mandatory
Assignable plugins
Search Contexts (searchContexts)
Description
Defines a list of search contexts (search trees with search levels) to use when looking for token list records. The search contexts are used in the defined order.
Attributes
Plugin-List
Mandatory
Assignable plugins
Search Filter (searchFilter)
Description
The LDAP search filter expression to extract a single user given its username. You must make sure, that the query - performed relative to the specified search-tree - results in exactly one entry. Use the variable notation ${userId} to specify the user id in the search filter. The format and interpretation of filter follows RFC 2254.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Iterator Search Filter (iteratorSearchFilter)
Description
The LDAP search filter expression applied when iterating over users (only used if used as UserIterator). If no filter is given, all entries in the specified search tree are returned from the directory. The format and interpretation of filter follows RFC 2254.
Attributes
Plugin-Link
Optional
Assignable plugins
Userid Attribute (useridAttribute)
Description
The LDAP attribute which holds the user id. This is in most cases the same attribute used in the search filter.
Attributes
String
Mandatory
Example
cn
Example
sAMAccountName
Example
userId
Update Dn Template (updateDnTemplate)
Description
Distinguished name (DN) template used for updating the user in the LDAP directory. Use ${userId} to specify the user id. The resulting DN must uniquely identify the user's LDAP entry.

Note: Usually it is not necessary (and not recommended) using an update template because it requires that the resulting DN is unique which is often not possible when searching with scope "subtree". This setting, however, can be very useful if the user directory service has no notion of "full names" and can therefore not determine the DN of search result by it-self.

Attributes
String
Optional
Example
uid=${userId},ou=users,o=test
Example
cn=${userId},cn=users,dc=exchangeserver,dc=yourcompany,dc=com
Token List Attribute (tokenListAttribute)
Description
The LDAP attribute with the binary hash values of the current token list.
The corresponding attribute must be able to store binary data.
Attributes
String
Mandatory
Example
tokenList
Example
matrixCard
Next Token List Attribute (nextTokenListAttribute)
Description
The LDAP attribute with the binary hash values of the next token list.
The corresponding attribute must be able to store binary data.
Attributes
String
Mandatory
Example
nextTokenList
Example
matrixCardNext
Active Attribute (activeAttribute)
Description
The name of the LDAP attribute column with the flag indicating whether the tokenlist is active or not. Inactive tokenlists may not be used by the callers.
If the column is not specified, all tokenlists are considered to be active.
Attributes
String
Optional
Example
active
Example
matrixCardActive
Challenge Open Since Attribute (challengeOpenSinceAttribute)
Description
Name of the LDAP attribute with the timestamp of the start of an ongoing challenge.
Attributes
String
Optional
Suggested values
challengeOpenSince, matrixChalOpenSince
Unanswered Challenges Attribute (unansweredChallengesAttribute)
Description
Name of the LDAP attribute with the number of unanswered challenges.
Attributes
String
Optional
Suggested values
unansweredChallenges, matrixOpenChals
Delivery Date Attribute (deliveryDateAttribute)
Description
The name of the LDAP attribute column with the date and time of the latest tokenlist delivery.
Attributes
String
Optional
Example
latestTokenListDelivery
Example
matrixCardDeliveryDate
Other Credentials Delivery Dates Attributes (otherCredentialsDeliveryDatesAttributes)
Description
Comma-separated list of LDAP attribtues with the delivery dates of other credentials. This information may be used in order to delay the delivery time for credentials so no two credentials of the same user are delivered the same day.
Attributes
String-List
Optional
Generation Date Attribute (generationDateAttribute)
Description
The name of the LDAP attributes with the date and time of the latest tokenlist generation or assignment.
Attributes
String
Optional
Example
tokenListGenerationDate
Example
matrixCardGenerationDate
Ordered Attribute (orderedAttribute)
Description
The name of the LDAP attribute with the flag indicating whether a new tokenlist should be generated for the user.
Attributes
String
Optional
Example
orderNewTokenlist
Example
matrixCardOrdered
Ordered User Attribute (orderedUserAttribute)
Description
The name of the LDAP attribute with the user by whom a new tokenlist was ordered to be generated for the user.
Attributes
String
Optional
Example
orderNewTokenlistUser
Example
orderMatrixCardUser
Ordered Date Attribute (orderedDateAttribute)
Description
The name of the LDAP attribute with the date of when a new tokenlist was ordered to be generated for the user.
Attributes
String
Optional
Example
orderNewTokenlistDate
Example
orderMatrixCardDate
Context Data Attributes (contextDataAttributes)
Description
A list of attribute names that are loaded into the context data container of the token list. This can be used to transport arbitrary information such as user address information to calling plug-ins.
Attributes
String-List
Optional
Read Only Attributes (readOnlyAttributes)
Description
A list of attribute names that are to be treated read-only.
Attributes
String-List
Optional
Search Result Page Size (searchResultPageSize)
Description
If set to a value greater than zero, "paging" is enabled for LDAP searches: This property defines the amount of entries to fetch at once when searching in a directory. This setting may be useful if the LDAP directory server limits the amount of entries in a search result.
If the property is set to zero (the default), paging is disabled.
Attributes
Integer
Optional
Default value
0
Special Date Time Pattern (specialDateTimePattern)
Description
Optional special date formatter / parser pattern used to read and write timestamps in a different way than in standard LDAP. This may be useful if timestamps are stored in some proprietary way as strings in a directory.
The used timezone is UTC or the local one if the flag special-date-time-pattern-use-local-timezone ist set to true.

If this property is not defined, the LDAP-standard pattern yyyyMMddHHmmss.SSS'Z' is used.

Attributes
String
Optional
Suggested values
yyyyMMddHHmmss, yyyyMMddHHmmss'Z', MM-dd-yyyy HH:mm:ss
Special Date Time Pattern Use Local Timezone (specialDateTimePatternUseLocalTimezone)
Description
Optional flag telling the plug-in that the special date formatter should use the local timezone.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: LdapTokenListPersister
id: LdapTokenListPersister-xxxxxx
displayName: 
comment: 
properties:
  activeAttribute:
  challengeOpenSinceAttribute:
  connectionPool:
  contextDataAttributes:
  deliveryDateAttribute:
  generationDateAttribute:
  iteratorSearchFilter:
  nextTokenListAttribute:
  orderedAttribute:
  orderedDateAttribute:
  orderedUserAttribute:
  otherCredentialsDeliveryDatesAttributes:
  readOnlyAttributes:
  searchContexts:
  searchFilter:
  searchResultPageSize: 0
  specialDateTimePattern:
  specialDateTimePatternUseLocalTimezone: false
  tokenListAttribute:
  unansweredChallengesAttribute:
  updateDnTemplate:
  useridAttribute: