← Back to plugin index

LDAP User Persister

Description
User persister (extended) and iterator using a LDAP directory (also Active Directory) as repository.

This plug-in binds to the LDAP server using a technical user. With this technical user, users are searched, read and updated. Make sure the technical user has enough access rights to perform these actions.

Note that setting passwords is done in an LDAP specific way such that it only works in conjunction with the password hash plug-in IdentityPasswordHash.

The method changeUsername(String oldUsername, String newUsername) is not implemented and will throw a NotImplementedException.

Working with Microsoft Active Directory (MSAD)

When setting passwords using this plug-in and an MSAD, the following settings must be used:
  • Set password-attribute to UnicodePwd.
  • Set password-attribute-is-string to FALSE.
  • Set ad-like-password-set to TRUE. This will tell this plug-in that it has to deal with an MSAD and therefore set the password slightly different. (It encodes the new password specially for MSAD.)
Type name
LdapUserPersister
Class
com.airlock.iam.core.misc.impl.persistency.ldap.LdapUserPersister
May be used by
Properties
Connection Pool (connectionPool)
Description
The connection pool connecting to the LDAP directory (or active directory).
Attributes
Plugin-Link
Mandatory
Assignable plugins
Search Contexts (searchContexts)
Description
Defines a list of search contexts (search trees with search levels) to use when looking for users. The search contexts are used in the defined order.

Note that new users (using "insertUser(...)") will be added to one tree only. See property "Insert DN Template".

Attributes
Plugin-List
Mandatory
Assignable plugins
Search Filter (searchFilter)
Description
The LDAP search filter expression to extract a single user given its username. You must make sure, that the query - performed relative to the specified search-tree - results in exactly one entry. Use the variable notation ${userId} to specify the user id in the search filter. The format and interpretation of filter follows RFC 2254.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Iterator Search Filter (iteratorSearchFilter)
Description
The LDAP search filter expression applied when iterating over users (only used if used as UserIterator). If no filter is given, all entries in the specified search tree are returned from the directory. The format and interpretation of filter follows RFC 2254.
Attributes
Plugin-Link
Optional
Assignable plugins
Userid Attribute (useridAttribute)
Description
The LDAP attribute which holds the user id. This is in most cases the same attribute used in the search filter.
Attributes
String
Mandatory
Suggested values
cn, sAMAccountName, userPrincipalName, uid
Update Dn Template (updateDnTemplate)
Description
Distinguished name (DN) template used for updating the user in the LDAP directory. Use ${userId} to specify the user id. Use ${xxx} to use the context data value with name xxx. The resulting DN must uniquely identify the user's LDAP entry.

Note: Usually it is not necessary (and not recommended) using an update template because it requires that the resulting DN is unique which is often not possible when searching with scope "subtree". This setting, however, can be very useful if the user directory service has no notion of "full names" and can therefore not determine the DN of search result by it-self.

Attributes
String
Optional
Example
uid=${userId},ou=users,o=test
Example
cn=${userId},cn=users,dc=exchangeserver,dc=yourcompany,dc=com
Insert Dn Template (insertDnTemplate)
Description
Distinguished name (DN) template used for inserting new users into the LDAP directory. Use ${userId} to specify the user id (username). Use ${xxx} to use the context data value with name xxx. The resulting DN must be a correct DN for a newly inserted user. If an update-dn-template is set (see separate configuration property), then this property has usually the same value.

A DN-template is essential if users are inserted using this persister. If this plugin only reads and updates user data, this property is optional. If users have to be inserted, either this property or the property "update-dn-template" is mandatory. If both are defined, this property has precedence over the "update-dn-template" when inserting users.

Attributes
String
Optional
Example
uid=${userId},ou=users,o=test
Example
cn=${userId},cn=users,dc=exchangeserver,dc=yourcompany,dc=com
Insert Object Classes (insertObjectClasses)
Description
Object class used for newly inserted users. (At least one object class must be structural.)

Note: When inserting a new entry into an LDAP, the object class defines a number of mandatory attributes. You must make sure that the corresponding attributes are inserted by adding the corresponding values to the new user's context data container and/or mapping other user values to the required attributes (e.g. map the user name to the cn attribute).

This property is only used if users are inserted using this plugin.

Attributes
String-List
Optional
Default value
[inetOrgPerson]
Default Auth Method (defaultAuthMethod)
Description
The default authentication method value used when inserting new users that have no auth method set. This is only used if an authentication method attribute is configured.
Attributes
String
Optional
Suggested values
PASSWORD, MATRIX, MTAN, OATH_OTP, CERTIFICATE, CRONTO, EMAILOTP, SECURID, SECOVID
Default Next Auth Method (defaultNextAuthMethod)
Description
The default next authentication method value used when inserting new users that have no next auth method set. This is only used if a next authentication method attribute is configured.
Attributes
String
Optional
Suggested values
PASSWORD, MATRIX, MTAN, OATH_OTP, CERTIFICATE, EMAILOTP, SECURID, SECOVID
Additional Insert Data (additionalInsertData)
Description
A List of additional user insert data. If the same attribute is already defined, an exception will be thrown.
Attributes
Plugin-List
Optional
Assignable plugins
Password Attribute (passwordAttribute)
Description
The LDAP attribute which holds the password or its hash value.
Attributes
String
Optional
Example
password
Example
unicodePwd
Password Attribute Is String (passwordAttributeIsString)
Description
Optional flag indicating whether the password attribute is string type or not. Usually, the password attribute is stored in an LDAP directory as a binary hash value and has to be treated differently from string passwords.
Attributes
Boolean
Optional
Default value
false
Ad Like Password Handling (adLikePasswordHandling)
Description
Optional flag telling the plug-in that is has to deal with a Microsoft Active Directory (MSAD). Set this property to TRUE when using an active directory.
Attributes
Boolean
Optional
Default value
false
Force Password Change Attribute (forcePasswordChangeAttribute)
Description
The name of the LDAP attribute holding the force password flag.
Attributes
String
Optional
Example
forcePwdChange
Order Password Attribute (orderPasswordAttribute)
Description
The name of the LDAP attribute holding the order password flag. This attribute is used for batch processes generating password letters and alike.
Attributes
String
Optional
Example
orderNewPassword
Password Order User Attribute (passwordOrderUserAttribute)
Description
The name of the LDAP attribute holding the user by whom the new password was ordered. This attribute is used for batch processes generating password letters and alike.
Attributes
String
Optional
Example
passwordOrderUser
Password Order Date Attribute (passwordOrderDateAttribute)
Description
The name of the LDAP attribute holding the date when the new password was ordered. This attribute is used for batch processes generating password letters and alike.
Attributes
String
Optional
Example
passwordOrderDate
Latest Password Change Date Attribute (latestPasswordChangeDateAttribute)
Description
The name of the LDAP attribute holding the date of the latest password change.
Attributes
String
Optional
Example
latestPasswordChangeDateAttribute
Next Enforced Password Change Date Attribute (nextEnforcedPasswordChangeDateAttribute)
Description
The name of the LDAP attribute holding the date of the next enforced password change.
Attributes
String
Optional
Example
nextEnforcedPasswordChangeDateAttribute
Password Generation Date Attribute (passwordGenerationDateAttribute)
Description
The name of the LDAP attribute holding the password generation date. This attribute is used for batch processes generating password letters and alike.
Attributes
String
Optional
Example
passwordGenerationDate
Password Delivery Date Attribute (passwordDeliveryDateAttribute)
Description
The name of the LDAP attribute holding the password delivery date. This attribute is used for batch processes generating password letters and alike.
Attributes
String
Optional
Example
passwordDeliveryDate
Failed Password Resets Attribute (failedPasswordResetsAttribute)
Description

The name of the LDAP attribute holding the number of failed password reset attempts for flow-based password reset.

Security note: If this column is not specified, failed password reset attempts are not counted, which enables brute-force attacks.

Attributes
String
Optional
Suggested values
failedPasswordResets
Other Credentials Delivery Timestamp Attributes (otherCredentialsDeliveryTimestampAttributes)
Description
list of column names with the delivery dates of other credentials.
The type of every referenced column is either a DATE or TIMESTAMP.
This information can be used by components that care about not delivering more than one user credential at the same time.
If this column is not specified, no delivery dates are provided to callers.
Attributes
String-List
Optional
Auth Method Attribute (authMethodAttribute)
Description
The name of the LDAP attribute holding the user's authentication method.
Attributes
String
Optional
Example
authMethod
Next Auth Method Attribute (nextAuthMethodAttribute)
Description
The name of the LDAP attribute holding the user's authentication method after migration.
Attributes
String
Optional
Example
nextAuthMethod
Auth Migration Date Attribute (authMigrationDateAttribute)
Description
The name of the LDAP attribute holding the date until which the migration of the auth method has to be performed.
Attributes
String
Optional
Example
authMigrationDate
Locked Attribute (lockedAttribute)
Description
The name of the LDAP attribute holding the locked status flag.
Attributes
String
Optional
Example
locked
Lock Reason Attribute (lockReasonAttribute)
Description
The name of the LDAP attribute contains the reason why the users is locked.
This can be the hole description of the reason or a key to the string resource.
Attributes
String
Optional
Example
lockReason
Lock Date Attribute (lockDateAttribute)
Description
The name of the LDAP attribute contains the timestamp of the user locking.
.
Attributes
String
Optional
Example
lockDate
Valid Attribute (validAttribute)
Description
The name of the LDAP attribute telling if the user is valid or not. This attribute is only read but not written (i.e. cannot be changed on the directory).
Attributes
String
Optional
Example
valid
Not Valid Before Attribute (notValidBeforeAttribute)
Description
The name of the LDAP attribute indicating the point in time before which a user is considered not valid yet. The attribute must contain a timestamp.
Attributes
String
Optional
Example
notValidBefore
Not Valid After Attribute (notValidAfterAttribute)
Description
The name of the LDAP attribute indicating the point in time after which a user is considered not valid anymore. The attribute must contain a timestamp.
Attributes
String
Optional
Example
notValidAfter
Failed Login Attribute (failedLoginAttribute)
Description
The name of the LDAP attribute holding the number of failed logins. If this attribute is not specified, the number of failed logins is not counted and the user is not locked after a certain amount of failed logins even if the maximum number of failed logins is specified in the authenticator.
Attributes
String
Optional
Example
failedLogins
Failed Login Before Latest Successful Login Attribute (failedLoginBeforeLatestSuccessfulLoginAttribute)
Description
The name of the LDAP attribute holding the number of failed logins before the latest successful login. If this attribute is not specified, the number of failed logins before the latest successful login is not counted.
Attributes
String
Optional
Example
failedLoginsBeforeLatestSuccessfulLogin
Failed Token Counts Attribute (failedTokenCountsAttribute)
Description
The name of the LDAP attribute holding the failed attempts on authentication tokens (for the flow-based REST API). If this attribute is not specified, the failed token attempts are not counted.
Attributes
String
Optional
Example
failedTokenCounts
Total Logins Attribute (totalLoginsAttribute)
Description
The name of the LDAP attribute holding the total number of successful logins. If this attribute is not specified, the total number of logins is not counted.
Attributes
String
Optional
Example
totalLogins
Latest Login Attempt Attribute (latestLoginAttemptAttribute)
Description
The name of the LDAP attribute holding the date and time of the latest login attempt.
Attributes
String
Optional
Example
latestLoginAttempt
Latest Successful Login Attribute (latestSuccessfulLoginAttribute)
Description
The name of the LDAP attribute holding the date and time of the latest successful login.
Attributes
String
Optional
Example
latestSuccessfulLogin
Second Latest Successful Login Attribute (secondLatestSuccessfulLoginAttribute)
Description
The name of the LDAP attribute holding the date and time of the second latest successful login.
Attributes
String
Optional
Example
secondLatestSuccessfulLogin
First Login Attribute (firstLoginAttribute)
Description
The name of the LDAP attribute holding the date and time of the very first login.
Attributes
String
Optional
Example
firstLogin
Unlock Attempts Attribute (unlockAttemptsAttribute)
Description
The name of the LDAP attribute holding the number of failed unlock attempts.
Attributes
String
Optional
Example
unlockAttempts
Latest Unlock Attempt Attribute (latestUnlockAttemptAttribute)
Description
The name of the LDAP attribute holding the date and time of the latest unlock attempt.
Attributes
String
Optional
Example
latestUnlockAttempt
Self Registered Attribute (selfRegisteredAttribute)
Description
The name of the LDAP attribute holding the flag indicating if a user is self-registered.
Attributes
String
Optional
Example
selfRegisteredFlag
Self Registration Date Attribute (selfRegistrationDateAttribute)
Description
The name of the LDAP attribute holding the self-registration date (if applicable).
Attributes
String
Optional
Example
selfRegistrationDate
Channel Verification Resends Attribute (channelVerificationResendsAttribute)
Description
Name of the LDAP attribute holding the number of completed resends of the channel verification token during the user's self-registration.
Attributes
String
Optional
Suggested values
channelVerificationResends
Realm Attribute (realmAttribute)
Description
Name of the LDAP attribute holding the realm of the user.
Setting this attribute is mandatory when using the Multi-Realm feature. The column specificied here must not also be in the list of Context Data Attributes.
Attributes
String
Optional
Suggested values
realm
Last GSID Value Attribute (lastGSIDValueAttribute)
Description
Name of the LDAP attribute holding the last global session id.
Attributes
String
Optional
Suggested values
lastGsidValue
Last GSID Date Attribute (lastGSIDDateAttribute)
Description
Name of the LDAP attribute holding the last update timestamp for the global session id.
Attributes
String
Optional
Suggested values
lastGsidDate
Secret Questions Enabled Attribute (secretQuestionsEnabledAttribute)
Description
Name of the LDAP attribute holding the secret questions enable/disable flag.
Attributes
String
Optional
Suggested values
secretQuestionsEnabled
Active Directory Locked Flag Supported (activeDirectoryLockedFlagSupported)
Description
Optional flag telling the plug-in that the locked state is managed by MSAD setting the UserAccountControl attribute. If enabled, the locked flags are read only.
Attributes
Boolean
Optional
Default value
false
Active Directory Disabled Flag Supported (activeDirectoryDisabledFlagSupported)
Description
Optional flag telling the plug-in to use the MSAD UserAccountControl attribute to handle enable/disable. If enabled, the valid flag and the valid-from- and valid-to-dates cannot be written into the directory by this plugin.
Attributes
Boolean
Optional
Default value
false
Active Directory Enforce Password Change Flag Supported (activeDirectoryEnforcePasswordChangeFlagSupported)
Description
Optional flag telling the plug-in to use the MSAD pwdLastSet attribute to handle enforced password change. If enabled the password change enforced flag is read only.
Attributes
Boolean
Optional
Default value
false
Add objectGUID To Context Data (addObjectGuidToContextData)
Description
If enabled, the "objectGUID" attribute will be added read-only as context data attribute in its canonical form, e.g. "abcdef12-3456-7890-abcd-ef1234567890".
Attributes
Boolean
Optional
Default value
false
Add ImmutableID To Context Data (addImmutableIDToContextData)
Description
If enabled, the "ImmutableID" attribute will be added read-only as context data attribute, representing the Base64-Encoded objectGUID.
Attributes
Boolean
Optional
Default value
false
User DN Context Data Attribute (userDNContextDataAttribute)
Description
The name of the attribute to store the user's DN into.
This DN is in the format "uid=user,ou=People,dc=company,dc=ch"
Attributes
String
Optional
Example
dn
Context Data Attributes (contextDataAttributes)
Description
A list of attribute names that are loaded into the context data container of the user. This can be used to transport arbitrary information such as user address information to calling plug-ins.
Note: Context data attributes are string based. Values will be read as strings and are converted to string when written. In case the referenced attribute contains multiple values, the values will be read as a list of strings.

Notice: When using Active Directory and needing the special attribute "objectGUID" or "ImmutableID", please enable it in the "MSAD-specific Settings" instead to ensure proper encoding.

Attributes
String-List
Optional
Read Only Attributes (readOnlyAttributes)
Description
A list of attribute names that must not be written to.
Attributes
String-List
Optional
Roles Attribute (rolesAttribute)
Description
Name of the LDAP attribute holding a list of roles granted to the user after successful authentication.
The attribute can have multiple values (= multiple occurrences of the attribute in the directory; not a comma-separated list of values).

Note that there are other ways to retrieve a user's roles from the directory. See configuration properties roles-search-* and static-roles.

Attributes
String
Optional
Example
roles
Example
userRoles
Roles Attribute RDN (rolesAttributeRdn)
Description
When using the property roles-attribute and when the role value is given as a full DN, e.g. "cn=admin,dc=groups,dc=auth,o=acme", you can specify the RDN which identifies the role name. In the previous example if you specify "cn" as the RDN then the value "admin" will be extracted.
Attributes
String
Optional
Example
cn
Example
role
Roles Nested Resolution Depth (rolesNestedResolutionDepth)
Description
When using the property roles-attribute you can specify the depth of nested role resolution.

That is, if the user has a role superusers, which again has a role users then both roles are returned. A value of 0 turns off nested role resolution and looks for roles only on the current user object.

Attributes
Integer
Optional
Default value
0
Roles Nested Resolution Top Only (rolesNestedResolutionTopOnly)
Description
When using the property rolesNestedResolutionDepth with a value >0 you can specify whether all nested roles are selected or only the top-most roles.

For example, assume the user has a role superusers, which has a role users, which again has a role basicusers. If this property is enabled and the resolution depth is at least 2 then only the role basicusers is returned. If this property is enabled and the resolution depth is set to 1 the role users is returned. If this property is disabled all visited roles are returned (all three if the resolution depth is at least 2).

Attributes
Boolean
Optional
Default value
false
Static Roles (staticRoles)
Description
List of roles granted to authenticated users.

Note that there are other ways to retrieve a user's roles from the directory. See configuration properties roles-search-* and roles-attribute.

Attributes
String-List
Optional
Roles Search Base (rolesSearchBase)
Description
Together with the attributes roles-search-level, roles-search-filter, and roles-search-attribute this forms a flexible way to retrieve a user's role from the LDAP directory. The selected roles are granted to the user after successful authentication.
This attribute specifies the search context (subtree) where roles are searched. It must identify a subtree in the directory.

Note that there are other ways to retrieve a user's roles from the directory. See configuration properties roles-search-* and roles-attribute.

Attributes
String
Optional
Example
CN=roles,dc=exchangeserver,dc=company,dc=com
Roles Search Level (rolesSearchLevel)
Description
Together with the attributes roles-search-base, roles-search-filter, and roles-search-attribute this forms a flexible way to retrieve a user's role from the LDAP directory. The selected roles are granted to the user after successful authentication.
This attribute specifies whether the search scope is the node selected by the configuration property roles-search-base only or whether the serach scope is the whole subtree.

Note that there are other ways to retrieve a user's roles from the directory. See configuration properties roles-search-* and roles-attribute.

Attributes
Enum
Optional
Default value
onelevel
Roles Search Filter (rolesSearchFilter)
Description
Together with the attributes roles-search-base, roles-search-level, and roles-search-attribute this forms a flexible way to retrieve a user's role from the LDAP directory. The selected roles are granted to the user after successful authentication.
This attribute specifies an arbitrary filter applied when searching the roles. In the filter, you can refer to the user's DN by ${DN}, the username by ${userId} and you can use any attribute value listed of the context data container (values of attributes listed in configuration property context-data-attribute) by referring to it in the following way: ${attribute-name}.

Note that there are other ways to retrieve a user's roles from the directory. See configuration properties roles-search-* and roles-attribute.

Attributes
String
Optional
Example
(member=${DN})
Example
(userId=${userId})
Example
&(userId=${userId})(memberOf=CN=@VPNMail,OU=${town},DC=company,DC=com))
Roles Search Attribute (rolesSearchAttribute)
Description
Together with the attributes roles-search-base, roles-search-level, and roles-search-filter this forms a flexible way to retrieve a user's role from the LDAP directory. The selected roles are granted to the user after successful authentication.
This attribute specifies the name of the attribute with the role name in the result of the search. The attribute must select a string type attribute.

Note that there are other ways to retrieve a user's roles from the directory. See configuration properties roles-search-* and roles-attribute.

Attributes
String
Optional
Example
role
Example
cn
Role Filters (roleFilters)
Description
Allows filtering of retrieved user roles. If configured, only roles that match at least one of the filter patterns are assigned to the user. Static roles are not filtered.
Attributes
RegEx-List
Optional
Match Roles Case Sensitive (matchRolesCaseSensitive)
Description
If enabled, roles are matched against the role filters considering the case (the default).
Attributes
Boolean
Optional
Default value
true
Search Result Page Size (searchResultPageSize)
Description
If set to a value greater than zero and if the LDAP server supports the SimplePaging control, paging is enabled for LDAP searches.
This property defines the amount of entries to fetch per page. When loading a large number of entries, paging improves performance. This setting may also be useful if the LDAP directory server limits the amount of entries in a search result.
If the property is set to zero (the default) or if the server does not announce support of the SimplePaging control, paging is disabled and all results will be loaded at once.
Attributes
Integer
Optional
Default value
0
Special Date Time Pattern (specialDateTimePattern)
Description
Optional special date formatter / parser pattern used to read and write timestamps in a different way than in standard LDAP. This may be useful if timestamps are stored in some proprietary way as strings in a directory.
The used timezone is UTC or the local one if the flag special-date-time-pattern-use-local-timezone ist set to true.

If this property is not defined, the LDAP-standard pattern yyyyMMddHHmmss.SSS'Z' is used.

Attributes
String
Optional
Suggested values
yyyyMMddHHmmss, yyyyMMddHHmmss'Z', MM-dd-yyyy HH:mm:ss
Special Date Time Pattern Use Local Timezone (specialDateTimePatternUseLocalTimezone)
Description
Optional flag telling the plug-in that the special date formatter should use the local timezone.
Attributes
Boolean
Optional
Default value
false
Suppress Substring Search (suppressSubstringSearch)
Description
If enabled, substring string searches are suppressed, i.e. attributes do only match a filter if the whole filter string matches.
This may greatly improve search performance in large directories.
Attributes
Boolean
Optional
Default value
false
User Count Search Filter (userCountSearchFilter)
Description
The LDAP search filter expression applied (in addition to the "Iterator Search Filter" expression if present) to count the users. If no filter expression is given, the "Iterator Search Filter" expression is used to determine the user count. If also no "Iterator Search Filter" expression is given the default filter is used to determine the user count. The format and interpretation of filter follows RFC 2254.

Note: The user count is relevant for the product license. This filter should therefore describe the set of users who should be able to authenticate by Airlock IAM.

Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: LdapUserPersister
id: LdapUserPersister-xxxxxx
displayName: 
comment: 
properties:
  activeDirectoryDisabledFlagSupported: false
  activeDirectoryEnforcePasswordChangeFlagSupported: false
  activeDirectoryLockedFlagSupported: false
  adLikePasswordHandling: false
  addImmutableIDToContextData: false
  addObjectGuidToContextData: false
  additionalInsertData:
  authMethodAttribute:
  authMigrationDateAttribute:
  channelVerificationResendsAttribute:
  connectionPool:
  contextDataAttributes:
  defaultAuthMethod:
  defaultNextAuthMethod:
  failedLoginAttribute:
  failedLoginBeforeLatestSuccessfulLoginAttribute:
  failedPasswordResetsAttribute:
  failedTokenCountsAttribute:
  firstLoginAttribute:
  forcePasswordChangeAttribute:
  insertDnTemplate:
  insertObjectClasses: [inetOrgPerson]
  iteratorSearchFilter:
  lastGSIDDateAttribute:
  lastGSIDValueAttribute:
  latestLoginAttemptAttribute:
  latestPasswordChangeDateAttribute:
  latestSuccessfulLoginAttribute:
  latestUnlockAttemptAttribute:
  lockDateAttribute:
  lockReasonAttribute:
  lockedAttribute:
  matchRolesCaseSensitive: true
  nextAuthMethodAttribute:
  nextEnforcedPasswordChangeDateAttribute:
  notValidAfterAttribute:
  notValidBeforeAttribute:
  orderPasswordAttribute:
  otherCredentialsDeliveryTimestampAttributes:
  passwordAttribute:
  passwordAttributeIsString: false
  passwordDeliveryDateAttribute:
  passwordGenerationDateAttribute:
  passwordOrderDateAttribute:
  passwordOrderUserAttribute:
  readOnlyAttributes:
  realmAttribute:
  roleFilters:
  rolesAttribute:
  rolesAttributeRdn:
  rolesNestedResolutionDepth: 0
  rolesNestedResolutionTopOnly: false
  rolesSearchAttribute:
  rolesSearchBase:
  rolesSearchFilter:
  rolesSearchLevel: onelevel
  searchContexts:
  searchFilter:
  searchResultPageSize: 0
  secondLatestSuccessfulLoginAttribute:
  secretQuestionsEnabledAttribute:
  selfRegisteredAttribute:
  selfRegistrationDateAttribute:
  specialDateTimePattern:
  specialDateTimePatternUseLocalTimezone: false
  staticRoles:
  suppressSubstringSearch: false
  totalLoginsAttribute:
  unlockAttemptsAttribute:
  updateDnTemplate:
  userChangeEventListeners:
  userCountSearchFilter:
  userDNContextDataAttribute:
  useridAttribute:
  validAttribute: