LDAP User Persister
This plug-in binds to the LDAP server using a technical user. With this technical user, users are searched, read and updated. Make sure the technical user has enough access rights to perform these actions.
Note that setting passwords is done in an LDAP specific way such that it only works in conjunction with the password hash plug-in IdentityPasswordHash.
The method changeUsername(String oldUsername, String newUsername) is not implemented and will throw a NotImplementedException.
Working with Microsoft Active Directory (MSAD)
When setting passwords using this plug-in and an MSAD, the following settings must be used:- Set
password-attributetoUnicodePwd. - Set
password-attribute-is-stringtoFALSE. - Set
ad-like-password-settoTRUE. This will tell this plug-in that it has to deal with an MSAD and therefore set the password slightly different. (It encodes the new password specially for MSAD.)
connectionPool) searchContexts) Note that new users (using "insertUser(...)") will be added to one tree only. See property "Insert DN Template".
searchFilter) ${userId} to specify the user id in the search filter. The format and interpretation of filter follows RFC 2254. iteratorSearchFilter) UserIterator). If no filter is given, all entries in the specified search tree are returned from the directory. The format and interpretation of filter follows RFC 2254. useridAttribute) updateDnTemplate) Note: Usually it is not necessary (and not recommended) using an update template because it requires that the resulting DN is unique which is often not possible when searching with scope "subtree". This setting, however, can be very useful if the user directory service has no notion of "full names" and can therefore not determine the DN of search result by it-self.
insertDnTemplate) A DN-template is essential if users are inserted using this persister. If this plugin only reads and updates user data, this property is optional. If users have to be inserted, either this property or the property "update-dn-template" is mandatory. If both are defined, this property has precedence over the "update-dn-template" when inserting users.
insertObjectClasses) Note: When inserting a new entry into an LDAP, the object class defines a number of mandatory attributes. You must make sure that the corresponding attributes are inserted by adding the corresponding values to the new user's context data container and/or mapping other user values to the required attributes (e.g. map the user name to the cn attribute).
This property is only used if users are inserted using this plugin.
defaultAuthMethod) defaultNextAuthMethod) additionalInsertData) passwordAttribute) passwordAttributeIsString) adLikePasswordHandling) TRUE when using an active directory. forcePasswordChangeAttribute) orderPasswordAttribute) passwordOrderUserAttribute) passwordOrderDateAttribute) latestPasswordChangeDateAttribute) nextEnforcedPasswordChangeDateAttribute) passwordGenerationDateAttribute) passwordDeliveryDateAttribute) failedPasswordResetsAttribute) The name of the LDAP attribute holding the number of failed password reset attempts for flow-based password reset.
Security note: If this column is not specified, failed password reset attempts are not counted, which enables brute-force attacks.
otherCredentialsDeliveryTimestampAttributes) The type of every referenced column is either a
DATE or TIMESTAMP.
This information can be used by components that care about not delivering more than one user credential at the same time.
If this column is not specified, no delivery dates are provided to callers.
authMethodAttribute) nextAuthMethodAttribute) authMigrationDateAttribute) lockedAttribute) lockReasonAttribute) This can be the hole description of the reason or a key to the string resource.
lockDateAttribute) .
validAttribute) notValidBeforeAttribute) notValidAfterAttribute) failedLoginAttribute) failedLoginBeforeLatestSuccessfulLoginAttribute) failedTokenCountsAttribute) totalLoginsAttribute) latestLoginAttemptAttribute) latestSuccessfulLoginAttribute) secondLatestSuccessfulLoginAttribute) firstLoginAttribute) unlockAttemptsAttribute) latestUnlockAttemptAttribute) selfRegisteredAttribute) selfRegistrationDateAttribute) channelVerificationResendsAttribute) realmAttribute) Setting this attribute is mandatory when using the Multi-Realm feature. The column specificied here must not also be in the list of Context Data Attributes.
lastGSIDValueAttribute) lastGSIDDateAttribute) secretQuestionsEnabledAttribute) activeDirectoryLockedFlagSupported) activeDirectoryDisabledFlagSupported) activeDirectoryEnforcePasswordChangeFlagSupported) addObjectGuidToContextData) addImmutableIDToContextData) userDNContextDataAttribute) This DN is in the format "uid=user,ou=People,dc=company,dc=ch"
contextDataAttributes) Note: Context data attributes are string based. Values will be read as strings and are converted to string when written. In case the referenced attribute contains multiple values, the values will be read as a list of strings.
Notice: When using Active Directory and needing the special attribute "objectGUID" or "ImmutableID", please enable it in the "MSAD-specific Settings" instead to ensure proper encoding.
readOnlyAttributes) rolesAttribute) The attribute can have multiple values (= multiple occurrences of the attribute in the directory; not a comma-separated list of values).
Note that there are other ways to retrieve a user's roles from the directory. See configuration properties roles-search-* and static-roles.
rolesAttributeRdn) roles-attribute and when the role value is given as a full DN, e.g. "cn=admin,dc=groups,dc=auth,o=acme", you can specify the RDN which identifies the role name. In the previous example if you specify "cn" as the RDN then the value "admin" will be extracted. rolesNestedResolutionDepth) roles-attribute you can specify the depth of nested role resolution.
That is, if the user has a role superusers, which again has a role users then both roles are returned. A value of 0 turns off nested role resolution and looks for roles only on the current user object.
rolesNestedResolutionTopOnly) rolesNestedResolutionDepth with a value >0 you can specify whether all nested roles are selected or only the top-most roles.
For example, assume the user has a role superusers, which has a role users, which again has a role basicusers. If this property is enabled and the resolution depth is at least 2 then only the role basicusers is returned. If this property is enabled and the resolution depth is set to 1 the role users is returned. If this property is disabled all visited roles are returned (all three if the resolution depth is at least 2).
staticRoles) Note that there are other ways to retrieve a user's roles from the directory. See configuration properties roles-search-* and roles-attribute.
rolesSearchBase) roles-search-level, roles-search-filter, and roles-search-attribute this forms a flexible way to retrieve a user's role from the LDAP directory. The selected roles are granted to the user after successful authentication.
This attribute specifies the search context (subtree) where roles are searched. It must identify a subtree in the directory.
Note that there are other ways to retrieve a user's roles from the directory. See configuration properties roles-search-* and roles-attribute.
rolesSearchLevel) roles-search-base, roles-search-filter, and roles-search-attribute this forms a flexible way to retrieve a user's role from the LDAP directory. The selected roles are granted to the user after successful authentication.
This attribute specifies whether the search scope is the node selected by the configuration property
roles-search-base only or whether the serach scope is the whole subtree.
Note that there are other ways to retrieve a user's roles from the directory. See configuration properties roles-search-* and roles-attribute.
rolesSearchFilter) roles-search-base, roles-search-level, and roles-search-attribute this forms a flexible way to retrieve a user's role from the LDAP directory. The selected roles are granted to the user after successful authentication.
This attribute specifies an arbitrary filter applied when searching the roles. In the filter, you can refer to the user's DN by
${DN}, the username by ${userId} and you can use any attribute value listed of the context data container (values of attributes listed in configuration property context-data-attribute) by referring to it in the following way: ${attribute-name}.
Note that there are other ways to retrieve a user's roles from the directory. See configuration properties roles-search-* and roles-attribute.
rolesSearchAttribute) roles-search-base, roles-search-level, and roles-search-filter this forms a flexible way to retrieve a user's role from the LDAP directory. The selected roles are granted to the user after successful authentication.
This attribute specifies the name of the attribute with the role name in the result of the search. The attribute must select a string type attribute.
Note that there are other ways to retrieve a user's roles from the directory. See configuration properties roles-search-* and roles-attribute.
roleFilters) matchRolesCaseSensitive) searchResultPageSize) This property defines the amount of entries to fetch per page. When loading a large number of entries, paging improves performance. This setting may also be useful if the LDAP directory server limits the amount of entries in a search result.
If the property is set to zero (the default) or if the server does not announce support of the SimplePaging control, paging is disabled and all results will be loaded at once.
specialDateTimePattern) The used timezone is UTC or the local one if the flag
special-date-time-pattern-use-local-timezone ist set to true.
If this property is not defined, the LDAP-standard pattern yyyyMMddHHmmss.SSS'Z' is used.
specialDateTimePatternUseLocalTimezone) suppressSubstringSearch) This may greatly improve search performance in large directories.
userCountSearchFilter) Note: The user count is relevant for the product license. This filter should therefore describe the set of users who should be able to authenticate by Airlock IAM.
userChangeEventListeners)
type: LdapUserPersister
id: LdapUserPersister-xxxxxx
displayName:
comment:
properties:
activeDirectoryDisabledFlagSupported: false
activeDirectoryEnforcePasswordChangeFlagSupported: false
activeDirectoryLockedFlagSupported: false
adLikePasswordHandling: false
addImmutableIDToContextData: false
addObjectGuidToContextData: false
additionalInsertData:
authMethodAttribute:
authMigrationDateAttribute:
channelVerificationResendsAttribute:
connectionPool:
contextDataAttributes:
defaultAuthMethod:
defaultNextAuthMethod:
failedLoginAttribute:
failedLoginBeforeLatestSuccessfulLoginAttribute:
failedPasswordResetsAttribute:
failedTokenCountsAttribute:
firstLoginAttribute:
forcePasswordChangeAttribute:
insertDnTemplate:
insertObjectClasses: [inetOrgPerson]
iteratorSearchFilter:
lastGSIDDateAttribute:
lastGSIDValueAttribute:
latestLoginAttemptAttribute:
latestPasswordChangeDateAttribute:
latestSuccessfulLoginAttribute:
latestUnlockAttemptAttribute:
lockDateAttribute:
lockReasonAttribute:
lockedAttribute:
matchRolesCaseSensitive: true
nextAuthMethodAttribute:
nextEnforcedPasswordChangeDateAttribute:
notValidAfterAttribute:
notValidBeforeAttribute:
orderPasswordAttribute:
otherCredentialsDeliveryTimestampAttributes:
passwordAttribute:
passwordAttributeIsString: false
passwordDeliveryDateAttribute:
passwordGenerationDateAttribute:
passwordOrderDateAttribute:
passwordOrderUserAttribute:
readOnlyAttributes:
realmAttribute:
roleFilters:
rolesAttribute:
rolesAttributeRdn:
rolesNestedResolutionDepth: 0
rolesNestedResolutionTopOnly: false
rolesSearchAttribute:
rolesSearchBase:
rolesSearchFilter:
rolesSearchLevel: onelevel
searchContexts:
searchFilter:
searchResultPageSize: 0
secondLatestSuccessfulLoginAttribute:
secretQuestionsEnabledAttribute:
selfRegisteredAttribute:
selfRegistrationDateAttribute:
specialDateTimePattern:
specialDateTimePatternUseLocalTimezone: false
staticRoles:
suppressSubstringSearch: false
totalLoginsAttribute:
unlockAttemptsAttribute:
updateDnTemplate:
userChangeEventListeners:
userCountSearchFilter:
userDNContextDataAttribute:
useridAttribute:
validAttribute: