Access Cookie Identity Propagator
This plugin performs a HTTP POST request with the username and the password the user entered on a login form to the configured application and it expects this application to set an access cookie. This access cookie is then set to the response object involved in the identity propagation process.
This plugin requires that the caller of the identity propagator puts the username and the password into the parameter map. The username must be stored under the key USERNAME and the password under the key PASSWORD.
The plugin is thought to be used in situations where there is a legacy application providing access cookies after a weak authentication process (username and password) and these access cookie should be used in a different authenticaiton process for telling other legacy applications (that are "used to" the access cookie) about the authenticated user.
accessCookieSourceUrl) See note in plug-in description when using SSL (HTTPS instead of HTTP).
httpParamUsername) httpParams) In many cases, the submit button value must be sent to an application to make it think that the button has been pressed.
httpParamPassword) allowOnlyTrustedCerts) Only allow connections to servers whose certificate is trusted. See documentation of property "Trust Store Path" for more information about what certificates are trusted.
Security warning: Trusting all certificates allows connections to adversarial hosts. Only disable this property for testing and integration setups.
verifyServerHostname) Enables hostname verification, i.e. the actual hostname must be the same as in the server certificate.
Security warning: Not verifying the hostname may allow connections to adversarial hosts, e.g. if they employ DNS spoofing. Only disable this property for testing and integration setups.
trustStorePath) If this property is not defined the following certificate issuers are trusted:
- The list of issuers known to the Java VM if the system property "javax.net.ssl.trustStore" is not defined.
- The list of issuers in a keystore referenced by system property "javax.net.ssl.trustStore" if defined in instance.properties using iam.java.opts
If this property is defined then the following certificate issuers are trusted:
- The list of issuers in the referenced truststore file and no others.
This property is only relevant if the property "Allow Only Trusted Certs" is enabled.
trustStoreType) trustStorePassword) Depending on the keystore type, leaving this property empty (or undefined) has a different effect:
- In keystores like JKS, the keystore can be opened and used but the integrity of the keystore is not checked.
- In keystores like PKCS12, the keystore cannot be opened an an error occurs.
connectTimeout) correlationIdHeaderName) When configured, all requests sent contain a header with the correlation ID with the configured name. If no value or an empty value is specified, the correlation ID header is not sent.
If the correlation ID is not defined, the correlation ID header is not included in sent requests.
proxyHost) proxyPort) proxyLoginUser) proxyLoginPassword) cookies)
type: AccessCookieIdentityPropagator
id: AccessCookieIdentityPropagator-xxxxxx
displayName:
comment:
properties:
accessCookieSourceUrl:
allowOnlyTrustedCerts: true
connectTimeout: 10
cookies:
correlationIdHeaderName:
httpParamPassword:
httpParamUsername:
httpParams:
proxyHost:
proxyLoginPassword:
proxyLoginUser:
proxyPort:
trustStorePassword:
trustStorePath:
trustStoreType: JKS
verifyServerHostname: true