← Back to plugin index

Kerberos Identity Propagator (requires Airlock Gateway)

Description
Propagates user information using back-side Kerberos with Airlock WAF.

This propagator only works together with Airlock Gateway (WAF) 6.0 or later. It uses the Gateway's control API to propagate username and domain.

Type name
KerberosIdentityPropagator
Class
com.airlock.iam.core.misc.impl.sso.KerberosIdentityPropagator
May be used by
Properties
Kerberos Users (kerberosUsers)
Description

Defines the Kerberos user, that contains the username, the Windows Domain and the Airlock Gateway (WAF) mapping name. Multiple Kerberos user definitions can be sent to the Airlock Gateway if a mapping is specified for each user definition.

For each entry, the Kerberos username can be determined based on context data and it can be transformed using various transformation plugins.
The mapping and the domain can be specified in the configuration. The mapping is mandatory if multiple user definitions are configured.

Attributes
Plugin-List
Mandatory
Assignable plugins
Control Cookie Name (controlCookieName)
Description
The name of the Airlock control cookie. The name must match the control cookie name defined in the Airlock server.
Attributes
String
Optional
Default value
AL_CONTROL
Suggested values
AL_CONTROL
YAML Template (with default values)

type: KerberosIdentityPropagator
id: KerberosIdentityPropagator-xxxxxx
displayName: 
comment: 
properties:
  controlCookieName: AL_CONTROL
  kerberosUsers: