Kerberos User Definition
Description
Defines the user to be propagated to the back-end server with the Airlock Gateway (WAF) Back-side Kerberos SSO. Windows domain and mapping are optional if only one Kerberos User Spec is configured. If multuple Kerberos User Specs are configured, the mapping must be specified.
May be used by
Properties
Username Attribute (
usernameAttribute) Description
Defines the username to be propagated as Kerberos user.
By default the username from the login form is used ("@username"). Keep in mind that username transformation configured in the target application may have taken place.
Use the prefix "STATIC:" to indicate that what follows is the statically configured username to be used for all users.
Any other value from the context data container may be referred to using its key (for example: "userPrincipalName" or "sAMAccountname"). Make sure that the referenced context data attribute is read by the used user store or user persister plugin.Attributes
String
Optional
Default value
@username
Windows Domain (
windowsDomain) Description
Specifies the Windows Domain the user belongs to. If no Windows Domain is defined, the Airlock Gateway (WAF) tries to use this user for all configured Windows Domains.
The domain name must not contain the backslash ("\") character.
The domain name must not contain the backslash ("\") character.
Attributes
String
Optional
Example
airlock.intra
Mapping Name (
mappingName) Description
If specified, the Kerberos user is only used for the corresponding mapping. The mapping must be specified if multiple Kerberos User Specs are configured.
Valid characters are letters, digits and the special characters '.', ':', '-' and '_'.
Valid characters are letters, digits and the special characters '.', ':', '-' and '_'.
Attributes
String
Optional
Example
cms
Example
owa
Username Transformation (
usernameTransformation) Description
List of transformation plugins which allow various mutations of the username before it is used as Kerberos user. The transformations are applied in order. Note that some username transformer stop the transformation chain after successful application.
Note: The target application configuration allows to perform user transformation, too.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)
type: KerberosUserSpec
id: KerberosUserSpec-xxxxxx
displayName:
comment:
properties:
mappingName:
usernameAttribute: @username
usernameTransformation:
windowsDomain: