NTLM Identity Propagator
This propagator only works together with Airlock Gateway. It uses the control API to propagate username and password.
Attention: due to a known limitation (AP-27159), only passwords only containing characters in the iso-8859-1 character set can be used. Incompatible passwords will result in an error.
controlCookieName) usernameProperty) The name of the context key holding the username to be used for idenitity propagation.
Use the special value "@username" to use the username the user entered during authentication.
Use the prefix "STATIC:" to indicate that what follows is the statically configured username to be used for all users. Example: "STATIC:techaccount" means that the username "techaccount" is used for all users.
passwordProperty) The name of the context key holding the password to be used for identity propagation.
Use the special value "@password" to use the password the user entered during authentication. Note that depending on the authentication scheme, there is no such password (e.g. when using client certificates).
Use the special value "@roles" to use the user's roles as the password. The roles are represented as comma-separated list (e.g. "admin,empoloyee,user").
Notice: If there are users with no roles and basic-auth headers with no passwords are accepted by the backend, the property "Allow Empty Passwords" must be enabled.
Use the prefix "STATIC:" to indicate that what follows is the statically configured password to be used for all users. Example: "STATIC:abcd1234" means that the password "abcd1234" is used for all users.
allowEmptyPasswords) targetMappingName)
type: NtlmIdentityPropagator
id: NtlmIdentityPropagator-xxxxxx
displayName:
comment:
properties:
allowEmptyPasswords: false
controlCookieName: AL_CONTROL
passwordProperty: @password
targetMappingName:
usernameProperty: @username