← Back to plugin index

NTLM Identity Propagator

Description
An identity propagator that instructs the Airlock Gateway (WAF) to send an HTTP NTLM auth header to the back-end.

This propagator only works together with Airlock Gateway. It uses the control API to propagate username and password.

Attention: due to a known limitation (AP-27159), only passwords only containing characters in the iso-8859-1 character set can be used. Incompatible passwords will result in an error.

Type name
NtlmIdentityPropagator
Class
com.airlock.iam.core.misc.impl.sso.NtlmIdentityPropagator
May be used by
Properties
Control Cookie Name (controlCookieName)
Description
The name of the Airlock control cookie. The name must match the control cookie name defined in the Airlock server.
Attributes
String
Optional
Default value
AL_CONTROL
Suggested values
AL_CONTROL
Username Property (usernameProperty)
Description

The name of the context key holding the username to be used for idenitity propagation.

Use the special value "@username" to use the username the user entered during authentication.

Use the prefix "STATIC:" to indicate that what follows is the statically configured username to be used for all users. Example: "STATIC:techaccount" means that the username "techaccount" is used for all users.

Attributes
String
Optional
Default value
@username
Example
@username
Example
db_col_sso_username
Example
STATIC:techaccount
Password Property (passwordProperty)
Description

The name of the context key holding the password to be used for identity propagation.

Use the special value "@password" to use the password the user entered during authentication. Note that depending on the authentication scheme, there is no such password (e.g. when using client certificates).

Use the special value "@roles" to use the user's roles as the password. The roles are represented as comma-separated list (e.g. "admin,empoloyee,user").
Notice: If there are users with no roles and basic-auth headers with no passwords are accepted by the backend, the property "Allow Empty Passwords" must be enabled.

Use the prefix "STATIC:" to indicate that what follows is the statically configured password to be used for all users. Example: "STATIC:abcd1234" means that the password "abcd1234" is used for all users.

Attributes
String
Optional
Default value
@password
Example
@password
Example
db_col_sso_pwd
Example
STATIC:abcd1234
Example
@roles
Allow Empty Passwords (allowEmptyPasswords)
Description
If enabled, empty passwords are accepted and propagated. Only enable this option if your backend is able to handle NTLM authentication with empty passwords.
Attributes
Boolean
Optional
Default value
false
Target Mapping Name (targetMappingName)
Description
The NTLM auth header can be restricted to just one back-end by specifying its name here. If left unset, the NTLM auth header is sent to every back-end having the 'on-behalf' login configured.
Attributes
String
Optional
YAML Template (with default values)

type: NtlmIdentityPropagator
id: NtlmIdentityPropagator-xxxxxx
displayName: 
comment: 
properties:
  allowEmptyPasswords: false
  controlCookieName: AL_CONTROL
  passwordProperty: @password
  targetMappingName:
  usernameProperty: @username