Default TAN Service
Description
Default implementation of the Tan Service extension point.
This plugin provides TAN service functionality for TAN list and matrix card authentication.
This plugin provides TAN service functionality for TAN list and matrix card authentication.
May be used by
Properties
Token List Persister (
tokenListPersister) Description
Name of the token list persister plugin used by this plugin to read and write token list information.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Token Alphabet (
tokenAlphabet) Description
Defines the alphabet (or set of characters) of which a token is composed.
Attributes
Enum
Mandatory
Token Length (
tokenLength) Description
Specifies the length of each token on the token list.
Attributes
Integer
Mandatory
Tokens Per List (
tokensPerList) Description
Specifies the total number of tokens per token list.
Attributes
Integer
Mandatory
Reuse Challenge Tokens (
reuseChallengeTokens) Description
When this plugin is used for challenge response authentication (with matrix cards or indexed token lists), this property specifies if tokens may be reused in future challenges. If set to
false a single token will never be re-challenged. As a result, the space of remaining tokens will decrease with each successful challenge response. Attributes
Boolean
Optional
Default value
true
Index Positions Per Challenge (
indexPositionsPerChallenge) Description
When this plugin is used for challenge response authentication (with matrix cards or indexed token lists), this property specifies the number of indices (or matrix coordinates) to return in a challenge.
Attributes
Integer
Mandatory
Hash Function (
hashFunction) Description
Specifies the hash function plugin used by this plugin in order to produce hash value of the tokens. Using an insecure hash function (such as the
IdentityPasswordHash plugin) results potential security vulnerability in that the token lists may easily be reconstructed from the stored hash values. Attributes
Plugin-Link
Mandatory
Assignable plugins
AWS KMS Password Hash Argon2id Password Hash Bcrypt Password Hash Combined Password Hash Encrypted Password Hash History Password Hash Identity Password Hash LDAP Password Hash MD5 Base64 Password Hash MD5 Hex Password Hash Multi Password Hash (LDAP-style) Password Hash Configuration SHA1 Base64 Password Hash SHA1 Hex Password Hash SHA1 Password Hash SHA256 Base64 Password Hash SHA256 Hex Password Hash SHA256 Password Hash Scrypt Password Hash
Low On Tokens Threshold (
lowOnTokensThreshold) Description
Specifies the number of unused (remaining) tokens which indicates that a new list should be generated. When the threshold is reached, a new list is ordered, but not yet generated. Generating a new list is handled by a task (normally the TanBatchTask). The value -1 turns this feature off (no threshold).
Attributes
Integer
Mandatory
Event Source Name (
eventSourceName) Description
String used as event source name for events generated by this service. The event source name is included in events such that events from different sources (for example different tan service instances) can be distinguished.
Attributes
String
Optional
Example
Instance A
Example
Prod
Example
Test
Event Notificator (
eventNotificator) Description
Defines the event notificator that should be informed if a user is low on tokens (see configuration property
Leaving this property unset results in no notification events to be generated.
low-on-tokens-threshold). The event notificator can then handle the event by (for example) sending an email to somebody or starting some asynchronous processing.
Leaving this property unset results in no notification events to be generated.
Attributes
Plugin-Link
Optional
Assignable plugins
Activate New List With First Usage (
activateNewListWithFirstUsage) Description
This property is only relevant for token lists (and not for challenge-response matrix cards or indexed lists). For matrix cards and indexed lists, this feature is always activated.
If this property is set to
If this property is set to
TRUE and there are both an active and a new list, the new list can be activated any time by using it. If the property is FALSE (default), the new list is only activated after the active list has expired or the all the tokens have been used. Attributes
Boolean
Optional
Default value
false
Max List Validity (
maxListValidity) Description
Specifies the number of days a token list is valid after its generation. After the period has elapsed, the list can no longer be used and is replaced by the new token list (if there is any). If there is no new list, the list is deleted.
If the value -1 is used, the token list does not expire.
If the value -1 is used, the token list does not expire.
Attributes
Long
Optional
Default value
-1
Ignore Token Case (
ignoreTokenCase) Description
If set to
true the case of characters is ignored when checking tokens. Attributes
Boolean
Optional
Default value
false
Max Token Length (
maxTokenLength) Description
The maximum length of a token entered by the user. If the property
ignoreTokenCase is set to true, all combinations of lowercase and uppercase characters are generated and checked against the stored hash value of the token. If a user enters a token that is very long, the generation of all combinations takes a significant amount of time. To prevent the system from being slowed down because of the generation, this property has to be configured if the property ignoreTokenCase is set to true. Attributes
Integer
Optional
Default value
10
YAML Template (with default values)
type: DefaultTanService
id: DefaultTanService-xxxxxx
displayName:
comment:
properties:
activateNewListWithFirstUsage: false
eventNotificator:
eventSourceName:
hashFunction:
ignoreTokenCase: false
indexPositionsPerChallenge:
lowOnTokensThreshold:
maxListValidity: -1
maxTokenLength: 10
reuseChallengeTokens: true
tokenAlphabet:
tokenLength:
tokenListPersister:
tokensPerList: