← Back to plugin index

Ace Radius Token Verifier

Description
Token verifier to test ACE/RSA tokens using the RADIUS protocol.
This plug-in supports multiple ACE/RSA servers and failover.

The ACE server must be installed/configured to support RADIUS. Here are some configuration hints (may be different for more recent ACE server versions):

  • RADIUS support must be activated.
  • Create an agent host of type "Unix Agent" with the name and the IP of the host running this client. This makes sure that the ACE server accepts RADIUS requests from the client host.
  • Activate the users you like to use on the just created agent host.

Since the RADIUS protocol does not know anything about the different challenge responses (next token required, new pin required, etc.), some RSA/ACE server versions encode them in the state attribute (like a session id). This implementation can check for these special state values and behave accordingly. This is the default setting. If the next token mode (and new pin mode) does not work properly, enable the property Interpret Challenge Messages. In this case, this plug-in intreprets the reply messages rather than the special state attributes.

Type name
AceRadiusTokenVerifier
Class
com.airlock.iam.core.misc.impl.tokenverifier.ace.AceRadiusTokenVerifier
May be used by
License-Tags
RadiusClient,SecurID,SecureID
Properties
Radius Servers (radiusServers)
Description
The RADIUS Server(s). If more than one is provided, the list is used for failover.

Non-backward compatibility: Before hierarchical plugins were released, the RadiusServer informations were all configured directly in this plugin with a comma separated list. This must be converted by hand.

Attributes
Plugin-List
Mandatory
Assignable plugins
Interpret Challenge Messages (interpretChallengeMessages)
Description
If set to TRUE, this plug-in will look at the reply messages in RADIUS responses. The messages are used to distinguish next-token-mode, new-pin-mode, and new-pin-accepted-mode.
If the property is set to FALSE (default), this plugin interprets the RADIUS state attribute to make this distinction. This is may not work with newer RSA/ACE servers.
Attributes
Boolean
Optional
Default value
false
Nas Identifier (nasIdentifier)
Description
The NAS-Identifier to set in all requests.
Attributes
String
Optional
Length >= 3
YAML Template (with default values)

type: AceRadiusTokenVerifier
id: AceRadiusTokenVerifier-xxxxxx
displayName: 
comment: 
properties:
  interpretChallengeMessages: false
  nasIdentifier:
  radiusServers: