OATH OTP Settings
It can be used to verify counter based HOTP (event-triggered, incrementing counter) or to verify time based TOTP (draft standard).
On the client side we tested it with 'Google Authenticator' which was available for Android, iPhone and Blackberry at the time this plugin has been developed.
References:
HOTP RFC 4226 http://www.ietf.org/rfc/rfc4226.txt
TOTP RFC 6238 http://www.ietf.org/rfc/rfc6238.txt
password) credentialPersister) tokenType) More formal:
hotp := truncate(secureHash(sharedSecret, counter))
totp := truncate(secureHash(sharedSecret, time_slot))
We implement HOTP as defined in RFC 4226 and for TOTP we follow the draft standard http://www.ietf.org/id/draft-mraihi-totp-timebased-06.txt).
The default is TOTP.labelPattern) Recommended format: ${issuer}: ${accountName} (e.g. resolving to, My Company: alice@example.com).
${} The following variables are supported:
${issuer}: Resolved from 'Issuer Context Data Property' falling back to the value defined by the 'Default Issuer' property in case the referenced context data is missing.${accountName}: Resolved from 'Account Name Context Data Property' falling back to the user's 'username' (from themedusa_usertable) in case the referenced context data is missing.- Any context data property name (e.g.,
${email}). Compared to the${issuer}and${accountName}variables, these do not have a fallback. So in order for something to be displayed, make sure the referenced context data contains a value. Additionally, make sure the context data property is provided by the configured credential persister.
Assumptions for the following examples:
- Default Issuer Property:
My Company - Account Name Context Data Property:
email - Username (fallback for missing accountName):
f39286da-23a0-473d-986b-319741df785d(UUIDv4)
- Pattern:
${issuer}: ${accountName}(default)- With existing e-mail ->
My Company: alice@example.com - With missing e-mail ->
My Company: f39286da-23a0-473d-986b-319741df785d
- With existing e-mail ->
Note: Colons (':') are reserved characters in OATH URI labels for separating the issuer from the account name. To avoid issues with authenticator apps, Airlock IAM will automatically remove any colons from the issuer and accountName them during label generation.
In the above example, assume the email would be alice:1@example.com, then the generated label would be My Company: alice1@example.com.
issuerContextDataProperty) ${issuer} variable in the 'Label Pattern'. Resolves the variable from the user's attributes (e.g., company).
Fallback: If this property is not defined or the referenced context data value is blank, 'Default Issuer' is used.
Note: Make sure the context data property is provided by the configured credential persister.
defaultIssuer) ${issuer} variable in the 'Label Pattern'. Used if 'Issuer Context Data Property' is missing or resolves to a blank value. includeIssuerInParameters) This is recommended for better compatibility with modern OTP generator apps.
accountNameContextDataProperty) ${accountName} variable in the 'Label Pattern'. Resolves the variable from the user's attributes (e.g., email).
Fallback: If this property is not defined or the referenced context data value is blank, the user's 'username' (from the medusa_user table) is used.
Note: Make sure the context data property is provided by the configured credential persister.
digits) selectableAsAuthMethod) selectableAsNextAuthMethod) synchronizeIncreaseCounterButton) Using this button, the administrator can reset the time offset (for time-based OATH OTP) or increase the counter-value (event-based OATH OTP) in order to manually re-synchronize the token with the server.
showLetterAttributes) showSecretAsQrCode) The QR code allows admins to transfer the token key more easily to a compatible mobile app. This also eases "cloning" the OTP generator!
showSecretInHex) The HEX representation allows admins to transfer the token key to a mobile app. This also allows "cloning" the OTP generator!
showSecretInBase32)
type: OathOtpSettings
id: OathOtpSettings-xxxxxx
displayName:
comment:
properties:
accountNameContextDataProperty:
credentialPersister:
defaultIssuer: Airlock
digits: 6
includeIssuerInParameters: true
issuerContextDataProperty:
labelPattern: ${issuer}: ${accountName}
password:
selectableAsAuthMethod: true
selectableAsNextAuthMethod: true
showLetterAttributes: true
showSecretAsQrCode: true
showSecretInBase32: true
showSecretInHex: false
synchronizeIncreaseCounterButton: true
tokenType: