← Back to plugin index

OATH OTP Time-based Challenge Handler

Description
Handle TOTP Challenges (Timeslots).
Type name
TotpChallengeHandler
Class
com.airlock.iam.core.misc.impl.tokenverifier.oathotp.TotpChallengeHandler
May be used by
License-Tags
MobileOTP,OathOtp
Properties
Windows Size (windowsSize)
Description

The window size defines how many time slots before and after the current time slot that are allowed for the OTP verification. The length of a time slot is 30s. The window is symmetric. For a window size of 1, the time slots before and after the current time slot are allowed, in addition to the current time slot. Extending the time-window is required if the client's clock is not in perfect sync with the server clock (e.g. for hardware tokens).

This value must be as small as possible for security reasons. On the other hand, if the value is too small, usability may be impacted.

Attributes
Integer
Optional
Default value
1
Auto Time Shift (autoTimeShift)
Description
This property enables automatic clock sync. This can be handy in case of slowly diverging clocks. If enabled, when the user provided a correct OTP, the concerning time-slot is considered as the user's current time-slot. (this may be different from the servers current time-slot, because the window-size is usually > 0. )
Attributes
Boolean
Optional
Default value
true
YAML Template (with default values)

type: TotpChallengeHandler
id: TotpChallengeHandler-xxxxxx
displayName: 
comment: 
properties:
  autoTimeShift: true
  windowsSize: 1