← Back to plugin index

Credential Secret Generator

Description
Responsible for the generation and the rendering of credential secrets.
Type name
CredentialSecretGenerator
Class
com.airlock.iam.core.misc.renderer.CredentialSecretGenerator
May be used by
Properties
Hash Value Is Binary (hashValueIsBinary)
Description
Enable to tell this plugin that the hash value produced by the configured hash function is binary (and not a string). It will the be stored using the credential persisters "binary" data slot.
Attributes
Boolean
Optional
Default value
false
Password Generator (passwordGenerator)
Description
The string generator plugin which will generate the new password.
Attributes
Plugin-Link
Optional
Assignable plugins
Hash Function Plugin (hashFunctionPlugin)
Description
This property is used when new passwords are generated. The hash function is used to hash the generated password. It must be the same (or hash value compatible) as used when checking passwords.

NOTE: Some password hashes, such as SHA 256 Password Hash or Scrypt Password Hash, produce binary output. If one of these is used, make sure the persistence layer supports binary data in the hash field and the corresponding persistence plugins (e.g. Database User Store or Ldap Connector) are configured to treat hash values as binary values.
In case the persistence layer expects a string, encode the password hash by wrapping it with an encoder. To achieve this, use the Password Hash Configuration plugin and specify the hash function (such as Scrypt Password Hash) together with the desired encoder. We recommend using the Base64 Password Hash Encoder.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Output Directory Path (outputDirectoryPath)
Description
Directory in the file system to put the rendered passwords in. The directory is either absolute or relative to the JVMs current directory.

This property is not required if the renderer plugin (see separate property) does not write on the outputstream (e.g. sends it somewhere else). It is required otherwise.

Note: If this property is not defined and the used renderer plugin writes on the output stream, then the result (e.g. a PDF file) is lost.

Attributes
File/Path
Optional
Working Directory Path (workingDirectoryPath)
Description
A writable directory used to store partial reports.
If this property is defined, the passwords are not directly generated into the output directory (see other property) but they are generated into this working directory and are moved to the output directory once they are done.
This helps to solve problems with processes automatically reading the rendered passwords and reading partial reports during the generation process. Make sure that the working directory and the output directory reside in the same file system (if not the moving of the generated file will not be atomic).
The directory is either absolute or relative to the JVMs current directory.
Attributes
File/Path
Optional
File Name Prefix (fileNamePrefix)
Description
Filename prefix for rendered report files. It is important to set this to a unique value for the kind of reports generated by this task. When this task deletes old reports, it looks at this prefix (and the user id) in order to find out what files to delete. Thus, if this prefix is the same as for other reports and the reside in the same directory, other reports may be deleted.

Do not use the empty prefixes if token-list reports are stored in the same directory. The empty prefix is the default for token list letters (and not configurable in older plugin versions).

This property is optional to be backwards compatible. The prefix "pwd-" is used if none is defined.

Attributes
String
Optional
Default value
pwd-
Example
pwd-
Example
passwordLetter-
Configured File Name Suffix (configuredFileNameSuffix)
Description
Filename suffix for rendered password files. The configured file name suffix will be extended with a leading dot, before using as suffix if necessary.
Attributes
String
Optional
Suggested values
.pdf, .docx
Report Type Short Desc (reportTypeShortDesc)
Description
Defines a short textual description of the type of the report being rendered.
The text is used in the user trail log written when a report is rendered. Please specify a text like in the examples below, so it suits the structure of the log statement it is used in.
If this property is not specified, a general statement will be logged.
Attributes
String
Optional
Example
password letter
Example
activation key letter
Example
PIN letter
Password Renderer (passwordRenderer)
Description
Tells the password batch task which password renderer to use for the rendering of newly generated passwords.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Language Attribute Name (languageAttributeName)
Description
Tells the password batch task which attribute in the context data container contains the language to be used for rendering the password. If this property is configured and if the context data container of the user has a value for this attribute, it is used when calling the password renderer plugin.
Attributes
String
Optional
Suggested values
language
Delete Old Passwords (deleteOldPasswords)
Description
Deletes old rendered passwords of a user from the file system when a new one is rendered. Setting this to TRUE results in at most one rendered password per user.
Attributes
Boolean
Optional
Default value
false
Barcode Generator (barcodeGenerator)
Description
Optional barcode generator. If this property is configured, a barcode image and the corresponding barcode content are added to the parameter map accessible by report templates. The following keys are defined:
  • BarcodeImage: placeholder for the barcode image.
  • BarcodeContent: placeholder for the barcode content.
  • BarcodeContentDisplay: placeholder for the barcode content in a human-readable format.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: CredentialSecretGenerator
id: CredentialSecretGenerator-xxxxxx
displayName: 
comment: 
properties:
  barcodeGenerator:
  configuredFileNameSuffix:
  deleteOldPasswords: false
  fileNamePrefix: pwd-
  hashFunctionPlugin:
  hashValueIsBinary: false
  languageAttributeName:
  outputDirectoryPath:
  passwordGenerator:
  passwordRenderer:
  reportTypeShortDesc:
  workingDirectoryPath: