← Back to plugin index

AES256 Decryption Ticket Decoder

Description
Decodes the ticket produced by the AES256 Encryption Ticket Encoder plugin.
Type name
AES256DecryptionTicketDecoder
Class
com.airlock.iam.core.misc.util.ticket.codec.AES256DecryptionTicketDecoder
May be used by
Properties
Password (password)
Description
Specifies the password used to decrypt the ticket.
Attributes
String
Mandatory
Sensitive
Length >= 4
Require Authenticated Encryption (requireAuthenticatedEncryption)
Description
If integrity is essential, it is strongly recommended to forbid tickets which are not authenticated encrypted by GCM. Only for backward compatibility reasons we do not enforce incoming tickets to be encrypted in GCM mode. If this flag is set to false, this encoder also accepts tickets that were encrypted without authentication, using the CBC mode. That may be a threat if the ticket is exposed to an attacker.

If possible this flag should be enabled.

The AES256EncryptionTicketEncoder uses the GCM Mode by default.
Attributes
Boolean
Optional
Default value
true
Max PBKDF2 Iterations (maxPBKDF2Iterations)
Description
Specifies the maximum number of PBKDF2 iterations allowed for decryption. Choose this maximum as small as possible. Allowing a large number of iterations may require a considerable amount of computing time when decoding the ticket.
Attributes
Integer
Optional
Default value
32000
YAML Template (with default values)

type: AES256DecryptionTicketDecoder
id: AES256DecryptionTicketDecoder-xxxxxx
displayName: 
comment: 
properties:
  maxPBKDF2Iterations: 32000
  password:
  requireAuthenticatedEncryption: true