Airlock 2FA Authenticator
Description
Authenticator for Airlock 2FA.
Customize the string resource airlock2fa.one-touch.authentication-title to define the text that is displayed after the word "Approve" for One-Touch authentications.
May be used by
Administrators Configuration Meta Authenticator Meta Authenticator Meta Authenticator Persister Password Service Authenticator-based One-Shot Target Application User to Authenticator Mapping Authentication Method Identifier Mapping Fallback Authenticator Selection Authenticator Main Authenticator Auth Method-based Authenticator Selector Credential-based Authenticator Selector Credential to Authenticator Mapping Radius Authentication Service Roles-to-Authenticator Mapping Role-based Authenticator Selector User-based Authenticator Selector
Properties
Airlock 2FA Settings (
airlock2faSettings) Description
Settings of Airlock 2FA.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Factors (
factors) Description
Priority list of all enabled factors. Only factors that are in this list can be used for authentication. The factors are offered in the configured order.
Online factors (One-Touch and Online QR Code) must come before all other factors. It is recommended to include at least one offline factor.
Available factors:
- One-Touch: a push message is sent to the user's mobile app, where it must be approved. This is an online factor and will require device selection if the user has multiple devices.
- Passcode: the device (mobile app or hardware token) generates a time-dependent code (OTP) that has to be entered manually. This is an offline factor. No prior device selection is required.
- Offline QR Code: a QR code is returned which has to be scanned by a mobile app or hardware token. The device displays a code (OTP) that must be entered manually. This is an offline factor and will require device selection if the user has multiple devices.
If this plugin is configured in a 'Radius Authentication Service', the only two valid configurations here are: 1) One-Touch followed by Passcode or 2) One-Touch.
Attributes
String-List
Optional
Default value
[One-Touch, Passcode, Offline QR Code]
User Persister (
userPersister) Description
The user persister to access IAM users.
Attributes
Plugin-Link
Mandatory
Assignable plugins
String Resources File (
stringResourcesFile) Description
Specifies the prefix of the file(s) containing the language dependent string resources. Example: If the value of this property is
strings, the language dependent files must be strings_de.properties, strings_en.properties and so on and the default file must be strings.properties. Attributes
String
Optional
Default value
strings
YAML Template (with default values)
type: Airlock2FAAuthenticator
id: Airlock2FAAuthenticator-xxxxxx
displayName:
comment:
properties:
airlock2faSettings:
factors: [One-Touch, Passcode, Offline QR Code]
stringResourcesFile: strings
userPersister: