← Back to plugin index

Airlock 2FA Settings

Description
Global settings related to Airlock 2FA.
Type name
Airlock2FASettings
Class
com.airlock.iam.factor.application.configuration.airlock2fa.Airlock2FASettings
May be used by
License-Tags
Airlock2FA
Properties
Repository (repository)
Description
Configures the repository to store Airlock 2FA data.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Futurae Server (futuraeServer)
Description
Configures access to Futurae servers.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Account Display Name Provider (accountDisplayNameProvider)
Description
An optional display name that is displayed in the Airlock 2FA/Futurae mobile application. As an example, it could be the IAM username or a configured context data item such as the user's email address. Note that currently the display name will not be updated if the underlying user data changed after the user being enrolled.

Privacy warning: The display name, when configured, will be stored on Futurae's servers. Sensitive data should therefore not be used as display name.

Attributes
Plugin-Link
Optional
Assignable plugins
Trusted Session Binding for Activation (trustedSessionBindingForActivation)
Description

If enabled, activation codes (from a letter or on-screen QR code) can only be used as part of an authenticated session with Airlock IAM. If enabled, activation codes are only accepted together with a "Trusted Session Binding Token". This short-lived token can only be retrieved from an Airlock IAM flow and must be sent to the Futurae server together with the activation code.

This feature ensures that only the intended user can activate a 2FA app/device with a given activation code. The standard Airlock 2FA app does not support this feature, a custom mobile app built using the Futurae SDK is required.

Airlock IAM supports three modes for Trusted Session Binding:

  • Never: Trusted Session Binding is disabled.
  • Only with Letter: Trusted Session Binding is only enabled for activation letters.
  • Always: Trusted Session Binding is enabled both for activation letters and on-screen activation. For on-screen activation, Trusted Session Binding does not provide additional security because the activation code is already bound to an authenticated IAM session, but it could simplify the implementation of the activation process in the mobile app.
Attributes
Enum
Optional
Default value
OFF
Trusted Session Binding for Recovery (trustedSessionBindingForRecovery)
Description
If enabled, "Trusted Session Binding for Recovery" will be enabled on newly activated Airlock 2FA devices. This means that these devices can only be recovered from a backup as part of an authenticated session with Airlock IAM. Already activated devices are not retrospectively affected by this setting.
Attributes
Boolean
Optional
Default value
false
Binding Token Validity [s] (trustedSessionBindingValidity)
Description
The amount of time a Trusted Session Binding Token for device activation and recovery is valid in seconds. This setting only has an effect if at least one of the two following conditions is met:
  • Trusted Session Binding for Activation is set to "Only with Letter" or "Always".
  • Trusted Session Binding for Recovery is enabled.

The duration should not be larger than the "Session Idle Timeout" in the Loginapp, to avoid session timeouts when polling the IAM status.

Attributes
Integer
Optional
Default value
120
Lock User on Fraud (lockUserOnFraud)
Description
If enabled, the user is locked with reason LockReason.FraudReportedByUser when reporting a possible fraudulent authentication attempt via the Airlock 2FA app. This is done by rejecting the authentication attempt and then confirming that the attempt was not initiated by the user (in the app dialog).

Self-unlock is possible when locked by this option.

Attributes
Boolean
Optional
Default value
false
Allow Futurae Bypass Mode (allowFuturaeBypassMode)
Description

If enabled, Futurae users that have the bypass mode enabled will be allowed to authenticate / perform approval with IAM. Otherwise, any authentication or approval attempts for users with the bypass mode enabled will result in a failure.

Warning: Enabling bypass mode effectively disables all Airlock 2FA second factor checks. Bypass mode should not be used in production environments.

Attributes
Boolean
Optional
Default value
false
Payload Encryption Key (payloadEncryptionKey)
Description
The symmetric key to encrypt the authentication/transaction payloads. If left empty, the payloads are not encrypted.

The encryption of payloads in requests to the Futurae API prevents that intermediate infrastructure such as a reverse proxy is able to read or alter the confidential data therein. The encryption key can be obtained from the Futurae Admin Dashboard.

Attributes
String
Optional
Sensitive
Unencrypted Payload for Hardware Tokens (unencryptedPayloadForHWTokens)
Description
When a 'Payload Encryption Key' is configured, 'Unencrypted Payload for Hardware Tokens' should be enabled. This setting only applies when a hardware token is used for authentication or approval via Offline QR Code.
  • If the option is enabled, the payload is transmitted in plain text (unencrypted).
  • If the option is disabled, hardware tokens will not be available for authentication or approval via Offline QR Code, since Futurae does not support payload encryption for hardware tokens.
For security reasons, this exception must be explicitly configured.

Note: Enabling this property without configuring a 'Payload Encryption Key' has no effect, as the payload is transmitted unencrypted by default.

Attributes
Boolean
Optional
Default value
false
Cooldown Period (cooldownPeriod)
Description

If configured, a cooldown period is enabled during which a newly registered device cannot be used for certain operations.

By default, all Airlock 2FA steps are configured so that devices may not be used during the "Cooldown Period". Exceptions can be configured directly on the step by de-activating the "Respect Cooldown Period" property.

The duration must be specified in the format "2d 4h 10m 5s" (any part can be omitted).

Attributes
String
Optional
Example
10m
Example
12h
Example
2d
YAML Template (with default values)

type: Airlock2FASettings
id: Airlock2FASettings-xxxxxx
displayName: 
comment: 
properties:
  accountDisplayNameProvider:
  allowFuturaeBypassMode: false
  cooldownPeriod:
  futuraeServer:
  lockUserOnFraud: false
  payloadEncryptionKey:
  repository:
  trustedSessionBindingForActivation: OFF
  trustedSessionBindingForRecovery: false
  trustedSessionBindingValidity: 120
  unencryptedPayloadForHWTokens: false