← Back to plugin index

Security Settings

Description
Loginapp security settings.
Type name
SecuritySettings
Class
com.airlock.iam.login.app.application.configuration.SecurityConfig
May be used by
Properties
Encryption Key (Base64 Encoded) (encryptionKey)
Description

The encryption key (encoded in base64) is required to encrypt sensitive data in cookies or in REST responses.

The openssl tool can be used to generate a random base64 string with 256 bits (32 bytes): openssl rand -base64 32

Attributes
String
Mandatory
Sensitive
HMAC Key (Base64 Encoded) (hmacKey)
Description

The HMAC Key (encoded in base64) is required to sign sensitive data stored in cookies or REST responses.

The openssl tool can be used to generate a random base64 string with 512 bits (64 bytes): openssl rand -base64 64

Security Recommendation: Use an HMAC key length of 512 bit or greater for optimal security with the used HS512 algorithm.

Attributes
String
Mandatory
Sensitive
CORS Settings (corsSettings)
Description
The settings to allow cross-domain REST calls.
Attributes
Plugin-Link
Optional
Assignable plugins
CSRF Protection (csrfProtection)
Description

If enabled, REST endpoints are protected against CSRF attacks.

With this protection, the REST API only accepts requests that contain the custom header X-Same-Domain with an arbitrary non-empty value. In cross-origin resource sharing (CORS), such requests are not considered simple requests and thus must always be preceded by a preflight request, which prevents cross-site request forgery (CSRF) attacks.

Security warning: Disabling this feature may allow CSRF attacks. Only do so if the REST client is unable to comply with the aforementioned restrictions.

To be RFC-compliant, the endpoint /<loginapp-uri>/rest/public/tech-client-registration/oauth2/<as-identifier>/register never requires the X-Same-Domain header.

Requests to this endpoint are guaranteed to be non-simple, because of the enforced non-simple content type application/json

Attributes
Boolean
Optional
Default value
true
Minimal Error Response Duration [ms] (fixedResponseDuration)
Description

Defines how long it takes (in milliseconds) until IAM answers an unsuccessful request in the public part of the API. Faster answers are delayed until the configured duration is reached. This helps to prevent user enumeration timing attacks. The configured response delay does not affect successful or slower responses. Protection against timing attacks is only provided if IAM is able to process 'unsuccessful' requests within the configured duration.

The endpoints for the password policy check, application access check, and the user self-registration are excluded from response delaying.

Attributes
Integer
Optional
Default value
2000
Username Filter Pattern (usernameFilterPattern)
Description
Regular expression pattern used to validate usernames entered by the user. If the username does not match the pattern, the corresponding process is aborted and a message is logged.
Attributes
RegEx
Optional
Default value
[a-zA-Z0-9@._+-]{1,100}
Session Cookie SameSite Policy (sameSitePolicy)
Description

Specifies the 'SameSite' cookie attribute of the IAM session cookie 'iam-session-id'. The 'Secure' attribute is automatically set based on whether the request was performed using http or https (see exception for 'None' below).

  • Strict: The cookie is not sent in cross-origin requests.
  • Lax: The cookie is sent in some cross-origin requests, such as GET requests.
  • None: The cookie is sent in cross-origin requests. In this case, the 'Secure' Cookie-Attribute is always set, regardless of whether the request was performed using http or https.Use this setting when using SAML2 in combination with cross-domain POST Bindings.
  • No SameSite Attribute: No attribute is set. Browsers apply their default behaviour, usually 'Lax'.
Attributes
Enum
Optional
Default value
LAX
YAML Template (with default values)

type: SecuritySettings
id: SecuritySettings-xxxxxx
displayName: 
comment: 
properties:
  corsSettings:
  csrfProtection: true
  encryptionKey:
  fixedResponseDuration: 2000
  hmacKey:
  sameSitePolicy: LAX
  usernameFilterPattern: [a-zA-Z0-9@._+-]{1,100}