← Back to plugin index

STET PSD2 Authenticator

Description
Authenticator for STET PSD2 Access Tokens / Client Certificates. The resulting authenticated technical client (TPP) will contain the following elements:
  • The subject's organizationIdentifier (TPP) of the client certificate as the username.
  • The access token's scopes as roles (MUST be restricted accordingly in the authorization server configuration)
  • For authorization code grants, the user (PSU) that has granted the TPP access. Available in the context data as "PSU_ID"

Further constraints will be validated:

  • The used client certificate (QWAC) for the TLS connection will be validated according to the configuration.
  • The access token must belong to the same technical client as the client certificate.
Type name
StetPsd2CertificateAuthenticator
Class
com.airlock.iam.login.app.application.configuration.psd2.StetPsd2CertificateAuthenticatorConfig
May be used by
License-Tags
PSD2STET
Properties
OAuth 2.0 Authorization Server Reference (authorizationServerIdentifier)
Description
The reference to the authorization server (v3) that was used to generate the access token. The authorization server must be configured in the top-level settings in the Loginapp or else the authentication will fail.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Check Validity Period (checkValidityPeriod)
Description
If enabled, the validity period of the certificate is checked. If disabled, expired (or not-yet-valid) certificates are also accepted.
Attributes
Boolean
Optional
Default value
true
Certificate Status Checkers (certStatusCheckers)
Description
A list of certificate status checkers used to check the revocation status of the client certificate. If more than one checker is configured, all of them are consulted and the certificate is considered revoked if at least one of them tells so.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: StetPsd2CertificateAuthenticator
id: StetPsd2CertificateAuthenticator-xxxxxx
displayName: 
comment: 
properties:
  authorizationServerIdentifier:
  certStatusCheckers:
  checkValidityPeriod: true