Airlock Gateway Settings (Loginapp)
removedRolesMappings) Airlock Gateway can indicate (using an environment cookie) that roles have been dropped. Dropped roles can be mapped to tags in Airlock IAM that should be dropped as a consequence.
clientFingerprintingLockoutThreshold) If the Airlock Gateway terminates a session because of a high client fingerprinting (CFP) score, IAM is informed about this as part of the Airlock Gateway logout propagation.
This property defines a CFP score threshold: If the CFP score reported by the Airlock Gateway is above or equal to the threshold, the user account is locked in IAM. This way not only the current Airlock Gateway session is terminated but also the user account is locked for further login attempts. The user can't unlock his account by using the "Unlock Self-Service".
Note: Ensure that the logout propagation path in the corresponding Airlock Gateway mapping for IAM points to the corresponding REST endpoint.
Please refer to the Airlock Gateway manual for further information about client fingerprinting.
addCredentialsToSession) ADD_CREDENTIALS. If every identity propagation shall replace all previously set roles, disable this property, which results in the Airlock Control Cookie command SET_CREDENTIALS. controlCookieName) The name of the control cookie used to communicate with the Airlock Gateway (WAF) backend control API. This must be the same as configured in Airlock.
A control cookie is set after successful authentication with the roles granted to the user as credentials/roles. Additionally, a new session ID is generated (to prevent session fixation attacks) and the global session ID is set as audit token.
This property also enables so-called "session tickets". After successful authentication the user's name and the granted roles are stored in the current session plus a session ticket cookie including this information is stored in the Airlock Gateway cookie store. The session ticket is needed to re-authenticate any new session later.
environmentCookiePrefix) auditToken) Type of the audit token set in the Airlock Gateway (WAF) after the authentication.
- "Username": The audit token contains just the username.
- "SessionID": The audit token contains just the session id.
- "Username and SessionID": The audit token contains the username followed by a "-" and the session ID.
- "None": The audit token is empty.
type: LoginappGateway
id: LoginappGateway-xxxxxx
displayName:
comment:
properties:
addCredentialsToSession: true
auditToken: USERNAME
clientFingerprintingLockoutThreshold:
controlCookieName: AL_CONTROL
environmentCookiePrefix: AL_ENV_
removedRolesMappings: