← Back to plugin index

Airlock Gateway Settings (Loginapp)

Description
Gateway settings for the Loginapp. These settings are essential to ensure correct and secure behavior if Airlock IAM is deployed behind an Airlock Gateway.
Type name
LoginappGateway
Class
com.airlock.iam.login.application.configuration.gateway.LoginappGatewayConfig
May be used by
Properties
Removed Roles Mappings (removedRolesMappings)
Description

Airlock Gateway can indicate (using an environment cookie) that roles have been dropped. Dropped roles can be mapped to tags in Airlock IAM that should be dropped as a consequence.

Attributes
Plugin-List
Optional
Assignable plugins
Client Fingerprinting Lockout Threshold (clientFingerprintingLockoutThreshold)
Description

If the Airlock Gateway terminates a session because of a high client fingerprinting (CFP) score, IAM is informed about this as part of the Airlock Gateway logout propagation.
This property defines a CFP score threshold: If the CFP score reported by the Airlock Gateway is above or equal to the threshold, the user account is locked in IAM. This way not only the current Airlock Gateway session is terminated but also the user account is locked for further login attempts. The user can't unlock his account by using the "Unlock Self-Service".

Note: Ensure that the logout propagation path in the corresponding Airlock Gateway mapping for IAM points to the corresponding REST endpoint.

Please refer to the Airlock Gateway manual for further information about client fingerprinting.

Attributes
Integer
Optional
Add Credentials To Session (addCredentialsToSession)
Description
Usually, existing roles should be kept, i.e., the roles granted to a user in Airlock IAM should be added to the existing set of roles of an Airlock Gateway session. This is achieved by using the Airlock Control Cookie command ADD_CREDENTIALS. If every identity propagation shall replace all previously set roles, disable this property, which results in the Airlock Control Cookie command SET_CREDENTIALS.
Attributes
Boolean
Optional
Default value
true
Control Cookie Name (controlCookieName)
Description

The name of the control cookie used to communicate with the Airlock Gateway (WAF) backend control API. This must be the same as configured in Airlock.

A control cookie is set after successful authentication with the roles granted to the user as credentials/roles. Additionally, a new session ID is generated (to prevent session fixation attacks) and the global session ID is set as audit token.

This property also enables so-called "session tickets". After successful authentication the user's name and the granted roles are stored in the current session plus a session ticket cookie including this information is stored in the Airlock Gateway cookie store. The session ticket is needed to re-authenticate any new session later.

Attributes
String
Optional
Default value
AL_CONTROL
Environment Cookie Prefix (environmentCookiePrefix)
Description
The name of the prefix that Airlock Gateway (WAF) prepends to all environment cookies it sends to its backends. This must be the same as configured in Airlock Gateway. It is used to extract, for example, the client IP address or the client certificate.
Attributes
String
Optional
Default value
AL_ENV_
Audit Token (auditToken)
Description

Type of the audit token set in the Airlock Gateway (WAF) after the authentication.

  • "Username": The audit token contains just the username.
  • "SessionID": The audit token contains just the session id.
  • "Username and SessionID": The audit token contains the username followed by a "-" and the session ID.
  • "None": The audit token is empty.
Attributes
Enum
Optional
Default value
USERNAME
YAML Template (with default values)

type: LoginappGateway
id: LoginappGateway-xxxxxx
displayName: 
comment: 
properties:
  addCredentialsToSession: true
  auditToken: USERNAME
  clientFingerprintingLockoutThreshold:
  controlCookieName: AL_CONTROL
  environmentCookiePrefix: AL_ENV_
  removedRolesMappings: