← Back to plugin index

Flow Condition To Authentication Context Mapping

Description
Uses a specific Authentication Context if the Flow Condition can be satisfied.
Type name
Saml2FlowConditionToAuthnContextMapping
Class
com.airlock.iam.saml2.application.configuration.Saml2FlowConditionToAuthnContextMapping
May be used by
License-Tags
SamlIdp
Properties
Flow Condition (flowCondition)
Description
If this condition is fulfilled, the configured Authentication Context will be used in the Assertion (AuthnContextClassRef element).
Attributes
Plugin-Link
Mandatory
Assignable plugins
Authentication Context (authnContextUri)
Description

The Authentication Context URI to be used if the configured flow condition is satisfied.

The available context classes are configured in the IDP extended metadata under the attribute "idpAuthncontextClassrefMapping". Only URIs in that list are valid to be set here.

Attributes
String
Mandatory
Suggested values
urn:oasis:names:tc:SAML:2.0:ac:classes:InternetProtocol, urn:oasis:names:tc:SAML:2.0:ac:classes:InternetProtocolPassword, urn:oasis:names:tc:SAML:2.0:ac:classes:Kerberos, urn:oasis:names:tc:SAML:2.0:ac:classes:MobileOneFactorUnregistered, urn:oasis:names:tc:SAML:2.0:ac:classes:MobileTwoFactorUnregistered, urn:oasis:names:tc:SAML:2.0:ac:classes:MobileOneFactorContract, urn:oasis:names:tc:SAML:2.0:ac:classes:MobileTwoFactorContract, urn:oasis:names:tc:SAML:2.0:ac:classes:Password, urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport, urn:oasis:names:tc:SAML:2.0:ac:classes:PreviousSession, urn:oasis:names:tc:SAML:2.0:ac:classes:X509, urn:oasis:names:tc:SAML:2.0:ac:classes:PGP, urn:oasis:names:tc:SAML:2.0:ac:classes:SPKI, urn:oasis:names:tc:SAML:2.0:ac:classes:XMLDSig, urn:oasis:names:tc:SAML:2.0:ac:classes:Smartcard, urn:oasis:names:tc:SAML:2.0:ac:classes:SmartcardPKI, urn:oasis:names:tc:SAML:2.0:ac:classes:SoftwarePKI, urn:oasis:names:tc:SAML:2.0:ac:classes:Telephony, urn:oasis:names:tc:SAML:2.0:ac:classes:NomadTelephony, urn:oasis:names:tc:SAML:2.0:ac:classes:PersonalTelephony, urn:oasis:names:tc:SAML:2.0:ac:classes:AuthenticatedTelephony, urn:oasis:names:tc:SAML:2.0:ac:classes:SecureRemotePassword, urn:oasis:names:tc:SAML:2.0:ac:classes:TLSClient, urn:oasis:names:tc:SAML:2.0:ac:classes:TimeSyncToken, urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified
YAML Template (with default values)

type: Saml2FlowConditionToAuthnContextMapping
id: Saml2FlowConditionToAuthnContextMapping-xxxxxx
displayName: 
comment: 
properties:
  authnContextUri:
  flowCondition: