← Back to plugin index

Lock Expired Initial Passwords Task

Description
Server task that checks all users for too old initial passwords.

If a user account satisfies all of the following conditions, it is locked:

  • The account is not marked invalid
  • The account is not locked
  • A password change is enforced
  • The generation date of the password is not null and older than the initial-password-validity-period (as specified by the configuration of this plugin.

Note: This task determines whether a password is an initial password based only on the facts that the password change flag is set and that there is a password generation date/time. Thus, setting the password change flag to true and not changing an "old" generation date may result in the account being locked by this task.

Type name
LockExpiredInitialPasswordsTask
Class
com.airlock.iam.servicecontainer.app.application.configuration.task.LockExpiredInitialPasswordsTask
May be used by
Properties
User Persister (userPersister)
Description
User persister plugin used to read user account data and lock it if necessary.
Attributes
Plugin-Link
Mandatory
Assignable plugins
User Iterator (userIterator)
Description
The user iterator plugin used to iterate over all users.
Usually this is the same as the "User Persister".
Attributes
Plugin-Link
Mandatory
Assignable plugins
Password Validity Days (passwordValidityDays)
Description
Number of days an initial password is considered valid before it is locked.
Attributes
Long
Mandatory
Delete Password (deletePassword)
Description
If enabled, the password is deleted if the account is locked.
Attributes
Boolean
Optional
Default value
true
YAML Template (with default values)

type: LockExpiredInitialPasswordsTask
id: LockExpiredInitialPasswordsTask-xxxxxx
displayName: 
comment: 
properties:
  deletePassword: true
  passwordValidityDays:
  userIterator:
  userPersister: