← Back to plugin index

OATH OTP Letter Task

Description
This task generates letters with QR codes which allow initializing/provisioning of OTP authenticators using the OATH standard (time-based and event-based), such as 'Google Authenticator'. It iterates over credential records and generates an OATH OTP activation letter for all users that meet the conditions (see below).

The task uses the configured "Credential Iterator" to find users, where the "credential ordered" flag (configured in the iterator) is set. If no iterator is configured here, the Credential Persister from the OATH OTP Settings is used. If the flag is set, the "delivery security gap" is checked to ensure a minimum time between two reports for the same user. If this check is ok, the configured report renderer is called and the flag is reset.

Type name
OathOtpReportTask
Class
com.airlock.iam.servicecontainer.app.application.configuration.task.OathOtpReportTask
May be used by
License-Tags
MobileOTP,OathOtp
Properties
OATH OTP Settings (oathOtpSettings)
Description
The OATH OTP settings.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Credential Iterator (credentialIterator)
Description
The credential iterator to iterate over a set or credential structures. For efficiency reasons it makes sense to limit the set of credential structures returned by this plugin as much as possible, e.g. by including the "order-credential" flag already in the additional where clause of the iterator plugin.
If this property is not specified, the credential persister from the OATH OTP settings is used to iterate over the credentials.
Attributes
Plugin-Link
Optional
Assignable plugins
Report Renderer (reportRenderer)
Description
Renderer plugin used to generate the reports (PDFs, etc) for the OATH OTP token.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Delivery Security Gap (deliverySecurityGap)
Description
Specifies the minimum number of days that must elapse between reports generated for the same user. This delivery gap tries to prevent that two letters containing secrets are handled at the same time (e.g. by the postal service).
This feature only works correctly, if the other credential delivery timestamps are configured in the credential iterator (or, if no iterator is configured, in the credential persister from the OATH OTP settings).
Attributes
Integer
Optional
Default value
0
Language Attribute Name (languageAttributeName)
Description
The name of the context-data field that contains the language to be used for rendering the letter. This context-data field must be configured in the credential iterator (or, if no iterator is configured, in the credential persister from the OATH OTP settings), otherwise the language cannot be loaded and all reports are rendered in the default language.
Attributes
String
Mandatory
Suggested values
language
Working Directory (workingDirectory)
Description
A writable directory used to store partial reports.
If this property is defined, the letters are first written to this directory and then moved to the output directory configured below. This prevents downstream processes from reading partially rendered letters. To ensure atomic moves, the two directories must be in the same file system.
The directory is either absolute or relative to the JVMs current directory.
Attributes
File/Path
Optional
Output Directory (outputDirectory)
Description
This specifies the directory to where the rendered letters are written. The directory is either absolute or relative to the JVMs current directory.

This property is not required if the renderer plugin (see separate property) does not write on the output stream. If this property is not defined and the configured renderer plugin writes to the output stream, then the result (e.g. a PDF file) is lost.

Attributes
File/Path
Optional
File Name Prefix (fileNamePrefix)
Description
Filename prefix for rendered report files. It is important to set this to a unique value for the kind of reports generated by this task. Otherwise, this task will delete other reports with the same prefix during cleanup of old reports.
In particular, do not use the prefix "pwd-" (the default for password letters) or the empty prefix (the default for token lists) if such reports are stored in the same directory.
Attributes
String
Mandatory
Suggested values
oathotp-letter
File Name Suffix (fileNameSuffix)
Description
Filename suffix for rendered report files. The indicated suffix is appended to the generated reports. This may be required if the files are processed (e.g. printed) by another process (manual or automatic).
Attributes
String
Optional
Suggested values
.pdf, .txt
Delete Old Reports (deleteOldReports)
Description
Deletes old rendered reports of a user from the file system when a new one is rendered. Enabling this setting results in at most one rendered report of this type per user.
Caution: This feature will delete all reports starting with the prefix configured by property "file-name-prefix" and the user's name. Thus make sure, that different report types use different filename prefixes.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: OathOtpReportTask
id: OathOtpReportTask-xxxxxx
displayName: 
comment: 
properties:
  credentialIterator:
  deleteOldReports: false
  deliverySecurityGap: 0
  fileNamePrefix:
  fileNameSuffix:
  languageAttributeName:
  oathOtpSettings:
  outputDirectory:
  reportRenderer:
  workingDirectory: