Class UnboundIDYubiKeyOTPBindRequest
- java.lang.Object
-
- com.unboundid.ldap.sdk.LDAPRequest
-
- com.unboundid.ldap.sdk.BindRequest
-
- com.unboundid.ldap.sdk.SASLBindRequest
-
- com.unboundid.ldap.sdk.unboundidds.UnboundIDYubiKeyOTPBindRequest
-
- All Implemented Interfaces:
ReadOnlyLDAPRequest
,java.io.Serializable
@NotMutable @ThreadSafety(level=COMPLETELY_THREADSAFE) public final class UnboundIDYubiKeyOTPBindRequest extends SASLBindRequest
This class provides an implementation of a SASL bind request that may be used to authenticate to a Directory Server using the UNBOUNDID-YUBIKEY-OTP mechanism. The credentials include at least an authentication ID and a one-time password generated by a YubiKey device. The request may also include a static password (which may or may not be required by the server) and an optional authorization ID.
NOTE: This class, and other classes within the
com.unboundid.ldap.sdk.unboundidds
package structure, are only supported for use against Ping Identity, UnboundID, and Nokia/Alcatel-Lucent 8661 server products. These classes provide support for proprietary functionality or for external specifications that are not considered stable or mature enough to be guaranteed to work in an interoperable way with other types of LDAP servers.
The UNBOUNDID-YUBIKEY-OTP bind request MUST include SASL credentials with the following ASN.1 encoding:
UnboundIDYubiKeyCredentials ::= SEQUENCE { authenticationID [0] OCTET STRING, authorizationID [1] OCTET STRING OPTIONAL, staticPassword [2] OCTET STRING OPTIONAL, yubiKeyOTP [3] OCTET STRING, ... }
-
-
Field Summary
Fields Modifier and Type Field Description static java.lang.String
UNBOUNDID_YUBIKEY_OTP_MECHANISM_NAME
The name for the UnboundID YubiKey SASL mechanism.-
Fields inherited from class com.unboundid.ldap.sdk.SASLBindRequest
CRED_TYPE_SASL
-
Fields inherited from class com.unboundid.ldap.sdk.BindRequest
VERSION_ELEMENT
-
-
Constructor Summary
Constructors Constructor Description UnboundIDYubiKeyOTPBindRequest(java.lang.String authenticationID, java.lang.String authorizationID, byte[] staticPassword, java.lang.String yubiKeyOTP, Control... controls)
Creates a new UNBOUNDID-YUBIKEY-OTP bind request with the provided information.UnboundIDYubiKeyOTPBindRequest(java.lang.String authenticationID, java.lang.String authorizationID, java.lang.String staticPassword, java.lang.String yubiKeyOTP, Control... controls)
Creates a new UNBOUNDID-YUBIKEY-OTP bind request with the provided information.
-
Method Summary
All Methods Static Methods Instance Methods Concrete Methods Modifier and Type Method Description static UnboundIDYubiKeyOTPBindRequest
decodeCredentials(ASN1OctetString saslCredentials, Control... controls)
Creates a new UNBOUNDID-YUBIKEY-OTP SASL bind request decoded from the provided SASL credentials.UnboundIDYubiKeyOTPBindRequest
duplicate()
Creates a new instance of this LDAP request that may be modified without impacting this request.UnboundIDYubiKeyOTPBindRequest
duplicate(Control[] controls)
Creates a new instance of this LDAP request that may be modified without impacting this request.ASN1OctetString
encodeCredentials()
Retrieves an ASN.1 octet string containing the encoded credentials for this bind request.static ASN1OctetString
encodeCredentials(java.lang.String authenticationID, java.lang.String authorizationID, ASN1OctetString staticPassword, java.lang.String yubiKeyOTP)
Encodes the provided information into an ASN.1 octet string suitable for use as the SASL credentials for an UNBOUNDID-YUBIKEY-OTP bind request.java.lang.String
getAuthenticationID()
Retrieves the authentication ID for the bind request.java.lang.String
getAuthorizationID()
Retrieves the authorization ID for the bind request, if any.int
getLastMessageID()
Retrieves the message ID for the last LDAP message sent using this request.java.lang.String
getSASLMechanismName()
Retrieves the name of the SASL mechanism used in this SASL bind request.byte[]
getStaticPasswordBytes()
Retrieves the bytes that comprise the static password for the bind request, if any.java.lang.String
getStaticPasswordString()
Retrieves the string representation of the static password for the bind request, if any.java.lang.String
getYubiKeyOTP()
Retrieves the YubiKey-generated one-time password to include in the bind request.protected BindResult
process(LDAPConnection connection, int depth)
Sends this bind request to the target server over the provided connection and returns the corresponding response.void
toString(java.lang.StringBuilder buffer)
Appends a string representation of this request to the provided buffer.-
Methods inherited from class com.unboundid.ldap.sdk.SASLBindRequest
getBindType, responseReceived, sendBindRequest, sendMessage, toCode
-
Methods inherited from class com.unboundid.ldap.sdk.BindRequest
getOperationType, getRebindRequest
-
Methods inherited from class com.unboundid.ldap.sdk.LDAPRequest
followReferrals, getControl, getControlList, getControls, getIntermediateResponseListener, getReferralConnector, getResponseTimeoutMillis, hasControl, hasControl, setFollowReferrals, setIntermediateResponseListener, setReferralConnector, setResponseTimeoutMillis, toString
-
-
-
-
Field Detail
-
UNBOUNDID_YUBIKEY_OTP_MECHANISM_NAME
public static final java.lang.String UNBOUNDID_YUBIKEY_OTP_MECHANISM_NAME
The name for the UnboundID YubiKey SASL mechanism.- See Also:
- Constant Field Values
-
-
Constructor Detail
-
UnboundIDYubiKeyOTPBindRequest
public UnboundIDYubiKeyOTPBindRequest(java.lang.String authenticationID, java.lang.String authorizationID, java.lang.String staticPassword, java.lang.String yubiKeyOTP, Control... controls)
Creates a new UNBOUNDID-YUBIKEY-OTP bind request with the provided information.- Parameters:
authenticationID
- The authentication ID for the bind request. It must not benull
, and must have the form "dn:" followed by the DN of the target user or "u:" followed by the the username of the target user.authorizationID
- The authorization ID for the bind request. It may benull
if the authorization identity should be the same as the authentication identity.staticPassword
- The static password for the user specified as the authentication identity. It may benull
if authentication should be performed using only the YubiKey OTP.yubiKeyOTP
- The one-time password generated by the YubiKey device. It must not benull
.controls
- The set of controls to include in the bind request. It may benull
or empty if there should not be any request controls.
-
UnboundIDYubiKeyOTPBindRequest
public UnboundIDYubiKeyOTPBindRequest(java.lang.String authenticationID, java.lang.String authorizationID, byte[] staticPassword, java.lang.String yubiKeyOTP, Control... controls)
Creates a new UNBOUNDID-YUBIKEY-OTP bind request with the provided information.- Parameters:
authenticationID
- The authentication ID for the bind request. It must not benull
, and must have the form "dn:" followed by the DN of the target user or "u:" followed by the the username of the target user.authorizationID
- The authorization ID for the bind request. It may benull
if the authorization identity should be the same as the authentication identity.staticPassword
- The static password for the user specified as the authentication identity. It may benull
if authentication should be performed using only the YubiKey OTP.yubiKeyOTP
- The one-time password generated by the YubiKey device. It must not benull
.controls
- The set of controls to include in the bind request. It may benull
or empty if there should not be any request controls.
-
-
Method Detail
-
decodeCredentials
public static UnboundIDYubiKeyOTPBindRequest decodeCredentials(ASN1OctetString saslCredentials, Control... controls) throws LDAPException
Creates a new UNBOUNDID-YUBIKEY-OTP SASL bind request decoded from the provided SASL credentials.- Parameters:
saslCredentials
- The SASL credentials to decode in order to create the UNBOUNDID-YUBIKEY-OTP SASL bind request. It must not benull
.controls
- The set of controls to include in the bind request. This may benull
or empty if no controls should be included in the request.- Returns:
- The UNBOUNDID-YUBIKEY-OTP SASL bind request decoded from the provided credentials.
- Throws:
LDAPException
- If the provided credentials cannot be decoded to a valid UNBOUNDID-YUBIKEY-OTP bind request.
-
getAuthenticationID
public java.lang.String getAuthenticationID()
Retrieves the authentication ID for the bind request.- Returns:
- The authentication ID for the bind request.
-
getAuthorizationID
public java.lang.String getAuthorizationID()
Retrieves the authorization ID for the bind request, if any.- Returns:
- The authorization ID for the bind request, or
null
if the authorization identity should match the authentication identity.
-
getStaticPasswordString
public java.lang.String getStaticPasswordString()
Retrieves the string representation of the static password for the bind request, if any.- Returns:
- The string representation of the static password for the bind
request, or
null
if there is no static password.
-
getStaticPasswordBytes
public byte[] getStaticPasswordBytes()
Retrieves the bytes that comprise the static password for the bind request, if any.- Returns:
- The bytes that comprise the static password for the bind request,
or
null
if there is no static password.
-
getYubiKeyOTP
public java.lang.String getYubiKeyOTP()
Retrieves the YubiKey-generated one-time password to include in the bind request.- Returns:
- The YubiKey-generated one-time password to include in the bind request.
-
process
protected BindResult process(LDAPConnection connection, int depth) throws LDAPException
Sends this bind request to the target server over the provided connection and returns the corresponding response.- Specified by:
process
in classBindRequest
- Parameters:
connection
- The connection to use to send this bind request to the server and read the associated response.depth
- The current referral depth for this request. It should always be one for the initial request, and should only be incremented when following referrals.- Returns:
- The bind response read from the server.
- Throws:
LDAPException
- If a problem occurs while sending the request or reading the response.
-
encodeCredentials
public ASN1OctetString encodeCredentials()
Retrieves an ASN.1 octet string containing the encoded credentials for this bind request.- Returns:
- An ASN.1 octet string containing the encoded credentials for this bind request.
-
encodeCredentials
public static ASN1OctetString encodeCredentials(java.lang.String authenticationID, java.lang.String authorizationID, ASN1OctetString staticPassword, java.lang.String yubiKeyOTP)
Encodes the provided information into an ASN.1 octet string suitable for use as the SASL credentials for an UNBOUNDID-YUBIKEY-OTP bind request.- Parameters:
authenticationID
- The authentication ID for the bind request. It must not benull
, and must have the form "dn:" followed by the DN of the target user or "u:" followed by the the username of the target user.authorizationID
- The authorization ID for the bind request. It may benull
if the authorization identity should be the same as the authentication identity.staticPassword
- The static password for the user specified as the authentication identity. It may benull
if authentication should be performed using only the YubiKey OTP.yubiKeyOTP
- The one-time password generated by the YubiKey device. It must not benull
.- Returns:
- An ASN.1 octet string suitable for use as the SASL credentials for an UNBOUNDID-YUBIKEY-OTP bind request.
-
duplicate
public UnboundIDYubiKeyOTPBindRequest duplicate()
Creates a new instance of this LDAP request that may be modified without impacting this request.- Specified by:
duplicate
in interfaceReadOnlyLDAPRequest
- Specified by:
duplicate
in classBindRequest
- Returns:
- A new instance of this LDAP request that may be modified without impacting this request.
-
duplicate
public UnboundIDYubiKeyOTPBindRequest duplicate(Control[] controls)
Creates a new instance of this LDAP request that may be modified without impacting this request. The provided controls will be used for the new request instead of duplicating the controls from this request.- Specified by:
duplicate
in interfaceReadOnlyLDAPRequest
- Specified by:
duplicate
in classBindRequest
- Parameters:
controls
- The set of controls to include in the duplicate request.- Returns:
- A new instance of this LDAP request that may be modified without impacting this request.
-
getSASLMechanismName
public java.lang.String getSASLMechanismName()
Retrieves the name of the SASL mechanism used in this SASL bind request.- Specified by:
getSASLMechanismName
in classSASLBindRequest
- Returns:
- The name of the SASL mechanism used in this SASL bind request.
-
getLastMessageID
public int getLastMessageID()
Retrieves the message ID for the last LDAP message sent using this request.- Overrides:
getLastMessageID
in classSASLBindRequest
- Returns:
- The message ID for the last LDAP message sent using this request, or -1 if it no LDAP messages have yet been sent using this request.
-
toString
public void toString(java.lang.StringBuilder buffer)
Appends a string representation of this request to the provided buffer.- Specified by:
toString
in interfaceReadOnlyLDAPRequest
- Specified by:
toString
in classLDAPRequest
- Parameters:
buffer
- The buffer to which to append a string representation of this request.
-
-