Class UnboundIDYubiKeyOTPBindRequest

  • All Implemented Interfaces:
    ReadOnlyLDAPRequest, java.io.Serializable

    @NotMutable
    @ThreadSafety(level=COMPLETELY_THREADSAFE)
    public final class UnboundIDYubiKeyOTPBindRequest
    extends SASLBindRequest
    This class provides an implementation of a SASL bind request that may be used to authenticate to a Directory Server using the UNBOUNDID-YUBIKEY-OTP mechanism. The credentials include at least an authentication ID and a one-time password generated by a YubiKey device. The request may also include a static password (which may or may not be required by the server) and an optional authorization ID.
    NOTE: This class, and other classes within the com.unboundid.ldap.sdk.unboundidds package structure, are only supported for use against Ping Identity, UnboundID, and Nokia/Alcatel-Lucent 8661 server products. These classes provide support for proprietary functionality or for external specifications that are not considered stable or mature enough to be guaranteed to work in an interoperable way with other types of LDAP servers.

    The UNBOUNDID-YUBIKEY-OTP bind request MUST include SASL credentials with the following ASN.1 encoding:

       UnboundIDYubiKeyCredentials ::= SEQUENCE {
            authenticationID     [0] OCTET STRING,
            authorizationID      [1] OCTET STRING OPTIONAL,
            staticPassword       [2] OCTET STRING OPTIONAL,
            yubiKeyOTP           [3] OCTET STRING,
            ... }
     
    See Also:
    RegisterYubiKeyOTPDeviceExtendedRequest, DeregisterYubiKeyOTPDeviceExtendedRequest, Serialized Form
    • Constructor Detail

      • UnboundIDYubiKeyOTPBindRequest

        public UnboundIDYubiKeyOTPBindRequest​(@NotNull
                                              java.lang.String authenticationID,
                                              @Nullable
                                              java.lang.String authorizationID,
                                              @Nullable
                                              java.lang.String staticPassword,
                                              @NotNull
                                              java.lang.String yubiKeyOTP,
                                              @Nullable
                                              Control... controls)
        Creates a new UNBOUNDID-YUBIKEY-OTP bind request with the provided information.
        Parameters:
        authenticationID - The authentication ID for the bind request. It must not be null, and must have the form "dn:" followed by the DN of the target user or "u:" followed by the the username of the target user.
        authorizationID - The authorization ID for the bind request. It may be null if the authorization identity should be the same as the authentication identity.
        staticPassword - The static password for the user specified as the authentication identity. It may be null if authentication should be performed using only the YubiKey OTP.
        yubiKeyOTP - The one-time password generated by the YubiKey device. It must not be null.
        controls - The set of controls to include in the bind request. It may be null or empty if there should not be any request controls.
      • UnboundIDYubiKeyOTPBindRequest

        public UnboundIDYubiKeyOTPBindRequest​(@NotNull
                                              java.lang.String authenticationID,
                                              @Nullable
                                              java.lang.String authorizationID,
                                              @Nullable
                                              byte[] staticPassword,
                                              @NotNull
                                              java.lang.String yubiKeyOTP,
                                              @Nullable
                                              Control... controls)
        Creates a new UNBOUNDID-YUBIKEY-OTP bind request with the provided information.
        Parameters:
        authenticationID - The authentication ID for the bind request. It must not be null, and must have the form "dn:" followed by the DN of the target user or "u:" followed by the the username of the target user.
        authorizationID - The authorization ID for the bind request. It may be null if the authorization identity should be the same as the authentication identity.
        staticPassword - The static password for the user specified as the authentication identity. It may be null if authentication should be performed using only the YubiKey OTP.
        yubiKeyOTP - The one-time password generated by the YubiKey device. It must not be null.
        controls - The set of controls to include in the bind request. It may be null or empty if there should not be any request controls.
    • Method Detail

      • decodeCredentials

        @NotNull
        public static UnboundIDYubiKeyOTPBindRequest decodeCredentials​(@NotNull
                                                                       ASN1OctetString saslCredentials,
                                                                       @Nullable
                                                                       Control... controls)
                                                                throws LDAPException
        Creates a new UNBOUNDID-YUBIKEY-OTP SASL bind request decoded from the provided SASL credentials.
        Parameters:
        saslCredentials - The SASL credentials to decode in order to create the UNBOUNDID-YUBIKEY-OTP SASL bind request. It must not be null.
        controls - The set of controls to include in the bind request. This may be null or empty if no controls should be included in the request.
        Returns:
        The UNBOUNDID-YUBIKEY-OTP SASL bind request decoded from the provided credentials.
        Throws:
        LDAPException - If the provided credentials cannot be decoded to a valid UNBOUNDID-YUBIKEY-OTP bind request.
      • getAuthenticationID

        @NotNull
        public java.lang.String getAuthenticationID()
        Retrieves the authentication ID for the bind request.
        Returns:
        The authentication ID for the bind request.
      • getAuthorizationID

        @Nullable
        public java.lang.String getAuthorizationID()
        Retrieves the authorization ID for the bind request, if any.
        Returns:
        The authorization ID for the bind request, or null if the authorization identity should match the authentication identity.
      • getStaticPasswordString

        @Nullable
        public java.lang.String getStaticPasswordString()
        Retrieves the string representation of the static password for the bind request, if any.
        Returns:
        The string representation of the static password for the bind request, or null if there is no static password.
      • getStaticPasswordBytes

        @Nullable
        public byte[] getStaticPasswordBytes()
        Retrieves the bytes that comprise the static password for the bind request, if any.
        Returns:
        The bytes that comprise the static password for the bind request, or null if there is no static password.
      • getYubiKeyOTP

        @NotNull
        public java.lang.String getYubiKeyOTP()
        Retrieves the YubiKey-generated one-time password to include in the bind request.
        Returns:
        The YubiKey-generated one-time password to include in the bind request.
      • process

        @NotNull
        protected BindResult process​(@NotNull
                                     LDAPConnection connection,
                                     int depth)
                              throws LDAPException
        Sends this bind request to the target server over the provided connection and returns the corresponding response.
        Specified by:
        process in class BindRequest
        Parameters:
        connection - The connection to use to send this bind request to the server and read the associated response.
        depth - The current referral depth for this request. It should always be one for the initial request, and should only be incremented when following referrals.
        Returns:
        The bind response read from the server.
        Throws:
        LDAPException - If a problem occurs while sending the request or reading the response.
      • encodeCredentials

        @NotNull
        public ASN1OctetString encodeCredentials()
        Retrieves an ASN.1 octet string containing the encoded credentials for this bind request.
        Returns:
        An ASN.1 octet string containing the encoded credentials for this bind request.
      • encodeCredentials

        @NotNull
        public static ASN1OctetString encodeCredentials​(@NotNull
                                                        java.lang.String authenticationID,
                                                        @Nullable
                                                        java.lang.String authorizationID,
                                                        @Nullable
                                                        ASN1OctetString staticPassword,
                                                        @NotNull
                                                        java.lang.String yubiKeyOTP)
        Encodes the provided information into an ASN.1 octet string suitable for use as the SASL credentials for an UNBOUNDID-YUBIKEY-OTP bind request.
        Parameters:
        authenticationID - The authentication ID for the bind request. It must not be null, and must have the form "dn:" followed by the DN of the target user or "u:" followed by the the username of the target user.
        authorizationID - The authorization ID for the bind request. It may be null if the authorization identity should be the same as the authentication identity.
        staticPassword - The static password for the user specified as the authentication identity. It may be null if authentication should be performed using only the YubiKey OTP.
        yubiKeyOTP - The one-time password generated by the YubiKey device. It must not be null.
        Returns:
        An ASN.1 octet string suitable for use as the SASL credentials for an UNBOUNDID-YUBIKEY-OTP bind request.
      • duplicate

        @NotNull
        public UnboundIDYubiKeyOTPBindRequest duplicate​(@Nullable
                                                        Control[] controls)
        Creates a new instance of this LDAP request that may be modified without impacting this request. The provided controls will be used for the new request instead of duplicating the controls from this request.
        Specified by:
        duplicate in interface ReadOnlyLDAPRequest
        Specified by:
        duplicate in class BindRequest
        Parameters:
        controls - The set of controls to include in the duplicate request.
        Returns:
        A new instance of this LDAP request that may be modified without impacting this request.
      • getLastMessageID

        public int getLastMessageID()
        Retrieves the message ID for the last LDAP message sent using this request.
        Overrides:
        getLastMessageID in class SASLBindRequest
        Returns:
        The message ID for the last LDAP message sent using this request, or -1 if it no LDAP messages have yet been sent using this request.
      • toString

        public void toString​(@NotNull
                             java.lang.StringBuilder buffer)
        Appends a string representation of this request to the provided buffer.
        Specified by:
        toString in interface ReadOnlyLDAPRequest
        Specified by:
        toString in class LDAPRequest
        Parameters:
        buffer - The buffer to which to append a string representation of this request.
      • toCode

        public void toCode​(@NotNull
                           java.util.List<java.lang.String> lineList,
                           @NotNull
                           java.lang.String requestID,
                           int indentSpaces,
                           boolean includeProcessing)
        Appends a number of lines comprising the Java source code that can be used to recreate this request to the given list.
        Specified by:
        toCode in interface ReadOnlyLDAPRequest
        Overrides:
        toCode in class SASLBindRequest
        Parameters:
        lineList - The list to which the source code lines should be added.
        requestID - The name that should be used as an identifier for the request. If this is null or empty, then a generic ID will be used.
        indentSpaces - The number of spaces that should be used to indent the generated code. It must not be negative.
        includeProcessing - Indicates whether the generated code should include code required to actually process the request and handle the result (if true), or just to generate the request (if false).