Skip to main content

KOBIL Condition - ACR Selection

Overview

This execution contains the following main steps:

  1. This execution requires the expected Step-up ACR value, the current ACR value from the session, and the respective execution ACR value set in the configuration.
  2. This Conditional execution will allow the next step to proceed only if both the expected step-up ACR value and the respective execution ACR value are greater than the user's current ACR value.

Type

ProtocolOpenID Connect 1.0
HTTP methodGET
TypeBrowser Flow
EndpointAuthorization Endpoint
Flow SupportedAuthorization code flow
Implicit flow
Hybrid flow
ResponseID Token, Access Token, Refresh Token
Response Modequery, form_post, fragment

How to configure

To configure the authenticator, follow these steps

  1. Select the Settings button
  2. Click Config.

Choose the actions you want to proceed with and enter the necessary configuration data. By following these steps, you will be able to successfully configure the authenticator.

KOBIL Condition - ACR Selection

Configuration

Parameters involved in KOBIL Condition - ACR Selection execution
ParameterDescription
AliasName for the overall configured configurations which occurs in particular authenticator. (Example: ACR 1)
Authenticator ReferenceA custom name for the authenticator that populates the AMR claim in tokens after successful authentication.
Authenticator Reference Max AgeSpecifies the maximum age (in seconds) of the last successful authentication for this authenticator, after which the system requires re-authentication.
Respective ACR valueACR value of the device should be greater or equal to the configured value in
Respective ACR value configuration.

KOBIL Condition - ACR Selection

User Flow

This execution contains the following main steps:

  1. KOBIL Condition - ACR selection must fall under the conditional flow and be followed by password, email, and phone authenticators (For instance: KOBIL Username Password), as it retrieves the expected step-up ACR value and current ACR value from the session via the KOBIL Configure ACR authenticator.
  2. This execution will be used only for the Step-Up flow.
  3. Refer ACR value.
kobilcondition-acrselection