See below for integrating the Cryptographic Security Platform with external OpenID or Entrust IDaaS identity providers.
To integrate an external identity provider
Open the following URL in a Web browser.
https://<machine>:8443/management-consoleWhere
<machine>is the IP address or domain name of the machine hosting Cryptographic Security Platform.This release changes the URL port to 8443. Update your bookmarks accordingly.
- Log in to the Management Console as a user belonging to a role with identity provider management permissions – for example, the initial
adminadministrator user. - Select Identity providers in the sidebar.
- Click OpenID Connect v10.
- Configure the following settings.
- Redirect URI
- Alias
- Display name
- Display order
- Use discovery endpoint
- Authorization URL
- Token URL
- Logout URL
- User Info URL
- Token Introspection URL
- Issuer
- Validate Signatures
- Use PKCE
- Client authentication
- Client ID
- Client Secret
- Client assertion signature algorithm
- Client assertion audience
- Add X.509 Headers to the JWT
