By default, the KeyControl Vault Management application is configured for local authentication. You can change the authentication method as required, but you can use only one type of authentication per vault at a time.

  • If you want to use OIDC without AD, you can only change to that mode from the local authentication mode.
  • If you have configured AD or OIDC with AD, you cannot change to OIDC without AD. You must first delete all AD users and groups, then remove the AD and/or OIDC configuration before configuring OIDC without AD.

Each vault can be configured with a separate OIDC server or a separate application from same server.

OIDC without AD is the recommended mode of OIDC authentication method where the OIDC provider independently manages identity and authentication. For new OIDC setups, this is the preferred option.

To configure OIDC 

  1. Log into the Cryptographic Security Platform Vault Management webGUI using an account with Security Admin privileges.
  2. In the top right, click the Switch to Appliance Management link.
  3. In the top menu bar, click Settings.
  4. In the General Settings section, click Authentication.
  5. In the Choose Authentication Type drop-down list, select OpenID Connect.
  6. Specify the OpenID Connect Configuration settings: 

  7. Optional. Click Browse to upload the CA Certificate. 

    The certificate needs to be in base64 encoded pem format.

  8. Click Apply. The OpenID Connect Configuration window appears showing the current configuration.
  9. Click Verify and Enable. After verification, a message appears confirming that OpenID Connect has been successfully enabled. The vault is now configured for OIDC authentication.

Name

A user-defined name for the OpenID Connect provider. Cryptographic Security Platform Vault displays this name on the button on the login dialogs.

Client ID

The organizational identity assigned by the OpenID Connect provider when you sign up for the service.

Client Secret

A cryptographic component used to secure the organization's access to the OpenID Connect provider.

This field is write-only. It will never be displayed again after it has been initially created. It can be reentered if necessary.

Base URL

The URL that Cryptographic Security Platform Vault will use to contact the OpenID Connect provider to present the login page.