By default, the vault uses local authentication. You can change the authentication method as required, and you can have multiple authentication modes active at the same time. However, OIDC without Active Directory cannot be used with Active Directory, and OIDC with Active Directory cannot be used without Active Directory.

You cannot disable OIDC authentication once it is configured. After you enable OIDC, you can no longer sign in with AD credentials. However, you can sign in using local authentication credentials without any issues.

To configure OIDC

  1. Log in to the Vault web GUI.
  2. In the top menu bar, click Settings.
  3. In the General Settings section, click Authentication.
  4. In the Choose Authentication Type drop-down menu, select:

    • OpenID Connect to configure OIDC without Active Directory

    • OpenID Connect (with AD) to configure OIDC with Active Directory
  5. Click the Learn more about configuring the OIDC Provider link to view the OIDC provider's login redirect URL and logout redirect URL.

  6. Specify the OpenID Connect Configuration settings: 

  7. Optionally, click Load File to upload the CA certificate in base64-encoded PEM format.

  8. Click Apply.

  9. Select Verify and Enable. After verification, a message appears confirming OpenID Connect has been successfully enabled. Vault is set for OIDC authentication.

  10. Sign out from the vault and sign in to the vault as an OIDC user by selecting Sign in with IDAAS and entering your OIDC credentials.

Name

A user-defined name for the OpenID Connect provider. 

Cryptographic Security Platform Vault displays this name on the button in the login dialogs.

Client ID

The organizational identity assigned by the OpenID Connect provider when you sign up for the service.

Client Secret    

A cryptographic component used to secure the organization's access to the OpenID Connect provider.

This field is write-only. It will never be displayed again after it has been initially created. It can be reentered if necessary.

Base URL

The URL that Cryptographic Security Platform Vault will use to contact the OpenID Connect provider to present the login page.