Thanks,
By following the shared link and IBM Federation CookBook: Created OIDC OP Successfully using LMI.
Working on Configure Reverse Proxy for IdP . In LMI 9.0.0 there is no option for this. We need to run scripts "Using ISAM REST APIs".
Federation auto-configuration endpoint$ curl -k -v -u admin:Passw0rd -H 'Accept: application/json' -H 'Content-Type:
application/json'
https://isam.myidp.ibm.com/wga/reverseproxy/default/fed_config -d '{
"runtime":{"hostname":"localhost","port":"443","username":"easuser","password":"Passw0rd"
},"federation_id":"uuidd36144cb-0152-1a77-9a02-febccb94da75"}'
There facing challenge with user account "easuser" i.e. password is not with me as it was setup by my colleague and he does not remember it. I am planning to create an another account or reset easuser password and use that to complete Configure Reverse Proxy for IdP .
Before that , i am worried about resetting easuser password. Will it impact other configurations!!! Like: in reverse proxy this user easuser configured/being used. Can anyone confirm please two points
1) No issues , we can go ahead and reset easuser password or no?
2) Create another account and use that to complete my task "Configure Reverse Proxy for IdP" ?
Here another thing is , as I am running the above mentioned command from my workstation from where all required network ports are open to all ISAM URLs. But, do i need to have certificates also in my workstations to execute this command ? as connecting to ISAM Federation Runtime over 443 (SSL)
Thanks,
Usman
------------------------------
UsmanAli Shaik
------------------------------
Original Message:
Sent: Mon February 24, 2020 10:54 PM
From: Geethanjali D
Subject: Request for guideline to use OpenID Connect Mechanism where ISAM is IDP
Hey Usman,
You can find the link to configuring legacy OIDC,
https://www.ibm.com/support/knowledgecenter/SSPREK_9.0.7/com.ibm.isam.doc/config/concept/con_oidc_support.html
Details on creating OP and RP can be found in the link too. The KC document mentions 'OpenID Connect federations that were created with Security Access Manager Version 9.0.3 and older are legacy federations. The legacy federations do not have the enhanced features that Security Access Manager added in Version 9.0.4 for OIDC Providers and OIDC Relying Party federations'. It would be best for you to upgrade the appliance to 9.0.4 or newer and use the ISAM's newer OpenID Connection.
------------------------------
Geethanjali D
------------------------------
Original Message:
Sent: Thu February 20, 2020 06:44 AM
From: UsmanAli Shaik
Subject: Request for guideline to use OpenID Connect Mechanism where ISAM is IDP
Thanks for adding Gargaro,
Its very important otherwise we may communicate wrong information with customers.
Thanks a lot for the important information.
The information in blog you shared is showing supported but this one is saying "ISAM OIDC functionality is available from version 9.0.4 onwards".
https://community.ibm.com/community/user/security/blogs/madhura-damare1/2019/10/25/configure-isam-906-as-external-oidc-with-igi
Its decision making point for an application integration (which supports OpenID Connect) > Application is FSM (Field Service Management from IFS World vendor)
Current ISAM is 9.0.0.1. I can see the OpenID Connect protocol under Federation module only not in AAC.
From where we can select as OP or RP (Replying Party)
Thanks,
Usman
------------------------------
UsmanAli Shaik
Original Message:
Sent: Thu February 20, 2020 05:29 AM
From: Gianluca Gargaro
Subject: Request for guideline to use OpenID Connect Mechanism where ISAM is IDP
OIDC in ISAM is available since 9.0.0 see this https://www.ibm.com/blogs/security-identity-access/the-history-of-support-for-openid-connect-in-isam/
and if I'm not wrong I did that OIDC sso time ago with an ISAM earlier than 9.0.4.0. You may have some problem to follow that blog since ISAM OIDC configuration is different but the concepts are more or less the same
------------------------------
Gianluca Gargaro
IBM
Roma
Original Message:
Sent: Thu February 20, 2020 05:01 AM
From: UsmanAli Shaik
Subject: Request for guideline to use OpenID Connect Mechanism where ISAM is IDP
Thanks for the link shared.
Initial lines itself says "ISAM OIDC functionality is available from version 9.0.4 onwards". But, I am working on 9.0.0
I am working on 9.0.0 , in Secure Federation --> Federation. There are two protocols
SAML and OpenID Connect.
Does it mean that isam 9.0.0 can not be an OpenID Connect Operator (OP) (Identity Provider) , provide authentication to any target application support OIDC?
Thanks,
Usman
------------------------------
UsmanAli Shaik
Original Message:
Sent: Thu February 20, 2020 02:29 AM
From: Jens Petersen
Subject: Request for guideline to use OpenID Connect Mechanism where ISAM is IDP
Hallo Usman,
the following link deskribierst Hof to Integrated IGI and ISAM with OIDC. IGI Wolldecke be your app. Schuld give you the requested Info.
https://community.ibm.com/community/user/security/blogs/madhura-damare1/2019/10/25/configure-isam-906-as-external-oidc-with-igi
------------------------------
Jens Petersen