webMethods

 View Only
Expand all | Collapse all

Any one did oAuth2 Authentication with Azure AD as External Authorization in API GW

  • 1.  Any one did oAuth2 Authentication with Azure AD as External Authorization in API GW

    Posted Tue February 06, 2024 10:43 AM

    Hi All
    We have tried wM as authorization server in API GW and it worked fine. We are trying to setup oAuth2 Authentication using external server authorization and for that Azure AD is the oAuth provider.

    At Azure side we have setup the APP registration and scope and all those and when we generated the token we see the token is getting generated.

    When we are invoking the API with the token generated we are getting token expired or invalid where as the token is a valid one.

    Steps followed

    1. In API GW -->Administration–>Security–>JWT/OAuth/OpenID and
      Add Authorization Server
      Name,Discovery URL and in scopes gave the relative details

    Can you please let me know any specific settings need to be done still.


    #oauth2
    #webMethods-API-GW
    #Azure-Authorization-Server
    #API-Gateway
    #API-Management
    #webMethods


  • 2.  RE: Any one did oAuth2 Authentication with Azure AD as External Authorization in API GW

    Posted Mon February 12, 2024 05:56 AM


  • 3.  RE: Any one did oAuth2 Authentication with Azure AD as External Authorization in API GW

    Posted Mon February 12, 2024 06:34 AM

    hi @parre.abhijith,
    I see the only reason for error is that we have not done the scope mapping.
    As you said you have done the scope mapping oi dont se need to do anything with respect to the dynamic client registration. We need to pass the discovery url and rest should get populated.
    As i dont have azure provider , I will use local Auth server will try to replicate it.

    Regards
    Vikash Sharma


    #webMethods-API-GW
    #oauth2
    #API-Management
    #Azure-Authorization-Server
    #API-Gateway
    #webMethods


  • 4.  RE: Any one did oAuth2 Authentication with Azure AD as External Authorization in API GW

    Posted Mon February 12, 2024 08:51 AM

    Sure thank you… Will wait for your inputs after your implementation.


    #API-Management
    #webMethods
    #oauth2
    #webMethods-API-GW
    #Azure-Authorization-Server
    #API-Gateway


  • 5.  RE: Any one did oAuth2 Authentication with Azure AD as External Authorization in API GW

    Posted Thu February 15, 2024 04:40 AM

    hi @parre.abhijith ,
    I created the POC with local auth server and i can see i am getting the invalid token error in the case when i remove the mapping from the scope.
    In you case you are using Azure, so only point i can think of is some access related issue at azure end when the token is generated.
    This token is has limited access maybe be because of which it is giving the token is invalid.

    Regards
    Vikash Sharma


    #API-Gateway
    #oauth2
    #Azure-Authorization-Server
    #webMethods
    #webMethods-API-GW
    #API-Management


  • 6.  RE: Any one did oAuth2 Authentication with Azure AD as External Authorization in API GW

    Posted Thu February 15, 2024 07:32 AM

    Hi Vikash

    Thanks for the response i have raised a ticket with SAG and it is now solved.

    Azure generates JWT tokens even if we select oAuth details. So we had to do the below steps

    In the local introspection gave the url of issuer generated from token(meaning Azure is giving one introspection url but when the token is requested the iss is different in my case atleast

    iss: https://sts.windows.net/xxxxxxxxxxxxx/

    when i click on discover in 3rd party authorization

    Azure is giving out https://login.microsoftonline.com/xxxxxxxxxxx/v2.0

    Once the token is generated from Azure and when the token is passed to API… SAG asked us to keep the policy as JWT only then it will work.

    oAuth token from Azure is JWT

    image

    Policy for API should be JWT as per SAG

    Also in Application created a strategy and gave the Audience as the aud from JWT

    Now the output is successful

    If i change the policy back to oAuth in API

    Then the same error

    So the final recommendation from SAG is oAuth tokens from Azure are JWT tokens and in API we need to select the policy as JWT


    #webMethods-API-GW
    #API-Management
    #webMethods
    #API-Gateway
    #Azure-Authorization-Server
    #oauth2


  • 7.  RE: Any one did oAuth2 Authentication with Azure AD as External Authorization in API GW

    Posted Mon February 12, 2024 06:34 AM

    Ensure the following,

    1. Please check the issuer present in the JWT is same as the one configured in the authorization server issuer in the Local introspection section
    2. Validate the scope mapping
    3. Ensure the clientid and audience are matching with the JWT and the strategy of the application created.

    #webMethods-API-GW
    #webMethods
    #API-Gateway
    #Azure-Authorization-Server
    #oauth2
    #API-Management


  • 8.  RE: Any one did oAuth2 Authentication with Azure AD as External Authorization in API GW

    Posted Mon February 12, 2024 06:42 AM
    1. Please check the issuer present in the JWT is same as the one configured in the authorization server issuer in the Local introspection section
      Abhijith : Yes they are the same.

    2. Validate the scope mapping
      Abhijith : Yes scope is also correct.

    3.Ensure the clientid and audience are matching with the JWT and the strategy of the application created.
    Abhijith : They are matching.


    #webMethods
    #Azure-Authorization-Server
    #API-Gateway
    #webMethods-API-GW
    #oauth2
    #API-Management