Cognos Analytics

Cognos Analytics

Connect, learn, and share with thousands of IBM Cognos Analytics users! 

 View Only
Expand all | Collapse all

Namespace: OpenID Connect, Type:Generic cannot get to work

  • 1.  Namespace: OpenID Connect, Type:Generic cannot get to work

    Posted Mon October 21, 2019 11:45 AM
    Edited by System Admin Fri January 20, 2023 04:32 PM
    Using cognos analytics 11.0.9. Trying to get Namespace: OpenID Connect, Type:Generic to work. My company has a custom IDP. At this point considering using a consultant. Anyone recommendations?

    Ok , and while I am at it. Read that Release 10 added the following. Of course migrating to a new namespae (we are migrating from AD to Openid Connect Generic) is a huge hassle in making sure that nobody loses ownership of their Cognos Objects (schedules, reports, jobs, My folders, etc). So this new feature is of great interest to me. But besides the little blurb below, i can find nothing on it. Anyone have any information on how to move users over to a new namespace?

    Another addition to R10 is the simplification of migration to a new OpenID Connect authentication method, and the ability to remap ID’s from old providers to OpenID.  R10 eliminates the need for an administrator to go through a time-consuming Namespace migration and verify each user when they want to change their OIDC connect provider type.

    ------------------------------
    brenda grossnickle
    ------------------------------
    #CognosAnalyticswithWatson


  • 2.  RE: Namespace: OpenID Connect, Type:Generic cannot get to work

    Posted Mon October 28, 2019 08:55 AM
    We have successfully configured 11.0.7 to 11.0.13 to authenticate with openid, but not custom idp.  

    It does create a new namespace, so there's no relationship between the old user info and new user info.  
    The function in R10 that you're referring to is a passthrough that lets you authenticate openid then pass that auth through to another auth based on custom claims passed as REMOTEUSER.  So far we have NOT been able to get that to work yet.

    ------------------------------
    Jeff Demaris
    ------------------------------