A.2 Authentication Server Details

This tab defines the values for the LDAP authentication server, OSP authentication service, and bootstrap administrator. This tab provides the following groups of settings:

A.2.1 OAuth Server

This section represents the values for the LDAP authentication server.

Same as IG Server

Specifies whether the authentication server runs on the same computer as Identity Governance.

Protocol

Applies only when the authentication server and the Identity Governance server run on different computers.

Specifies whether you want to use http or https. To use Secure Sockets Layer (SSL) for communications, specify https.

Host Name

Applies only when the authentication server and the Identity Governance server run on different computers.

Specifies the DNS name or IP address of the LDAP authentication server. Do not use localhost.

Port

Applies only when the authentication server and the Identity Governance server run on different computers.

Specifies the port that you want the server to use for communication with client computers. The default is 8080. To use SSL, the default is 8443.

A.2.2 OAuth SSO Client

This section represents the values for OAuth authentication services to Identity Governance.

IG Client ID

Specifies the client ID of Identity Governance with which it is registered to the authentication service.

IG Client Secret

Specifies the client password of Identity Governance with the authentication service.

IG Redirect URL

Specifies the URL used by the authentication service to redirect to the Identity Governance login page if authentication token is valid.

IG Request Client ID

Specifies the client ID of Identity Governance Access Request with which it is registered to the authentication service.

IG Request Client Secret

Specifies the client password of Identity Governance Access Request with the authentication service.

IG Request Redirect URL

Specifies the URL used by the authentication service to redirect to the Identity Governance Access Request page if authentication token is valid.

A.2.3 Bootstrap Admin

This section represents the values for the bootstrap administrator.

Bootstrap Admin

Specifies the name of the bootstrap administrator account. The default value is igadmin.

(Conditional) When connecting to an existing Identity Manager authentication server, specify the full DN of a unique identity that already exists and can access Identity Manager Home as a bootstrap administrator. For example, cn=uaadmin,ou=sa,o=data.

NOTE:The name of this account must be unique. Do not duplicate any accounts in the adminusers.txt file or in the container source or subtrees that you use for authentication.

Authentication Source

Specifies whether the credentials for the bootstrap admin reside in an Identity Vault (LDAP authentication server) or a text file.

(Conditional) If you specify File, you must also specify values for Directory and Filename that correspond to the file that stores your bootstrap admin information.

  • Linux: Default location of /opt/netiq/idm/apps/idgov/osp/adminusers.txt

  • Windows: Default location of c:\netiq\idm\apps\idgov\osp/adminusers.txt