The following example shows how to configure Azure OIDC to use with Cryptographic Security Platform Vault for External Authentication using Open ID Connect. You will need to register Entrust Cryptographic Security Platform as a Microsoft Azure application, then copy the following information from Azure and paste it into Cryptographic Security Platform Vault:
the Client Secret
the Application (client) ID
the base URL
Procedure
In Microsoft Azure, click App Registrations in the sidebar.
Click New Registration.
In the Register an application page, enter the name to use for the application and enter the following redirect URIs:
Set the Login Redirect URIs for all nodes in the cluster to:
https://<IP or FQDN of Cryptographic Security Platform Vault node>/v5/oidc/callbackSet the Logout Redirect URIs for all nodes in the cluster to:
https://<IP or FQDN of Cryptographic Security Platform Vault node>/v5/kc/oidc/logout
Click Register.
After the application is created, you will be taken to the new application page.
Copy the Application (client) ID to a text window for later use.
Important: This will be the application (client) ID that you will paste into Cryptographic Security Platform Vault.
Click Certificates & secrets in the sidebar to create a client secret.
In the Client secrets section, click New client secret.
In the Add a client secret window, enter a description, set the expiration date, and click Add.
The new client secret appears in the Client secrets section.
Copy the client secret value to a text window for later use.
Important: This will be the client secret that you will paste into Cryptographic Security Platform Vault.
Click Token configuration in the sidebar and then click Add optional claim.
In the Add optional claim window, select 'ID' for the token type and 'upn' and 'sid' for the claim.
Click Add.
In the pop-up window, check the 'Turn on the Microsoft Graph profile permission (required for claims to appear in token) checkbox.
Click Overview in the sidebar, and then click Endpoints.
In the Endpoints window, copy the OpenID Connect metadata document (up to and including the v2.0) to a text window to find the OpenID Connect URI or Issuer URI. This is the only URL in the Endpoints window that ends with /.well-known/openid-configuration.
For example, if the OpenID Connect metadata document field has the URL https://login.microsoftonline.com/<GUID>/2.0/.well-known/openid-configuration, you will need to ignore everything after the /2.0 and copy this section to a text window for later use: https://login.microsoftonline.com/<GUID>/2.0.
Important: This will be the base URL that you will paste into Cryptographic Security Platform Vault.
Close the Endpoints window to return to the Overview page.