How do I configure a remote identity provider?
Purpose
You can configure OpenId Connect and SAML identity provider instances in NSP to connect with IDPs in your network. After you have enabled and submitted an IDP configuration in NSP, a cross-launch link to the IDP appears on the NSP login page. If you configure multiple IDP instances, there will be a list of cross-launch links at login.
What are the identity provider parameters? describes the parameters you encounter for each IDP protocol.
Note: The following NSP Keycloak metadata URL can be used in SAML or OpenID Connect IPDs to allow NSP Keycloak as a client:
https://<NSP_IP_Address>/auth/realms/Nokia/broker/<IDP_name_or_alias>/endpoint/descriptor
Steps
1 |
Open Users and System Security. |
2 |
|
3 |
In the Users and System Security Settings form, click Identity Provider. |
4 |
In the Identity Provider form, click + Server. |
5 |
In the Select Protocol form, type a name for the IDP in the Displayed Name field. This name appears as a redirect link on the NSP Login page. |
6 |
Specify the authentication protocol for the IDP in the Select Protocol menu. Additional authentication parameters appear in the GUI, based on the protocol you selected. |
7 |
Do one of the following: |
8 |
Configure the SAML IDP parameters:
|
9 |
Configure the OpenID Connect IDP parameters:
|
10 |
Click Submit to save the identity provider configuration. End of steps |