Use Case: Regular end-users as simple realm administrators

This use case applies to an organization where employees with regular end-user accounts are enabled to access the Adminapp as simple realm administrators.

The solution presented here has the following characteristics:

  • The solution allows a regular end-user to obtain an SSO ticket that contains both roles and the simple realm value for the Adminapp.
  • The Adminapp authenticates the administrator with the SSO ticket and limit access using the roles and the simple realm value from the SSO ticket.
  • For an end-user to be authorized to obtain the SSO ticket, the user must have at least the useradmin role and may have the tokenadmin role.

Configuration of the target application

Prerequisites

  • The attribute to store the simple realm value for both end-users and administrators is called realm.

Instruction

  1. Go to:
    Loginapp >> Applications and Authentication
  2. Create a new Target Application and add it to the Applications list.
  3. Configure the properties of the target application as follows:
  4. Configure or choose an authentication flow, and create an application ID (used in UI settings below).
  5. Configure an Application Selector such that the URL of the Adminapp matches the selector. This ensures that the target application is selected when trying to access the Adminapp.
  6. Add a Generic ID Propagator plugin to the Identity Propagation list.
  7. Configuration of Generic ID Propagator plugin:

    1. In the Ticket String Provider property field, create a Ticket String Provider plugin, with a JWT Ticket Encoder plugin as ticket encoder, in order to create a JWT.
    2. Configuration of JWT Ticket Encoder plugin:

      • Set username as Username Ticket Key.
      • Set an appropriate issuer in the Issuer field, e.g., Airlock IAM.
      • Set the Valid Not Before Skew property to 5.
      • Specify the following two values in the Claims Stored As Array field: roles and realm. The roles are taken from the end-user's roles (using @roles as value reference) and the realm from the context data attribute bearing the simple realm.
      • Create and configure a JWT ticket signer in the Signer field. Use an HMAC algorithm.
    3. Return to the Generic ID Propagator plugin dialog. Add a Forward Location Parameter Adder plugin to the Ticket Adder property field. It will send the JWT ticket to the Loginapp UI so it can be sent to the Adminapp.
  8. Next, go to:
    Loginapp >> UI Settings >> Authentication UIs
  9. In the Flow UIs list, add an Authentication & Authorization UI plugin.
  10. Configuration of Authentication & Authorization UI plugin

    • Make sure that the plugin refers to the previously created target application. You do this by specifying the target application's ID in the Target Application ID property
    • Scroll to the On Flow Completion section. In the Target URI Resolver field, add a Target URI Resolver plugin. In this plugin's dialog, specify the default Adminapp URL in the Default Value property field, e.g., https://myhost.com/auth-admin/.
  11. Your new target application is now configured.

Configuration of the Adminapp

Prerequisite

  • none

Instruction

  1. Go to:
    Adminapp >> Administrators
  2. In the Basic Settings section, SSO Ticket Authentication field, create an Admin SSO Ticket Request Authentication plugin.
  3. Configuration of Admin SSO Ticket Request Authentication plugin

    • Configure the Query Parameter Name property such that it matches the parameter name of the Ticket Adder configured in the Loginapp (see above). The default value is sso.
    • Configure a Ticket Decoder such that it can decode JWT tickets issued by the Loginapp.
    • Configure the Username Key and Roles Key properties such that they match the keys when issuing the JWT in the Loginapp.
    • Specify the Roles Blocklist if required (e.g., to disallow the superadmin role).
  4. To the Ticket Processors list, add a Context Data Import Ticket Processor to import the realm attribute.