Use Case: Regular end-users as simple realm administrators
This use case applies to an organization where employees with regular end-user accounts are enabled to access the Adminapp as simple realm administrators.
The solution presented here has the following characteristics:
- The solution allows a regular end-user to obtain an SSO ticket that contains both roles and the simple realm value for the Adminapp.
- The Adminapp authenticates the administrator with the SSO ticket and limit access using the roles and the simple realm value from the SSO ticket.
- For an end-user to be authorized to obtain the SSO ticket, the user must have at least the useradmin role and may have the tokenadmin role.
Configuration of the target application
Prerequisites
- The attribute to store the simple realm value for both end-users and administrators is called
realm.
Instruction
- Go to:
Loginapp >> Applications and Authentication - Create a new Target Application and add it to the Applications list.
- Configure the properties of the target application as follows:
- Configure or choose an authentication flow, and create an application ID (used in UI settings below).
- Configure an Application Selector such that the URL of the Adminapp matches the selector. This ensures that the target application is selected when trying to access the Adminapp.
- Add a Generic ID Propagator plugin to the Identity Propagation list.
Configuration of Generic ID Propagator plugin:
- In the Ticket String Provider property field, create a Ticket String Provider plugin, with a JWT Ticket Encoder plugin as ticket encoder, in order to create a JWT.
Configuration of JWT Ticket Encoder plugin:
- Set
usernameas Username Ticket Key. - Set an appropriate issuer in the Issuer field, e.g.,
Airlock IAM. - Set the Valid Not Before Skew property to
5. - Specify the following two values in the Claims Stored As Array field:
rolesandrealm. The roles are taken from the end-user's roles (using@rolesas value reference) and the realm from the context data attribute bearing the simple realm. - Create and configure a JWT ticket signer in the Signer field. Use an HMAC algorithm.
- Set
- Return to the Generic ID Propagator plugin dialog. Add a Forward Location Parameter Adder plugin to the Ticket Adder property field. It will send the JWT ticket to the Loginapp UI so it can be sent to the Adminapp.
- Next, go to:
Loginapp >> UI Settings >> Authentication UIs - In the Flow UIs list, add an Authentication & Authorization UI plugin.
Configuration of Authentication & Authorization UI plugin
- Make sure that the plugin refers to the previously created target application. You do this by specifying the target application's ID in the Target Application ID property
- Scroll to the On Flow Completion section. In the Target URI Resolver field, add a Target URI Resolver plugin. In this plugin's dialog, specify the default Adminapp URL in the Default Value property field, e.g.,
https://myhost.com/auth-admin/.
- Your new target application is now configured.
Configuration of the Adminapp
Prerequisite
- none
Instruction
- Go to:
Adminapp >> Administrators - In the Basic Settings section, SSO Ticket Authentication field, create an Admin SSO Ticket Request Authentication plugin.
Configuration of Admin SSO Ticket Request Authentication plugin
- Configure the Query Parameter Name property such that it matches the parameter name of the Ticket Adder configured in the Loginapp (see above). The default value is
sso. - Configure a Ticket Decoder such that it can decode JWT tickets issued by the Loginapp.
- Configure the Username Key and Roles Key properties such that they match the keys when issuing the JWT in the Loginapp.
- Specify the Roles Blocklist if required (e.g., to disallow the
superadminrole).
- Configure the Query Parameter Name property such that it matches the parameter name of the Ticket Adder configured in the Loginapp (see above). The default value is
- To the Ticket Processors list, add a Context Data Import Ticket Processor to import the
realmattribute.