A custom authentication action plugin for the Curity Identity Server.
The plugin is only tested with Curity Identity Server 6.2.0 but should work with older version also. More details in the Systems Requirement section of the product documentation.
Build the plugin by issuing the command mvn package
. This will produce a JAR file in the target
directory, which can be installed.
To install the plugin, copy the compiled JAR (and all of its dependencies from target/dependency/
) into ${IDSVR_HOME}/usr/share/plugins/${pluginGroup}
on each node, including the admin node. For more information about installing plugins, refer to the Product Documentation.
Parameter | Description |
---|---|
Client ID | The ID of the client use dto connect to Azure. Can be obtained by creating a Service Provider (SP) with the command az ad sp create-for-rbac . The appId is to be used as the ClientId in this configuration. |
Client Secret | Also available in the output of creating the SP. The Client Secret is the password in the output. |
Tenant ID | Also available in the output of creating the SP. The Tenant Id is the tenant in the output. |
Subscription ID | Can be obtained by running az account list . The output will contain an entry, id , this is the Subscription Id. |
Resource Group Name | The name of the Resource Group that the API Management is configured in. This can be found in Azure -> API Management services. In the row for the given API Management service the name of the Resource Group is in the column Resource group . |
Service Name | Similarly the Service Name can be found in the Name column. |
At a minimum the following attributes are required from the Authentication context:
- subject
- attributes containing a name entry with givenName and familyName (
"attributes": "{'name': {'givenName': 'alice', 'familyName': 'anderson'}}"
)
Please visit curity.io for more information about the Curity Identity Server.